<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Gre Tunnel traffic being dropped in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gre-Tunnel-traffic-being-dropped/m-p/178451#M32691</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We have 2 R81.10 appliances in 2 separate sites, connected over our WAN. Behind each firewall, there is a wireless controller. The 2 wireless controllers are configured to connect to each other via Gre tunnels. However, the gre tunnel is not getting established between these 2 controllers. Each controller also have other gre tunnels to other wireless controllers at other sites on the WAN, which are established and working. It appears it is only the gre traffic between the 2 main controllers that is getting dropped at each firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I run tcpdump, I can see the traffic coming in to the interface but not going out. If I run fw ctl zdebug drop I get the message&amp;nbsp;&lt;/P&gt;&lt;P&gt;"dropped by fw_handle_old_conn_recovery Reason: Other protocol packet that belongs to an old connection"&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm unable to find much information on this particular message. Has anyone any ideas what it could point to and how I troubleshoot this? Any reason why some gre traffic goes through and other traffic is dropped?&lt;/P&gt;&lt;P&gt;Many Thanks&lt;BR /&gt;Roy&lt;/P&gt;</description>
    <pubDate>Wed, 19 Apr 2023 08:26:45 GMT</pubDate>
    <dc:creator>Roy_Smith</dc:creator>
    <dc:date>2023-04-19T08:26:45Z</dc:date>
    <item>
      <title>Gre Tunnel traffic being dropped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gre-Tunnel-traffic-being-dropped/m-p/178451#M32691</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We have 2 R81.10 appliances in 2 separate sites, connected over our WAN. Behind each firewall, there is a wireless controller. The 2 wireless controllers are configured to connect to each other via Gre tunnels. However, the gre tunnel is not getting established between these 2 controllers. Each controller also have other gre tunnels to other wireless controllers at other sites on the WAN, which are established and working. It appears it is only the gre traffic between the 2 main controllers that is getting dropped at each firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I run tcpdump, I can see the traffic coming in to the interface but not going out. If I run fw ctl zdebug drop I get the message&amp;nbsp;&lt;/P&gt;&lt;P&gt;"dropped by fw_handle_old_conn_recovery Reason: Other protocol packet that belongs to an old connection"&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm unable to find much information on this particular message. Has anyone any ideas what it could point to and how I troubleshoot this? Any reason why some gre traffic goes through and other traffic is dropped?&lt;/P&gt;&lt;P&gt;Many Thanks&lt;BR /&gt;Roy&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 08:26:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gre-Tunnel-traffic-being-dropped/m-p/178451#M32691</guid>
      <dc:creator>Roy_Smith</dc:creator>
      <dc:date>2023-04-19T08:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Gre Tunnel traffic being dropped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gre-Tunnel-traffic-being-dropped/m-p/178480#M32695</link>
      <description>&lt;P&gt;sk121933 talks to a similar drop reason for UDP traffic flows.&lt;/P&gt;
&lt;P&gt;Can I confirm your connect persistence settings, are they set to keep or rematch?&lt;/P&gt;
&lt;P&gt;Is the issue always present or only after someone performs a policy installation for the intermediate gateway?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 14:02:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gre-Tunnel-traffic-being-dropped/m-p/178480#M32695</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-19T14:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: Gre Tunnel traffic being dropped</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gre-Tunnel-traffic-being-dropped/m-p/178570#M32706</link>
      <description>&lt;P&gt;Chris&lt;/P&gt;&lt;P&gt;Thanks for that. I initially went through the sk article but did not see any difference. I decided to go through the clear connections steps on both gateways and that appears to have resolved the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;Roy&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 07:07:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gre-Tunnel-traffic-being-dropped/m-p/178570#M32706</guid>
      <dc:creator>Roy_Smith</dc:creator>
      <dc:date>2023-04-20T07:07:32Z</dc:date>
    </item>
  </channel>
</rss>

