<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP segment out of maximum allowed in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-segment-out-of-maximum-allowed/m-p/169201#M35382</link>
    <description>&lt;P&gt;This is one of the sanity checks we perform by default on connections.&lt;BR /&gt;It can be triggered under load as described here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114529" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114529&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;You can disable this check or create a specific exception here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19314iC308009991B9CD2B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Note these Inspection Settings are done in the firewall (not IPS) and require pushing the Access Policy to take effect.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jan 2023 02:03:22 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-01-26T02:03:22Z</dc:date>
    <item>
      <title>TCP segment out of maximum allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-segment-out-of-maximum-allowed/m-p/169129#M35381</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Hoping someone can help! I am relatively new to checkpoints, we are seeing a lot of packets dropped with this description&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"https Traffic Dropped from XX.XXX.XXX.XXX to XX.XXX.XXX.XXX due to TCP segment out of maximum allowed sequence. Packet dropped."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This happens when users try to access an internal confluence site. Its very slow to load, I see a lot of the errors listed above, then eventually it will work and go through. So there isn't a rule blocking it as such. Its intermittent but repeatable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did google for this and found an article suggesting that it could be high memory usage, I got up a CLI and run the TOP command whilst the issue was occuring however %mem was never high, cpu spiked here and there, usually with cphwd_w_init_ke at the top, but its certainly not sitting at 100pc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;any help much appreciated!&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 15:03:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-segment-out-of-maximum-allowed/m-p/169129#M35381</guid>
      <dc:creator>jamesp</dc:creator>
      <dc:date>2023-01-25T15:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: TCP segment out of maximum allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-segment-out-of-maximum-allowed/m-p/169201#M35382</link>
      <description>&lt;P&gt;This is one of the sanity checks we perform by default on connections.&lt;BR /&gt;It can be triggered under load as described here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114529" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114529&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;You can disable this check or create a specific exception here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19314iC308009991B9CD2B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Note these Inspection Settings are done in the firewall (not IPS) and require pushing the Access Policy to take effect.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 02:03:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-segment-out-of-maximum-allowed/m-p/169201#M35382</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-26T02:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: TCP segment out of maximum allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-segment-out-of-maximum-allowed/m-p/169266#M35383</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Thanks so much for your reply, so if I set that to allow instead, it should speed up the loading of the site?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 11:24:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-segment-out-of-maximum-allowed/m-p/169266#M35383</guid>
      <dc:creator>jamesp</dc:creator>
      <dc:date>2023-01-26T11:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: TCP segment out of maximum allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-segment-out-of-maximum-allowed/m-p/191512#M35384</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have the same scenario.&lt;/P&gt;
&lt;P&gt;The memory, is exceeding the 90% usage threshold.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PC.png" style="width: 755px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22314i057D0EDE30A3F309/image-size/large?v=v2&amp;amp;px=999" role="button" title="PC.png" alt="PC.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The message is the same as reported at the beginning of this post.&lt;/P&gt;
&lt;P&gt;It is an "expected behavior" (normal), that this kind of alerts occur, and that the memory is "triggered" in terms of its consumption?&lt;/P&gt;
&lt;P&gt;I have checked sk114529, but I don't see any definitive "solutions".&lt;/P&gt;
&lt;P&gt;Could someone recommend me, what kind of solution can be applied for this scenario, please?&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 20:34:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-segment-out-of-maximum-allowed/m-p/191512#M35384</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-04T20:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: TCP segment out of maximum allowed</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-segment-out-of-maximum-allowed/m-p/191652#M35385</link>
      <description>&lt;P&gt;Is it expected behavior? Depends on the exact traffic involved.&lt;BR /&gt;The protection itself might not cause extra memory usage, but the client's reaction to the connection dropping might.&lt;BR /&gt;Regardless, if this is happening with a specific, trusted source or destination on a regular basis, your best bet is to create an exception for this protection.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 19:57:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-segment-out-of-maximum-allowed/m-p/191652#M35385</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-05T19:57:42Z</dc:date>
    </item>
  </channel>
</rss>

