<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: P2P Communication Intermittence in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194875#M36271</link>
    <description>&lt;P&gt;First packet isnt syn has been an error thats been around since probably the beginning of stateful firewalls. All that says, in layman's terms, is that connection is not completing to the point of 3-way handshake (syn -&amp;gt; syn-ack-&amp;gt;ack)&lt;/P&gt;
&lt;P&gt;You should do regular fw monitor and fw monitor -F flag to see what happens.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2023 18:49:41 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-10-11T18:49:41Z</dc:date>
    <item>
      <title>P2P Communication Intermittence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194872#M36268</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;We have a current IP-A-IP communication, which travels over a dedicated link (MPLS).&lt;BR /&gt;Since a few weeks, we have this communication very slow and unstable.&lt;/P&gt;
&lt;P&gt;What the source wants to consume is a service on port 80, but what I see in the logs, is that there is a traffic that at times is allowed, and at times not.&lt;/P&gt;
&lt;P&gt;When it is allowed, the traffic matches with its firewall rule and its NO-NAT rule (since they don't want to kick the origin), but then the traffic starts to match with a rule that is not visible in the SmartConsole, and simply "throws away" the connections (the only known message is that a DROP is done).&lt;/P&gt;
&lt;P&gt;Is there any way to detect the reason for this behavior?&lt;/P&gt;
&lt;P&gt;I publish a reference image.&lt;BR /&gt;&lt;BR /&gt;ClusterXL HA -&amp;gt; Version R81.10 -&amp;gt; Take 81&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IN1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22763iBBFE1E0B7F3807D4/image-size/large?v=v2&amp;amp;px=999" role="button" title="IN1.png" alt="IN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Cheers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 18:21:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194872#M36268</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-11T18:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: P2P Communication Intermittence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194873#M36269</link>
      <description>&lt;P&gt;Thats always tough bro, specially when its intermittent. MTU came to mind when I read the problem, but not so sure that might be the case here. Can you expand the drop log and send it as a screenshot, so we can see all the details? Does zdebug show anything when it fails?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 18:30:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194873#M36269</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-11T18:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: P2P Communication Intermittence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194874#M36270</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;I'm sharing a notepad, with a log (Accept) and a log in (Drop), so it can be more understandable.&lt;/P&gt;
&lt;P&gt;I'm not sure if these logs in DROPS should be ignored or not, or relate directly to the problem, since the problem is that the source has a "SLOW" problem when it wants to consume a resource from the destination.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 18:36:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194874#M36270</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-11T18:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: P2P Communication Intermittence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194875#M36271</link>
      <description>&lt;P&gt;First packet isnt syn has been an error thats been around since probably the beginning of stateful firewalls. All that says, in layman's terms, is that connection is not completing to the point of 3-way handshake (syn -&amp;gt; syn-ack-&amp;gt;ack)&lt;/P&gt;
&lt;P&gt;You should do regular fw monitor and fw monitor -F flag to see what happens.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 18:49:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194875#M36271</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-11T18:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: P2P Communication Intermittence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194876#M36272</link>
      <description>&lt;P&gt;Do you have the syntax of the command that I could apply in my scenario, in order to check the flow of this communication, please?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 19:25:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194876#M36272</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-11T19:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: P2P Communication Intermittence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194880#M36274</link>
      <description>&lt;P&gt;If you give src and dst, I can provide it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 19:45:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194880#M36274</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-11T19:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: P2P Communication Intermittence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194882#M36275</link>
      <description>&lt;P&gt;The origin and destination, are those shown in the initial image of this publication &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 20:20:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194882#M36275</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-11T20:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: P2P Communication Intermittence</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194883#M36276</link>
      <description>&lt;P&gt;I attached simple file I sent to customer once for things to check based on different issues, example is there.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 20:29:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-Communication-Intermittence/m-p/194883#M36276</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-11T20:29:38Z</dc:date>
    </item>
  </channel>
</rss>

