<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Occasional failing Echo Reply in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203971#M38457</link>
    <description>&lt;P&gt;Thats fair assesment.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jan 2024 14:58:11 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-01-23T14:58:11Z</dc:date>
    <item>
      <title>Occasional failing Echo Reply</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203940#M38445</link>
      <description>&lt;P&gt;We have a customer which has a VPN from Portugal to the Netherlands. The Portugese site is a 1570 with R80.20 and the central site is a cluster with 6000 appliances running R81&lt;/P&gt;
&lt;P&gt;Customer has a contact in Portugal&amp;nbsp; who has started a contious ping and every now and then we loose a packet. In the logs I see Encrypt in Portugal and Decryp in the Netherlands. But every now and again in between these log entries there is a DROP on the echo-reply packet. with the additional information: ICMP reply does not match a previous request. This happens about 9 to 10 times per hour.&lt;/P&gt;
&lt;P&gt;The ICMP virtual session timeout is set to 30 seconds under global properties. Which seems enough as the roundtrip over the VPN is just under 50 ms.&lt;/P&gt;
&lt;P&gt;Customer also has a continous ping open to the router just in front of the firewalls in the Netherlands and that does not show any dropped packets.&lt;/P&gt;
&lt;P&gt;Bsed on&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk66443" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk66443&lt;/A&gt;&amp;nbsp;I would have to run a packet capture to see what happens.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone any other suggestions?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 12:33:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203940#M38445</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2024-01-23T12:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Occasional failing Echo Reply</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203946#M38447</link>
      <description>&lt;P&gt;Packet capture on the central side was easy. I saw 2 instances where the logs shows a dropped reply packet and the central firewall shows a gap of 5 seconds where there is a normal echo request and echo reply every second. So I need to do this at both ends at the same time. to learn more.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 13:01:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203946#M38447</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2024-01-23T13:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Occasional failing Echo Reply</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203952#M38448</link>
      <description>&lt;P&gt;I dont like that "solution" from the sk at all. All that does is says uncheck "drop out of state", which is not even good workaround in my mind. I know it says as immediate workaround, but then obviously, who knows how much time it can take to find permenant fix. Here is how I always fixed this issue in the past...screenshots attached.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24196iD9C7C909550EACD1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_3.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24197iC2EA36ED492702DA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_3.png" alt="Screenshot_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 13:30:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203952#M38448</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-23T13:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: Occasional failing Echo Reply</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203953#M38449</link>
      <description>&lt;P&gt;Done fw monitor on the 1570 and packet wise there is nothing wrong with the reply but it fails to pass.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So this seems like bad behaviour of the appliance and I will create a TAC case for it. As I see other bad signs on the unit as well. (vmcore files of the last few days, .....&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 13:32:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203953#M38449</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2024-01-23T13:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Occasional failing Echo Reply</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203963#M38452</link>
      <description>&lt;P&gt;Hmmm. Global properties means it will impact a few dozen other VPN's as well. Not even sure this is an issue with losing SA's in the first place. Let me fetch the vpn deg ikeon output. to see if it makes any sense.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 14:20:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203963#M38452</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2024-01-23T14:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Occasional failing Echo Reply</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203967#M38455</link>
      <description>&lt;P&gt;Thats right, its global setting.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 14:29:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203967#M38455</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-23T14:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Occasional failing Echo Reply</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203969#M38456</link>
      <description>&lt;P&gt;Looking at the ike log it does not appear to be a VPN issue.&lt;/P&gt;
&lt;P&gt;At 14:22:05 there is an issu with the echo-reply packet being dropped. There is no chnage in the VPN between 14:03:06 and 14:38:09 so the cause of this particular issue is not VPN in itself.&lt;/P&gt;
&lt;P&gt;However seeing 4 times a Phase 1 build up in less then an hour is not a sign of a healthy VPN.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 14:51:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203969#M38456</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2024-01-23T14:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Occasional failing Echo Reply</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203971#M38457</link>
      <description>&lt;P&gt;Thats fair assesment.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 14:58:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Occasional-failing-Echo-Reply/m-p/203971#M38457</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-23T14:58:11Z</dc:date>
    </item>
  </channel>
</rss>

