<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Packet processing stops after chain module &amp;quot;fw post VM inbound&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209251#M39643</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have an issue with a connection that should be NATed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The NAT that should be applied on a connection between 10.1.1.82 and 10.1.1.154 does not work:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;fw monitor -p all -e "accept(host(10.1.1.154));"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[vs_0][fw_2] bond1.280:I16 (fw post VM inbound )[44]: 10.1.1.82 -&amp;gt; 10.1.1.154 (50) len=104 id=5411&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A working connection shows this as next step:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[vs_0][fw_3] bond1.280:I16 (fw post VM inbound )[44]: 10.1.1.82 -&amp;gt; 172.1.1.7 (50) len=152 id=5014&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[vs_0][fw_3] bond1.280:I17 (RTM packet in)[44]: 10.1.1.82 -&amp;gt; 84.1.1.93 (50) len=152 id=5014&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;So it looks like in the first scenario the processing stopped at chain module "&lt;SPAN&gt;fw post VM inbound".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It was working before but since we reapplied multi-queuing config on this cluster it stopped working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Any idea why ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks Thomas&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PS: Running R81.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2024 10:32:26 GMT</pubDate>
    <dc:creator>TomShanti</dc:creator>
    <dc:date>2024-03-20T10:32:26Z</dc:date>
    <item>
      <title>Packet processing stops after chain module "fw post VM inbound"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209251#M39643</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have an issue with a connection that should be NATed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The NAT that should be applied on a connection between 10.1.1.82 and 10.1.1.154 does not work:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;fw monitor -p all -e "accept(host(10.1.1.154));"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[vs_0][fw_2] bond1.280:I16 (fw post VM inbound )[44]: 10.1.1.82 -&amp;gt; 10.1.1.154 (50) len=104 id=5411&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A working connection shows this as next step:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[vs_0][fw_3] bond1.280:I16 (fw post VM inbound )[44]: 10.1.1.82 -&amp;gt; 172.1.1.7 (50) len=152 id=5014&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[vs_0][fw_3] bond1.280:I17 (RTM packet in)[44]: 10.1.1.82 -&amp;gt; 84.1.1.93 (50) len=152 id=5014&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;So it looks like in the first scenario the processing stopped at chain module "&lt;SPAN&gt;fw post VM inbound".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It was working before but since we reapplied multi-queuing config on this cluster it stopped working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;Any idea why ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks Thomas&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PS: Running R81.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 10:32:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209251#M39643</guid>
      <dc:creator>TomShanti</dc:creator>
      <dc:date>2024-03-20T10:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Packet processing stops after chain module "fw post VM inbound"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209283#M39645</link>
      <description>&lt;P&gt;Most likely, you're going to need to enable kernel debugs to see where the traffic goes (and why).&lt;BR /&gt;Might need the TAC to help you figure out the correct debug flags to use here (and fix the underlying problem, of course):&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk98799" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk98799&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 14:09:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209283#M39645</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-20T14:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Packet processing stops after chain module "fw post VM inbound"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209299#M39646</link>
      <description>&lt;P&gt;Try running &lt;STRONG&gt;fw ctl zdebug drop&lt;/STRONG&gt; while the traffic is not working, this will show you all live drops by any Check Point code along with a reason, even if it is not being logged.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 15:07:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209299#M39646</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-03-20T15:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Packet processing stops after chain module "fw post VM inbound"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209304#M39650</link>
      <description>&lt;P&gt;I would definitely do zdebug, to start with. Just to be 100% sure, can you remove multi q config and see if it works again?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 16:43:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209304#M39650</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-20T16:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Packet processing stops after chain module "fw post VM inbound"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209742#M39757</link>
      <description>&lt;P&gt;1. it's better to use: fw monitor -p all -F "0,0,10.1.1.154,0,0"&lt;/P&gt;
&lt;P&gt;2. i also suggest to use 'fw ctl zdebug + drop" | grep 10.1.1.154&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 18:20:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209742#M39757</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-03-26T18:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Packet processing stops after chain module "fw post VM inbound"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209763#M39761</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/34522"&gt;@TomShanti&lt;/a&gt;&amp;nbsp;if you are going to attempt to run a &lt;STRONG&gt;fw monitor -F&lt;/STRONG&gt; and a &lt;STRONG&gt;fw ctl zdebug + drop&lt;/STRONG&gt; simultaneously, be aware that you must do so in a particular order to keep the two commands from stepping on each other and causing problematic results.&amp;nbsp; See here:&amp;nbsp;&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Max-Capture-Update-2-Debug-Filter-Battle-fw-monitor-F-vs-fw-ctl/m-p/147374" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Max Capture Update 2: Debug Filter Battle -- fw monitor -F vs. fw ctl zdebug + drop&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 23:51:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-processing-stops-after-chain-module-quot-fw-post-VM/m-p/209763#M39761</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-03-26T23:51:34Z</dc:date>
    </item>
  </channel>
</rss>

