<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet Analysing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217556#M41454</link>
    <description>&lt;P&gt;Of course I can. I got a call in 20 mins, but can also check it while on that call, but let me do it now.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jun 2024 17:41:04 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-06-14T17:41:04Z</dc:date>
    <item>
      <title>Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217549#M41448</link>
      <description>&lt;P&gt;Hello All,&lt;BR /&gt;&lt;BR /&gt;We have faced an issue for one of our services we have from DMZ Zone to Internal. The issue is that from 100 requests sent to the internal server some requests getting a response within 2-4 minutes. But the fast ones will get with 2 seconds. And we have tried bypassing our checkpoint firewall and all 100 requests gets a response every 2 seconds. We have checked on our checkpoint rule but can't find thing. Below is a packet capture from different servers. If someone can help in finding the differences between the captures.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 05:40:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217549#M41448</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2024-06-15T05:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217550#M41449</link>
      <description>&lt;P&gt;I will download and have a look. Can you please indicate src and dst IP?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 17:20:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217550#M41449</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-14T17:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217551#M41450</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the quick reply. All SRC &amp;amp; DST IP's are on the captured packets.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 17:24:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217551#M41450</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2024-06-14T17:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217552#M41451</link>
      <description>&lt;P&gt;K, sounds good! Just finishing up an Azure lab, will check soon.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 17:25:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217552#M41451</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-14T17:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217554#M41452</link>
      <description>&lt;P&gt;I checked few streams and to me, appears server is NOT sending syn-ack, which it should&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26260i3615BCD0BDE508A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 17:36:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217554#M41452</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-14T17:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217555#M41453</link>
      <description>&lt;P&gt;Okay. Thanks.&lt;BR /&gt;&lt;BR /&gt;May be can you check the one named with Server2 and server 2 - retried&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 17:39:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217555#M41453</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2024-06-14T17:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217556#M41454</link>
      <description>&lt;P&gt;Of course I can. I got a call in 20 mins, but can also check it while on that call, but let me do it now.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 17:41:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217556#M41454</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-14T17:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217559#M41455</link>
      <description>&lt;P&gt;Well, one seems worse, as it shows syn and syn-ack absent. The send one is the same.&lt;/P&gt;
&lt;P&gt;Maybe do capture like this, dont output into a file and see what you get&lt;/P&gt;
&lt;P&gt;Idea is (srcip,srcport,dstip,dstport, protocol),&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, in your case, lets say port is 443, lets pretend ip's are 1.1.1.1 and 2.2.2.2&lt;/P&gt;
&lt;P&gt;fw monitor -F "1.1.1.1,0,2.2.2.2,443,0" -F "2.2.2.2,0,1.1.1.1,443,0"&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26261i670F338643650B60/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26262iE12E63DEB047E5BB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; You can also do zdebug as below, just replace with right IPs&lt;/P&gt;
&lt;P&gt;fw ctl zdebug + drop | grep x.x.x.x | grep y.y.y.y&lt;/P&gt;
&lt;P&gt;fw ctl debug 0 to turn off debugs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 17:47:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217559#M41455</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-14T17:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217561#M41456</link>
      <description>&lt;P&gt;so, which server is not sending proper ack/syn messages?&lt;BR /&gt;&lt;BR /&gt;And what do you suggest&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 18:00:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217561#M41456</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2024-06-14T18:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217563#M41457</link>
      <description>&lt;P&gt;I cant recall now, can check again soon. Do you have working capture?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 18:05:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217563#M41457</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-14T18:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217564#M41458</link>
      <description>&lt;P&gt;right now not. but i can do early morning&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 18:07:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217564#M41458</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2024-06-14T18:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217565#M41459</link>
      <description>&lt;P&gt;Just finished my call, let me check again.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 19:10:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217565#M41459</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-14T19:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217567#M41460</link>
      <description>&lt;P&gt;Every packet I check, you see this.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26264i181081F701848478/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 19:36:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217567#M41460</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-14T19:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217610#M41469</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I have executed&amp;nbsp;&lt;SPAN&gt;fw ctl zdebug + drop | grep x.x.x.x | grep y.y.y.y during the capture by replacing the IP's, but there is no rule that can drop this connection.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 11:38:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217610#M41469</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2024-06-15T11:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217612#M41470</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is it possible to only allow the access on Network only. I mean with out Application and URL for this specific rule.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 11:40:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217612#M41470</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2024-06-15T11:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217614#M41471</link>
      <description>&lt;P&gt;Yes, 100%. If you have say 2 ordered layers, just make sure its allowed on both, but 2nd layer can have any any allow at the bottom, but be configured for urlf+app &amp;nbsp;blades.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 11:44:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217614#M41471</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-15T11:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217615#M41472</link>
      <description>&lt;P&gt;Ok. We have suspected that if there is any URL/Application control is blocking it. And If there is any filtering on it.&lt;BR /&gt;&lt;BR /&gt;As I told you yesterday when we do the capture from campus network (Bypassing Checkpoint) all requests are getting the response with in seconds. Sample is 100 request&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 13:06:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217615#M41472</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2024-06-15T13:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217616#M41473</link>
      <description>&lt;P&gt;Here is good reference for the layered rules. I have real good document I made about it, but its on my work laptop, so can send tomorrow.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;All you need to remember is this...IF there are multiple ordered layers, traffic has to be accepted on ALL of them.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/What-is-the-point-of-ordered-layers-for-Accept-rules/m-p/200008" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/What-is-the-point-of-ordered-layers-for-Accept-rules/m-p/200008&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 13:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217616#M41473</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-15T13:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217617#M41474</link>
      <description>&lt;P&gt;If you send a screenshot oh how policy layers are configured, I can tell you if something is wrong. Just blur out any sensitive details.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 13:13:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217617#M41474</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-15T13:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Analysing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217622#M41475</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Since Im just watching some Euro cup football (or as our American friends call it soccer (well us Canadians too : - ), which I think is incorrect, as you play it with your feet lol), but anyway, cheering for Croatia, which is getting destroyed by Spain, as they are closest to where I grew up, Montenegro, and we did not even qualify, since we SUCK lol&lt;/P&gt;
&lt;P&gt;Anywho, I attached a document with layred rules examples from my lab. If you need help or not clear, let me know, we can do remote session.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 17:24:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-Analysing/m-p/217622#M41475</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-15T17:24:50Z</dc:date>
    </item>
  </channel>
</rss>

