<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: First Packet Isn't SYN drop in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238197#M46223</link>
    <description>&lt;P&gt;In my case, it causes encoders not responding to PMS requests cutting room keys.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2025 16:43:37 GMT</pubDate>
    <dc:creator>DannyCor</dc:creator>
    <dc:date>2025-01-10T16:43:37Z</dc:date>
    <item>
      <title>First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238111#M46203</link>
      <description>&lt;P&gt;I am new to Checkpoint firewall and have been dealing with "First Packet Isn't SYN" issue for the last few weeks. This is happening between interface and one of application server, both server communicate on port 4000. The odd thing I see only first 3 packets are dropped then the 4th allowed to get through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment, I only have access to logs only, not configuration. Any configuration changes need to be communicated with other team.&lt;/P&gt;&lt;P&gt;Anything place I can start to troubleshoot the issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 18:02:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238111#M46203</guid>
      <dc:creator>DannyCor</dc:creator>
      <dc:date>2025-01-09T18:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238142#M46204</link>
      <description>&lt;P&gt;That can sometimes be bit tricky to troubleshoot. I would say, run tcpdump and fw monitor to see whats happening with the traffic. Also, I would do ip r g command to make sure route is right. Say IP is 10.9.8.7, you can run ip r g 10.9.8.7 from the expert mode.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 03:30:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238142#M46204</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-10T03:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238151#M46208</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/123218"&gt;@DannyCor&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If you check the name of the incoming interface at the first packet what do you see? (eg.: eth1)&lt;/LI&gt;
&lt;LI&gt;The interface is the same by that packet which is dropped?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Here is a screenshot what to check:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-01-10 09_22_45-10.211.190.100-R81.20-SmartConsole.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29142iD5187976D37D15A3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2025-01-10 09_22_45-10.211.190.100-R81.20-SmartConsole.png" alt="2025-01-10 09_22_45-10.211.190.100-R81.20-SmartConsole.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If not the same, we are facing with asymmetrical routing.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 08:59:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238151#M46208</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-10T08:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238163#M46211</link>
      <description>&lt;P&gt;Routing usually comes to mind with this sort of error.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 12:40:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238163#M46211</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-10T12:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238174#M46214</link>
      <description>&lt;P&gt;Also, some SKs to consider.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk107618" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk107618&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk31382" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk31382&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk180253" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk180253&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 15:16:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238174#M46214</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-10T15:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238175#M46215</link>
      <description>&lt;P&gt;I checked them, it uses same interface.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 15:20:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238175#M46215</guid>
      <dc:creator>DannyCor</dc:creator>
      <dc:date>2025-01-10T15:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238176#M46216</link>
      <description>&lt;P&gt;Both dropped and allowed traffic coming from same interface.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 15:23:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238176#M46216</guid>
      <dc:creator>DannyCor</dc:creator>
      <dc:date>2025-01-10T15:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238178#M46218</link>
      <description>&lt;P&gt;I wanted to add. Tnterface server is communicating with several different application servers located on multiple different VLANs. This issue only happening on this one particular application server.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 15:27:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238178#M46218</guid>
      <dc:creator>DannyCor</dc:creator>
      <dc:date>2025-01-10T15:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238196#M46222</link>
      <description>&lt;P&gt;First question is always, are these drops causing any issues? Are there issue reported of this connection flow or you just saw them?&lt;/P&gt;
&lt;P&gt;And what is the issue? If they setup new connection is it slow? Or they get timeout after like 1 hour and have to rebuild connection.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 16:29:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238196#M46222</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-01-10T16:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238197#M46223</link>
      <description>&lt;P&gt;In my case, it causes encoders not responding to PMS requests cutting room keys.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 16:43:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238197#M46223</guid>
      <dc:creator>DannyCor</dc:creator>
      <dc:date>2025-01-10T16:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238198#M46224</link>
      <description>&lt;P&gt;In this case please check the routing and the interface of the accepted and droppet packet. Itt might help&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 16:46:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238198#M46224</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-10T16:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238225#M46231</link>
      <description>&lt;P&gt;Will the request work after some time or they never work? Or it works first few minutes and then stops working after an hour or so?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 20:19:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238225#M46231</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-01-10T20:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238363#M46242</link>
      <description>&lt;P&gt;Check the routing table of the affected server. There will be the problem.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 12:04:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238363#M46242</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-13T12:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238577#M46264</link>
      <description>&lt;P&gt;&amp;gt; Or it works first few minutes and then stops working after an hour or so?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or, does it work "right away', then, if no new traffic is passing, does it work after 1 hour?&lt;/P&gt;&lt;P&gt;"Such things"&amp;nbsp; might happen in, for example, the following cases:&lt;/P&gt;&lt;P&gt;- Asymmetrical routing, when the "reply" packet follows a different path then the "query" one. In this case the connection can not be established.&lt;BR /&gt;- New packets after TCP timeout. If there are no packets for 1 hour, the firewall removes the entry from the connection table. If any of the communicating side decides to send more packets, the firewall will drop them with an error "First Packet out of syn".&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;This can be solved in several ways:&lt;BR /&gt;- Just ignore it, if no issues noticed&lt;BR /&gt;- Increase the timeout for the service (SmartDashboard)&lt;BR /&gt;- Globally increase the TCP timeout for all TCP connections on the firewalls (SmartDashboard)&lt;BR /&gt;- Set the TCP heartbeat/keepalives to less than 3600 seconds on the communicating parties (Kernel)&lt;BR /&gt;- Configure the firewall to send RST to the parties, when the TCP timeout occurs (Kernel)&lt;/P&gt;&lt;P&gt;Which method to choose - depends on the application, for example, if it can recover from either connection reset or connection timeout.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 21:22:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238577#M46264</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2025-01-14T21:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238579#M46266</link>
      <description>&lt;P&gt;After server reboot, I have seen multiple packets allowed to pass, then after sometimes (hours), the FW starts dropping packets again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 21:44:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238579#M46266</guid>
      <dc:creator>DannyCor</dc:creator>
      <dc:date>2025-01-14T21:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: First Packet Isn't SYN drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238581#M46268</link>
      <description>&lt;P&gt;Here we go. Exactly what I said above.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 21:53:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/First-Packet-Isn-t-SYN-drop/m-p/238581#M46268</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2025-01-14T21:53:24Z</dc:date>
    </item>
  </channel>
</rss>

