<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packets get drop in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7651#M59296</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for this advice.&lt;/P&gt;&lt;P&gt;I will check this out and keep you posted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Aug 2018 05:27:35 GMT</pubDate>
    <dc:creator>Sven_Glock</dc:creator>
    <dc:date>2018-08-14T05:27:35Z</dc:date>
    <item>
      <title>Packets get drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7642#M59287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what is the reason for happen this ?&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=6 x.x.x.x:30730 -&amp;gt; 10.2.200.50:80 dropped by fw_first_packet_state_checks Reason: First packet isn't SYN;&lt;BR /&gt;;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=6 x.x.x.x:30731 -&amp;gt; 10.2.200.50:80 dropped by fw_first_packet_state_checks Reason: First packet isn't SYN;&lt;BR /&gt;;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=6 y.y.y.y:37020 -&amp;gt; 10.2.200.50:80 dropped by fw_first_packet_state_checks Reason: First packet isn't SYN;&lt;BR /&gt;;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 y.y.y.y:37021 -&amp;gt; 10.2.200.50:80 dropped by fw_first_packet_state_checks Reason: First packet isn't SYN;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Oct 2017 07:41:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7642#M59287</guid>
      <dc:creator>Prashan_Attanay</dc:creator>
      <dc:date>2017-10-18T07:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Packets get drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7643#M59288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stateful Inspection checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It means the first packet of a TCP session (proto=6) traversing the firewall isn't the syncronization packet (first of the three way handshake of TCP) so because of this, the firewall drops the packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default, Check Point Firewall is configured to drop out of state TCP Packets (Global Properties -&amp;gt; Stateful Inspection-&amp;gt;Drop Out of state TCP Packets is checked)&lt;/P&gt;&lt;P&gt;You can completely disable the TCP out of state drops:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;By unchecking the option on Stateful Inspection and installing policy&lt;/LI&gt;&lt;LI&gt;By adding an exception to Drop out of state TCP on Stateful Inspection and selecting the Firewall (also requires install policy).&lt;/LI&gt;&lt;LI&gt;Executing the following command on the gateway in expert mode to disable on the fly: "&lt;EM&gt;fw ctl set int fw_allow_out_of_state_tcp 1&lt;/EM&gt;" (Does not survive a reboot) .&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can follow this sk as workaround for allowing out of state packets to some traffic only: &lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk11088" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk11088"&gt;SmartView Tracker shows multiple logs for dropped &amp;amp;apos;TCP out of state&amp;amp;apos; packets with various TCP flags&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Oct 2017 21:55:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7643#M59288</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2017-10-18T21:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Packets get drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7644#M59289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your explanation&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Oct 2017 20:14:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7644#M59289</guid>
      <dc:creator>Prashan_Attanay</dc:creator>
      <dc:date>2017-10-20T20:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Packets get drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7645#M59290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible that "2." is not supported for vsx in R80.10?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2018 16:59:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7645#M59290</guid>
      <dc:creator>Sven_Glock</dc:creator>
      <dc:date>2018-08-03T16:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Packets get drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7646#M59291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not as far as I know.&lt;/P&gt;&lt;P&gt;What makes you think it isn't?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2018 17:20:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7646#M59291</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-03T17:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Packets get drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7647#M59292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried it in an environment where only virtual systems are available.&lt;/P&gt;&lt;P&gt;Here I am not able to select a gateway when adding a new gateway to TCP Out of state exceptions...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2018 17:26:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7647#M59292</guid>
      <dc:creator>Sven_Glock</dc:creator>
      <dc:date>2018-08-03T17:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: Packets get drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7648#M59293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh, you're talking about exceptions, which, true, might not be supported on a VS.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2018 17:38:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7648#M59293</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-03T17:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Packets get drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7649#M59294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good to know, thanks Dameon!&lt;/P&gt;&lt;P&gt;Is there an other way to disable stateful inspection on a single virtual system?&lt;/P&gt;&lt;P&gt;1. would impact other policies and 3. seems not to work with virtual systems, too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Aug 2018 07:10:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7649#M59294</guid>
      <dc:creator>Sven_Glock</dc:creator>
      <dc:date>2018-08-05T07:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Packets get drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7650#M59295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You'll need to contact the TAC to see if you can get a hotfix for the following:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109776" title="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109776"&gt;Option to allow out of state packets per VS&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 02:26:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7650#M59295</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-14T02:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Packets get drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7651#M59296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for this advice.&lt;/P&gt;&lt;P&gt;I will check this out and keep you posted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 05:27:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packets-get-drop/m-p/7651#M59296</guid>
      <dc:creator>Sven_Glock</dc:creator>
      <dc:date>2018-08-14T05:27:35Z</dc:date>
    </item>
  </channel>
</rss>

