<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is this a Legitimate &amp;quot;fist packet isn't SYN drop&amp;quot;? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-this-a-Legitimate-quot-fist-packet-isn-t-SYN-drop-quot/m-p/99849#M7796</link>
    <description>&lt;P&gt;We have this transaction that, in this example, startsat 11:00. At 11.02 the remote server tries to close it sending the FIN but the local server tries to close it only half an hour later (at 11.30). This FIN packet gets retransmitted&amp;nbsp; but no ack is sent by the remote server. At last the local server sends a RST&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-10-22 15_08_23-poller - 172.20.3.2 - Connessione Desktop remoto.png" style="width: 785px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8543iA55C1CFC048E1B70/image-dimensions/785x209?v=v2" width="785" height="209" role="button" title="2020-10-22 15_08_23-poller - 172.20.3.2 - Connessione Desktop remoto.png" alt="2020-10-22 15_08_23-poller - 172.20.3.2 - Connessione Desktop remoto.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; My problem here is that those Resets (and sometimes some final FIN ACK packet as well) get blocked by our Checkpoint as a "first packet isn't SYN"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-10-22 15_04_42-poller - 172.20.3.2 - Connessione Desktop remoto.png" style="width: 523px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8544i58A40926C5FA29BC/image-dimensions/523x426?v=v2" width="523" height="426" role="button" title="2020-10-22 15_04_42-poller - 172.20.3.2 - Connessione Desktop remoto.png" alt="2020-10-22 15_04_42-poller - 172.20.3.2 - Connessione Desktop remoto.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this legitimate? the tcp session timeout configured for the firewall is 3600. Is this because those packet are past both side FIN packet and the TCP end timeout is set (by default) at 5 seconds?&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Oct 2020 14:27:15 GMT</pubDate>
    <dc:creator>Stefano_Cappell</dc:creator>
    <dc:date>2020-10-22T14:27:15Z</dc:date>
    <item>
      <title>Is this a Legitimate "fist packet isn't SYN drop"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-this-a-Legitimate-quot-fist-packet-isn-t-SYN-drop-quot/m-p/99849#M7796</link>
      <description>&lt;P&gt;We have this transaction that, in this example, startsat 11:00. At 11.02 the remote server tries to close it sending the FIN but the local server tries to close it only half an hour later (at 11.30). This FIN packet gets retransmitted&amp;nbsp; but no ack is sent by the remote server. At last the local server sends a RST&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-10-22 15_08_23-poller - 172.20.3.2 - Connessione Desktop remoto.png" style="width: 785px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8543iA55C1CFC048E1B70/image-dimensions/785x209?v=v2" width="785" height="209" role="button" title="2020-10-22 15_08_23-poller - 172.20.3.2 - Connessione Desktop remoto.png" alt="2020-10-22 15_08_23-poller - 172.20.3.2 - Connessione Desktop remoto.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; My problem here is that those Resets (and sometimes some final FIN ACK packet as well) get blocked by our Checkpoint as a "first packet isn't SYN"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-10-22 15_04_42-poller - 172.20.3.2 - Connessione Desktop remoto.png" style="width: 523px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8544i58A40926C5FA29BC/image-dimensions/523x426?v=v2" width="523" height="426" role="button" title="2020-10-22 15_04_42-poller - 172.20.3.2 - Connessione Desktop remoto.png" alt="2020-10-22 15_04_42-poller - 172.20.3.2 - Connessione Desktop remoto.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this legitimate? the tcp session timeout configured for the firewall is 3600. Is this because those packet are past both side FIN packet and the TCP end timeout is set (by default) at 5 seconds?&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 14:27:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-this-a-Legitimate-quot-fist-packet-isn-t-SYN-drop-quot/m-p/99849#M7796</guid>
      <dc:creator>Stefano_Cappell</dc:creator>
      <dc:date>2020-10-22T14:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Is this a Legitimate "fist packet isn't SYN drop"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-this-a-Legitimate-quot-fist-packet-isn-t-SYN-drop-quot/m-p/100069#M7810</link>
      <description>&lt;P&gt;Seems legit to me, as FIN would start the TCP end timer and remove it from the main connection table.&lt;BR /&gt;As such, it would see that FIN packet 28 mins later as a “new” connection, thus you get the message.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Oct 2020 23:27:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-this-a-Legitimate-quot-fist-packet-isn-t-SYN-drop-quot/m-p/100069#M7810</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-24T23:27:54Z</dc:date>
    </item>
  </channel>
</rss>

