<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic dropped with message information: &amp;quot;Rulebase Internal Error&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/74075#M83461</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18124"&gt;@Ilmo_Anttonen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you ever get this resolved?&lt;/P&gt;&lt;P&gt;I am having the same issue with R80.30 HFA 111 but only when adding a new rule with an access-role.&lt;/P&gt;&lt;P&gt;Got a TAC case opened with no progress so far.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Tue, 04 Feb 2020 05:36:55 GMT</pubDate>
    <dc:creator>Alex_Shpilman</dc:creator>
    <dc:date>2020-02-04T05:36:55Z</dc:date>
    <item>
      <title>Traffic dropped with message information: "Rulebase Internal Error"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/65305#M83456</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have are having some traffic that is being dropped with the message information: "Rulebase Internal Error"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log.png" style="width: 455px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2769i9D9BEBF376E5736B/image-dimensions/455x364?v=v2" width="455" height="364" role="button" title="log.png" alt="log.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As of yet I have not found any information related to what this message and how it can be remedied.&lt;/P&gt;&lt;P&gt;Normally this traffic should be allowed, but because of the issue, it appears the traffic is being dropped.&lt;/P&gt;&lt;P&gt;Has anyone have any information that might help in resolving this or might aid the invesitgation?&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2019 11:26:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/65305#M83456</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2019-10-18T11:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped with message information: "Rulebase Internal Error"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/65317#M83457</link>
      <description>I suspect a TAC case is in order here.&lt;BR /&gt;What does fw ctl zdebug drop | grep x.y.z.w show? (Where x.y.z.w is the IP in question)</description>
      <pubDate>Fri, 18 Oct 2019 12:41:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/65317#M83457</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-18T12:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped with message information: "Rulebase Internal Error"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/69306#M83458</link>
      <description>&lt;P&gt;I'll pick this up where you left off, since I've observed the same issue. Here's the output of my zdebug:&lt;BR /&gt;&lt;BR /&gt;@;293891;[cpu_1];[fw4_2];[&lt;EM&gt;&amp;lt;internal-IP&amp;gt;&lt;/EM&gt;:34476 -&amp;gt; 194.29.39.27:443] [ERROR]: up_rulebase_should_drop_possible_on_SYN: conn dir 0, &lt;EM&gt;&amp;lt;internal-IP&amp;gt;&lt;/EM&gt;:34476 -&amp;gt; 194.29.39.27:443, IPP 6 required_4_match = 0x4003002, not expected required_4_match = 0x3000;&lt;BR /&gt;@;293891;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=6 &lt;EM&gt;&amp;lt;internal-IP&amp;gt;&lt;/EM&gt;:34476 -&amp;gt; 194.29.39.27:443 dropped by fw_send_log_drop Reason: Rulebase drop - NO MATCH;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;This is my mgmt server and that destination is&amp;nbsp;productservices.checkpoint.com. It cannot pull updates from that IP-address. The mgmt server has two interfaces. One in a mgmt network and the other in a server network. The mgmt network interface is the one on the SmartConsole object. Both interfaces are directly connected to the FW appliance.&lt;/P&gt;&lt;P&gt;The rulebase allows both interfaces to communicate with checkpoint services.&lt;BR /&gt;I want the mgmt server to fetch updates and communicate with checkpoint on the interface in the server network, but it desires to do so over the mgmt interface. On the mgmt serer, I then added a default route with lower prio for the server network interface. That's when it stopped receiving updates because of this "rulebase internal error" drop.&lt;/P&gt;&lt;P&gt;Removing the the route fixes everything, but then I have the original problem again. Does the gateway mess up routing somehow or why is this happening?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know if maybe OP has a similar problem; a host with multiple interfaces.&lt;/P&gt;&lt;P&gt;The environment I'm running here is R80.30 with jhf take 111 on both mgmt and appliance. It's been the same throughout all R80.30 iterations at least.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 12:46:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/69306#M83458</guid>
      <dc:creator>Ilmo_Anttonen</dc:creator>
      <dc:date>2019-12-04T12:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped with message information: "Rulebase Internal Error"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/69371#M83459</link>
      <description>This is definitely TAC case territory as I'm not aware that we should be forcing traffic through a specific interface.</description>
      <pubDate>Thu, 05 Dec 2019 00:09:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/69371#M83459</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-05T00:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped with message information: "Rulebase Internal Error"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/69382#M83460</link>
      <description>&lt;P&gt;Thanks for the input. I'll submit a case once they solve the current case I have with them&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":pensive_face:"&gt;😔&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 07:25:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/69382#M83460</guid>
      <dc:creator>Ilmo_Anttonen</dc:creator>
      <dc:date>2019-12-05T07:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped with message information: "Rulebase Internal Error"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/74075#M83461</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18124"&gt;@Ilmo_Anttonen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you ever get this resolved?&lt;/P&gt;&lt;P&gt;I am having the same issue with R80.30 HFA 111 but only when adding a new rule with an access-role.&lt;/P&gt;&lt;P&gt;Got a TAC case opened with no progress so far.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 05:36:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/74075#M83461</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2020-02-04T05:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped with message information: "Rulebase Internal Error"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/74360#M83462</link>
      <description>&lt;P&gt;Unfortunately I have not yet solved the previous issue with the support so I have not proceeded with this yet. I solved it by just reverting to as it was before. Meaning the traffic to Internet is exiting the wrong way. But thanks for reminidng me, I hade forgotten about this because of the long wait &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 17:31:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/74360#M83462</guid>
      <dc:creator>Ilmo_Anttonen</dc:creator>
      <dc:date>2020-02-06T17:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped with message information: "Rulebase Internal Error"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/103877#M83463</link>
      <description>&lt;P&gt;Dear &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/883"&gt;@Michael_Horne&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How did you resolve this issue? can you please share the solution?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;I&amp;nbsp;am also facing the same issue, have you got any idea regarding the solution to this issue?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please share with us if you have any.&lt;/P&gt;&lt;P&gt;Thank You,&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 15:07:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/103877#M83463</guid>
      <dc:creator>Rabindra_Khadka</dc:creator>
      <dc:date>2020-12-01T15:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped with message information: "Rulebase Internal Error"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/103908#M83464</link>
      <description>&lt;P&gt;Open a TAC case, as suggested previously.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 16:54:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/103908#M83464</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-01T16:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic dropped with message information: "Rulebase Internal Error"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/241743#M83465</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I know this is an old issue. However it is still present in R81.10 Jumbo HFA Take 150 in february 2025.&lt;BR /&gt;We had this issue in the past and TAC could not find the root cause.&lt;BR /&gt;&lt;BR /&gt;we had it on a 64k and "asg_policy verify -v" should correct policy - however an immediate additional policy Install after the error occured only on 1 of 5 SGMs the issue was solved. And it started immediately after the first Policy Install.&lt;BR /&gt;&lt;BR /&gt;So I suspect a Policy Install mechanism error and to solve it another Policy Install helps.&lt;BR /&gt;However this leads to business impact and tells me that this issue is not solved since 2019 undtil 2025.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 08:04:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-dropped-with-message-information-quot-Rulebase-Internal/m-p/241743#M83465</guid>
      <dc:creator>Alexander_Wilke</dc:creator>
      <dc:date>2025-02-20T08:04:26Z</dc:date>
    </item>
  </channel>
</rss>

