<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Legitimate traffic being blocked - R80.20 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/57902#M87934</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we had the same issue. Solution was to downgrade the gateway (appliance) back to R80.10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2019 11:49:47 GMT</pubDate>
    <dc:creator>ThomasH</dc:creator>
    <dc:date>2019-07-10T11:49:47Z</dc:date>
    <item>
      <title>Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36145#M87924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After migration to R80.20 we are having a legitimate traffic being blocked, filtering via "fw ctl zdebug drop", we receive the following log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; font-size: 13px;"&gt;@;2731325746;[cpu_9];[fw4_2];fw_log_drop_ex: Packet proto=6 x.x.x.x:45242 -&amp;gt; y.y.y.y:443 dropped by fwmultik_process_f2p_cookie_inner Reason: PSL Drop: internal - reject enabled&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; font-size: 13px;"&gt;We opened a SR and passed us the SK33328, which was done but did not work, we still have connection problems sometimes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; font-size: 13px;"&gt;The traffic is from an apache server to an nginx, TCP / 443&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; font-size: 13px;"&gt;Anyone else went through this and could help?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2019 00:03:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36145#M87924</guid>
      <dc:creator>Rafael_Lima1</dc:creator>
      <dc:date>2019-02-27T00:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36146#M87925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sk109777 give the&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33328" target="_blank"&gt;sk33328 - How to clear $FWDIR/state/ directory to resolve policy corruption issues&lt;/A&gt;&amp;nbsp;as the solution. If this has only resolved parts of your issue, the reason could not be file corruption only ! In sk97876, there is a known issue with CP versions &amp;lt;&amp;nbsp;R77.20 - but that is unsuppported by now. What version do you use ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2019 10:46:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36146#M87925</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-02-27T10:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36147#M87926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Running sk33328 has not changed anything in behavior, it is occurring in the same way.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="" data-aura-rendered-by="4463:0"&gt;&lt;SPAN class="" data-aura-class="uiOutputTextArea" data-aura-rendered-by="4453:0"&gt;Environment: &lt;BR /&gt;Check Point's software version R80.20 - Build 255 &lt;BR /&gt;kernel: R80.20 - Build 014 &lt;BR /&gt;JHF Take: 17&lt;BR /&gt;OpenServer R730&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2019 11:20:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36147#M87926</guid>
      <dc:creator>Rafael_Lima1</dc:creator>
      <dc:date>2019-02-27T11:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36148#M87927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then i would involve TAC even more !&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;JHF Take: 17 is the GA from 8.1.19 - current GA is 33, Ongoing Take 47, so that installing a newer Jumbo would be the first suggestion !&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;What do you mean by&amp;nbsp;&lt;SPAN&gt;OpenServer R730 ? R77.30 GWs Jumbo Take ... ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2019 11:57:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36148#M87927</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-02-27T11:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36149#M87928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;PRE class="" data-fulltext="" data-placeholder="Tradução" dir="ltr" style="text-align: left; height: 120px;"&gt;&lt;SPAN lang="en"&gt;We already have SR open, but have a few days without an answer.  No, it's the server model, Dell PowerEdge R730&lt;/SPAN&gt;.&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2019 12:18:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36149#M87928</guid>
      <dc:creator>Rafael_Lima1</dc:creator>
      <dc:date>2019-02-27T12:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36150#M87929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We installed JHF 33, but the problem still continues.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 21:36:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/36150#M87929</guid>
      <dc:creator>Rafael_Lima1</dc:creator>
      <dc:date>2019-03-06T21:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/53919#M87930</link>
      <description>i have the jumbo hotfix accumulator take 47&lt;BR /&gt;but the problem persist</description>
      <pubDate>Mon, 20 May 2019 17:20:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/53919#M87930</guid>
      <dc:creator>Cesar_Almada</dc:creator>
      <dc:date>2019-05-20T17:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/53941#M87931</link>
      <description>&lt;P&gt;Part of your error message is F2P which is "Forward to PSL" in R80.20, which I think is SecureXL dumping the inspection for that connection up to a worker core and it can't.&amp;nbsp; Either this is some kind of bug with handling the connection, or it could be similar to an "instance is fully utilized" situation encountered in R80.10 and earlier like this: &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61143&amp;amp;partition=Advanced&amp;amp;product=CoreXL%22" target="_blank"&gt;sk61143: Traffic is dropped by CoreXL with "fwmultik_inbound_packet_from_dispatcher Reason: Instance is currently fully utilized"&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;What is your CoreXL split (fw ctl affinity -l -r) and do these drops tend to occur when one or more of your Firewall worker/instances are at 100% CPU?&amp;nbsp; You might need more of them if so...&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 22:36:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/53941#M87931</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-05-20T22:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/53946#M87932</link>
      <description>pls open a TAC case to verify</description>
      <pubDate>Mon, 20 May 2019 23:22:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/53946#M87932</guid>
      <dc:creator>tpoole_global</dc:creator>
      <dc:date>2019-05-20T23:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/57399#M87933</link>
      <description>&lt;P&gt;So, what was the resolution here?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 21:23:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/57399#M87933</guid>
      <dc:creator>Chris_Wilson</dc:creator>
      <dc:date>2019-07-03T21:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/57902#M87934</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we had the same issue. Solution was to downgrade the gateway (appliance) back to R80.10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 11:49:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/57902#M87934</guid>
      <dc:creator>ThomasH</dc:creator>
      <dc:date>2019-07-10T11:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/59928#M87935</link>
      <description>&lt;P&gt;I see drops of return trafic similar to this on Jumbo 87. I will open a case now.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 09:34:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/59928#M87935</guid>
      <dc:creator>Rene_Rosenkrant</dc:creator>
      <dc:date>2019-08-09T09:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/60257#M87936</link>
      <description>&lt;P&gt;I have the same issue, R80.20 T47 - Hardware 13800.&lt;/P&gt;&lt;P&gt;I am assuming this starts after the upgrade R77.30 &amp;gt;&amp;gt; R80.20, because a similar (function) firewall with R77.30 does not have this issue but the R77.30 firewall has a very low load, so not 100% sure.&lt;/P&gt;&lt;P&gt;Overall none of the SND / worker CPU's are not showing spikes - firewall is not overloaded.&lt;/P&gt;&lt;P&gt;We were recommended SK150933 - increase value of&amp;nbsp;psl_max_future_segments from 8 to 16G. I want to make sure about this issue before jumping to the solution.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 18:13:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/60257#M87936</guid>
      <dc:creator>Muazzam</dc:creator>
      <dc:date>2019-08-13T18:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/60259#M87937</link>
      <description>&lt;P&gt;Can you share any other update?&lt;/P&gt;&lt;P&gt;Did you look at&amp;nbsp;sk150933?&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 18:53:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/60259#M87937</guid>
      <dc:creator>Muazzam</dc:creator>
      <dc:date>2019-08-13T18:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/60260#M87938</link>
      <description>&lt;P&gt;I opened a case. Running R80.20 we went to Take 87, and then TAC gave us a hotfix - fw1_wrapper_HOTFIX_R80_20_JHF_T87_183_MAIN_GA_FULL.tgz for the fwpslglue_chain Reason: PSL Reject: internal - reject enabled; errors.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 19:04:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/60260#M87938</guid>
      <dc:creator>Chris_Wilson</dc:creator>
      <dc:date>2019-08-13T19:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/60322#M87939</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Does anyone know if this hotfix&amp;nbsp;"&lt;SPAN&gt;fw1_wrapper_HOTFIX_R80_20_JHF_T87_183_MAIN_GA_FULL.tgz"&amp;nbsp;&lt;/SPAN&gt;will be integrated into next released Jumbo hotfix, as I also have this issues with "fwpslglue_chain Reason: PSL Reject: internal - reject enabled" for FTP traffic on R80.20.&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 13:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/60322#M87939</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2019-08-14T13:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/60717#M87940</link>
      <description>&lt;P&gt;IPS-Exceptions "solved" the issue... Increasing the&amp;nbsp;psl_max_future_segments had no positive effect to the droped traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2019 10:35:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/60717#M87940</guid>
      <dc:creator>Radu_Dr</dc:creator>
      <dc:date>2019-08-20T10:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/64465#M87941</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the same problem. R80.20 gateways with take 91. If we disable Anti-Virus blade - everything works.&lt;/P&gt;&lt;P&gt;Exceptions don't work.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2019 13:25:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/64465#M87941</guid>
      <dc:creator>AntonMakarychev</dc:creator>
      <dc:date>2019-10-07T13:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/66779#M87943</link>
      <description>&lt;P&gt;Same problem with fwpslglue and fwmultik_process dropping packets, only our error is due to "internal streaming."&lt;/P&gt;&lt;P&gt;Occurred after R80.20 upgrade, Take 101.&lt;/P&gt;&lt;P&gt;We tried increasing PSL buffer and this only solved the problem for a few days. No antivirus blade is in use. No IPS detects on this "internal streaming" activity are being logged, so I don't see what exception can be added.&lt;/P&gt;&lt;P&gt;We are going to try disabling CoreXL today.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 13:31:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/66779#M87943</guid>
      <dc:creator>bign</dc:creator>
      <dc:date>2019-11-07T13:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Legitimate traffic being blocked - R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/83907#M87944</link>
      <description>&lt;P&gt;Did you fix the issue with that hotfix ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the same error with r80.30 latest GA.&lt;/P&gt;</description>
      <pubDate>Sat, 02 May 2020 16:31:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legitimate-traffic-being-blocked-R80-20/m-p/83907#M87944</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-05-02T16:31:06Z</dc:date>
    </item>
  </channel>
</rss>

