<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet is dropped. I do not know why is reason. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/92526#M88336</link>
    <description>&lt;P&gt;We had similar behaviour while upgrading a 4-node VSX cluster from R80.10 to R80.30 with HFA Take 214 last week.&lt;/P&gt;&lt;P&gt;ICMP were passing the gateways whithout any flaw but at least TCP connections were dropped with "dropped by fw_send_log_drop Reason: Rulebase drop - NO MATCH;". No Logs in SmartLog. After re-installing all policies on all virtual systems, the problem disappeared. With an unplanned outage of more than one hour.&lt;/P&gt;&lt;P&gt;I opened a support ticket but the root cause could not be found.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jul 2020 13:10:41 GMT</pubDate>
    <dc:creator>Marc_Suelzle</dc:creator>
    <dc:date>2020-07-27T13:10:41Z</dc:date>
    <item>
      <title>Packet is dropped. I do not know why is reason.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/33274#M88328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi CP engineers !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test environment&lt;/P&gt;&lt;P&gt;Version : MGMT(R80.20), FW(R80.10), Both not JHF&lt;/P&gt;&lt;P&gt;model : MGMT(Dell Openserver), FW(SG5x00)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am very odd experience packet drop on CheckPoint firewall.&lt;/P&gt;&lt;P&gt;1. I made a rule to pass the packet.&lt;/P&gt;&lt;P&gt;2. I also made a manual NAT rule to translate the packet.&lt;/P&gt;&lt;P&gt;3. when I execute the command "fw ctl zdebug + drop, fw monitor -e" , saw the packet is dropped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below it is that Things I've done. (Rule number is example)&lt;/P&gt;&lt;P&gt;1. When tested only with Manual NAT, the packet is dropped.&lt;/P&gt;&lt;P&gt;-&amp;gt; Manual NAT Rule 10&lt;/P&gt;&lt;P&gt;2. when I added the rule Automatic NAT and deleted Manual NAT, packet was passed.&lt;/P&gt;&lt;P&gt;-&amp;gt; Because of Automatic NAT Rule 20, no Manual NAT exist&lt;/P&gt;&lt;P&gt;3. when I added Manual NAT same with automatic NAT, packet was passed.&lt;/P&gt;&lt;P&gt;-&amp;gt; Only Manual NAT (NAT Rule 10), Automatic NAT (NAT Rule 20)&lt;/P&gt;&lt;P&gt;Packet is passed because of NAT Rule 10(Manual NAT)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I added only Manual NAT, I think the action have to be running well. But if the automatic NAT does not exist, Manual NAT is not running and the packet is dropped because of No MATCH rule. I do not know why is reason.&lt;/P&gt;&lt;P&gt;I upload the file zdebug result and NAT table.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2019 05:09:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/33274#M88328</guid>
      <dc:creator>DaeGyu_Kyoung</dc:creator>
      <dc:date>2019-02-14T05:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Packet is dropped. I do not know why is reason.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/33275#M88329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try this capture, then you will see where its dropt&lt;BR /&gt;#fw monitor -e "(src=10.10.10.10) or (dst=10.10.10.10),accept;" -p all&lt;BR /&gt;if oyu whant to excam it in wireshark or some other you can add the line under to make the output to a file&lt;/P&gt;&lt;P&gt;-o /tmp/capture.cap&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2019 08:11:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/33275#M88329</guid>
      <dc:creator>Tor-Erik_Ones</dc:creator>
      <dc:date>2019-02-14T08:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: Packet is dropped. I do not know why is reason.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/33276#M88330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;but drop reason are Roulebased drop - NO MATCH. So how does you firewall roule look like, are you using your internal IP adress or are you using your NAT adress?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW&lt;BR /&gt;If its not matching any roules... don't you have a cleanup roule? as far that i know its recomanded and bestpractice (or atleast it was, unsure if it changed in R80...)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2019 08:23:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/33276#M88330</guid>
      <dc:creator>Tor-Erik_Ones</dc:creator>
      <dc:date>2019-02-14T08:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Packet is dropped. I do not know why is reason.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/33277#M88331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A cleanup rule is still added in R80.x, though whether it is an "Accept" or "Drop" depends on how the layer is configured.&lt;/P&gt;&lt;P&gt;Further, if you do not have an explicit cleanup rule, you will see the "implicit" cleanup rule show up as a comment at the end of the rulebase with a note the traffic will NOT be logged.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2019 04:18:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/33277#M88331</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-15T04:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: Packet is dropped. I do not know why is reason.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/33278#M88332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rule exists about the packet on the number 20.&lt;/P&gt;&lt;P&gt;I make a rule &lt;STRONG&gt;internal IP.&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2019 04:47:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/33278#M88332</guid>
      <dc:creator>DaeGyu_Kyoung</dc:creator>
      <dc:date>2019-02-18T04:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Packet is dropped. I do not know why is reason.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/84171#M88333</link>
      <description>&lt;P&gt;I was also dealing with this error today and stumbled on this thread. I didn't find the answer but thought I would share how I resolved it.&lt;/P&gt;&lt;P&gt;The symptom was there was nothing in the logs for some connections after instaling JHFA T191 on R80.30 appliance. fw ctl zdebug drop | grep x.y.z.a revealed this drop reason.&lt;/P&gt;&lt;P&gt;@;1281124;[cpu_0];[fw4_1];fw_log_drop_ex: Packet proto=6 x.y.z.a:60458 -&amp;gt; x.y.z.a:443 dropped by fw_send_log_drop Reason: Rulebase drop - NO MATCH;&lt;/P&gt;&lt;P&gt;The fix was simple: Policy install on the gateway.&lt;/P&gt;&lt;P&gt;Borut&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 08:38:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/84171#M88333</guid>
      <dc:creator>Borut</dc:creator>
      <dc:date>2020-05-05T08:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: Packet is dropped. I do not know why is reason.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/85475#M88334</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;I have just updated from R80.30 GA 155 take to R80.30 GA 191 take and noticed the same behaviour as Borut&lt;BR /&gt;&lt;BR /&gt;@;815760;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=6 y.y.y.y:18732 -&amp;gt; x.x.x.x:443 dropped by fw_send_log_drop Reason: Rulebase drop - NO MATCH;&lt;/P&gt;&lt;P&gt;After I pushed policy out all packets being matched in their respective rules.&lt;/P&gt;</description>
      <pubDate>Sat, 16 May 2020 18:31:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/85475#M88334</guid>
      <dc:creator>FelipeTropeia</dc:creator>
      <dc:date>2020-05-16T18:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Packet is dropped. I do not know why is reason.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/91739#M88335</link>
      <description>&lt;P&gt;We experience same behavor yesterday upgrading a customr Cluster from R80.10 to R80.30 HF 196. We had to reinstall policies to get it right.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any clues as to what may be causing this behavior?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 18:40:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/91739#M88335</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2020-07-16T18:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Packet is dropped. I do not know why is reason.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/92526#M88336</link>
      <description>&lt;P&gt;We had similar behaviour while upgrading a 4-node VSX cluster from R80.10 to R80.30 with HFA Take 214 last week.&lt;/P&gt;&lt;P&gt;ICMP were passing the gateways whithout any flaw but at least TCP connections were dropped with "dropped by fw_send_log_drop Reason: Rulebase drop - NO MATCH;". No Logs in SmartLog. After re-installing all policies on all virtual systems, the problem disappeared. With an unplanned outage of more than one hour.&lt;/P&gt;&lt;P&gt;I opened a support ticket but the root cause could not be found.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 13:10:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Packet-is-dropped-I-do-not-know-why-is-reason/m-p/92526#M88336</guid>
      <dc:creator>Marc_Suelzle</dc:creator>
      <dc:date>2020-07-27T13:10:41Z</dc:date>
    </item>
  </channel>
</rss>

