<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stateful Inspection Override in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-Override/m-p/56613#M11399</link>
    <description>&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk147093" target="_self"&gt;sk147093 - Security Gateway drops out of state TCP packets even though the option is disabled&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jun 2019 09:43:08 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2019-06-25T09:43:08Z</dc:date>
    <item>
      <title>Stateful Inspection Override</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-Override/m-p/56611#M11397</link>
      <description>&lt;P&gt;A customer has a video conference system which keeps disconnecting.&amp;nbsp; At the time of the disconnections, the firewall logs show a couple of "out of state" drops, then it carries on normally again for a while, then a few more "out of state" drops.&lt;/P&gt;&lt;P&gt;The drops are always only on port TCP 2776.&lt;/P&gt;&lt;P&gt;There is also tons of working/allowed traffic between the SRC and DST on TCP 2776.&lt;/P&gt;&lt;P&gt;I've created a custom service for TCP 2776 and extended the Virtual Session Timeout to the max of&amp;nbsp;86400.&amp;nbsp; This hasn't fixed it.&lt;/P&gt;&lt;P&gt;Next, in an attempt to prove the point that it is actually out of state I've tried to turn off stateful inspection for the video conference IP's.&amp;nbsp; I've inserted the following in to $FWDIR/conf/user.def.FW:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;/* Start of INSPECT modification - sk11088 */
deffunc user_accept_non_syn() { (src=192.168.1.189) or (src=192.168.1.190) and (dport = 2776) };
/* End of INSPECT modification */&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This hasn't fixed it either.&amp;nbsp; Same disconnections and drops in the&amp;nbsp; log.&lt;/P&gt;&lt;P&gt;Does anyone have any other ideas to try before I tell the customer there's nothing else I can do on the firewall (e.g. go fix your VC system!)?&lt;/P&gt;&lt;P&gt;(I haven't disabled SecureXL yet - maybe I should try that?)&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 09:22:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-Override/m-p/56611#M11397</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2019-06-25T09:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection Override</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-Override/m-p/56613#M11399</link>
      <description>&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk147093" target="_self"&gt;sk147093 - Security Gateway drops out of state TCP packets even though the option is disabled&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 09:43:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-Override/m-p/56613#M11399</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2019-06-25T09:43:08Z</dc:date>
    </item>
  </channel>
</rss>

