<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: upgrading security gateways in a cluster from R77.30 to R80.20 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/60655#M12290</link>
    <description>I saw a similar problem with terminal services, are there any symptom occurred on sk147093?&lt;BR /&gt;&lt;BR /&gt;Kernel debug (fw ctl zdebug + drop) shows the following packet drops:&lt;BR /&gt;[DATE TIME];[kern];[tid_0];[SIM-206609312];update_tcp_state: invalid state detected (current state: 0x10000, th_flags=0x14, cdir=1) -&amp;gt; dropping packet, conn: [&amp;lt;SrouceIP,SourcePort,DestinationIP,DestinationPort,6&amp;gt;][PPK0];&lt;BR /&gt;[DATE TIME];[kern];[tid_0];[SIM-206609312];do_inbound: Possible TCP state violation for &amp;lt;SrouceIP,SourcePort,DestinationIP,DestinationPort,6&amp;gt; -&amp;gt; dropping packet ;&lt;BR /&gt;[DATE TIME];[kern];[tid_0];[SIM-206609312];do_packet_finish: SIMPKT_IN_DROP vsid=10, conn:&amp;lt;SrouceIP,SourcePort,DestinationIP,DestinationPort,6&amp;gt;;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Issue does not replicate when SecureXL is off.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Mon, 19 Aug 2019 18:12:55 GMT</pubDate>
    <dc:creator>HelioLeite</dc:creator>
    <dc:date>2019-08-19T18:12:55Z</dc:date>
    <item>
      <title>upgrading security gateways in a cluster from R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/60649#M12285</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have upgraded my cluster R77.30 to R80.20 last week and I faced an issue after upgrading as follow:&lt;/P&gt;&lt;P&gt;Unix server couldn`t send files to FTP server via FTP passive mode and after 2, 3 hours troubleshooting I disabled the SecureXL and issue resolved so do you have any suggestion or thought?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 16:59:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/60649#M12285</guid>
      <dc:creator>Kamiar_Sh</dc:creator>
      <dc:date>2019-08-19T16:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: upgrading security gateways in a cluster from R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/60651#M12287</link>
      <description>are there asymmetric traffic in this environment or Anti-Virus or IPS blade enabled in this environment to inspect FTP traffic?</description>
      <pubDate>Mon, 19 Aug 2019 17:15:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/60651#M12287</guid>
      <dc:creator>HelioLeite</dc:creator>
      <dc:date>2019-08-19T17:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: upgrading security gateways in a cluster from R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/60652#M12288</link>
      <description>&lt;P&gt;after upgrading IPS was enabled but his act was only detect then I disabled it for time being&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 17:24:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/60652#M12288</guid>
      <dc:creator>Kamiar_Sh</dc:creator>
      <dc:date>2019-08-19T17:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: upgrading security gateways in a cluster from R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/60655#M12290</link>
      <description>I saw a similar problem with terminal services, are there any symptom occurred on sk147093?&lt;BR /&gt;&lt;BR /&gt;Kernel debug (fw ctl zdebug + drop) shows the following packet drops:&lt;BR /&gt;[DATE TIME];[kern];[tid_0];[SIM-206609312];update_tcp_state: invalid state detected (current state: 0x10000, th_flags=0x14, cdir=1) -&amp;gt; dropping packet, conn: [&amp;lt;SrouceIP,SourcePort,DestinationIP,DestinationPort,6&amp;gt;][PPK0];&lt;BR /&gt;[DATE TIME];[kern];[tid_0];[SIM-206609312];do_inbound: Possible TCP state violation for &amp;lt;SrouceIP,SourcePort,DestinationIP,DestinationPort,6&amp;gt; -&amp;gt; dropping packet ;&lt;BR /&gt;[DATE TIME];[kern];[tid_0];[SIM-206609312];do_packet_finish: SIMPKT_IN_DROP vsid=10, conn:&amp;lt;SrouceIP,SourcePort,DestinationIP,DestinationPort,6&amp;gt;;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Issue does not replicate when SecureXL is off.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 19 Aug 2019 18:12:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/60655#M12290</guid>
      <dc:creator>HelioLeite</dc:creator>
      <dc:date>2019-08-19T18:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: upgrading security gateways in a cluster from R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/60766#M12318</link>
      <description>Anytime disabling SecureXL "solves" a problem, open a TAC case.</description>
      <pubDate>Tue, 20 Aug 2019 17:49:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/60766#M12318</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-08-20T17:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: upgrading security gateways in a cluster from R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/66712#M13684</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I want to share the solution that fixed my issue:&lt;/P&gt;&lt;P&gt;# fw ctl set int asm_allow_syn_with_data 1&lt;/P&gt;&lt;P&gt;but if you want it as permanent solution&amp;nbsp; the kernel file should be modified and gateway should be rebooted&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 19:16:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/upgrading-security-gateways-in-a-cluster-from-R77-30-to-R80-20/m-p/66712#M13684</guid>
      <dc:creator>Kamiar_Sh</dc:creator>
      <dc:date>2019-11-06T19:16:53Z</dc:date>
    </item>
  </channel>
</rss>

