<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICMP reply does not match a previous request in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/ICMP-reply-does-not-match-a-previous-request/m-p/62794#M12719</link>
    <description>&lt;DIV&gt;If SmartView Tracker shows that ICMP packets are dropped with "message_info: ICMP reply does not match a previous request" log.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;This drop is related to stateful inspection of ICMP. Due to a mismatch between the ID of ICMP Reply and the ID of the original recorded ICMP Request, Security Gateway will not find the original ICMP Request in the Connections table (id 8158) and will drop this ICMP Reply packet&amp;nbsp;as out-of-state.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Try to find out why the replying device (or what forwarding device) is changing the ID in the ICMP Reply packet.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;As an immediate solution or workaround, disable the Stateful Inspection for ICMP to allow this traffic:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;In SmartDashboard, go to the&amp;nbsp;Policy&amp;nbsp;menu - click on the&amp;nbsp;Global Properties....&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In the left tree, click on the&amp;nbsp;Stateful Inspection.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Clear the box "Drop out of state ICMP packets" - click on OK&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;Install Policy&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Note: Disabling the Stateful Inspection will lower the security. This should be done with caution and only as the last resort.&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Sun, 15 Sep 2019 09:49:30 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2019-09-15T09:49:30Z</dc:date>
    <item>
      <title>ICMP reply does not match a previous request</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ICMP-reply-does-not-match-a-previous-request/m-p/62792#M12718</link>
      <description>&lt;P&gt;Hello friends,&lt;/P&gt;&lt;P&gt;I have multicast topology like this:&lt;/P&gt;&lt;P&gt;Router1(receiver multicast)------&amp;gt;Checkpoint R80-------&amp;gt;Router2-----Router3(Multicast sender)&lt;/P&gt;&lt;P&gt;All devices run PIM-SM mode.&lt;/P&gt;&lt;P&gt;On router1: I join group 239.9.9.9&lt;/P&gt;&lt;P&gt;On router2: ping to 239.9.9.9&lt;/P&gt;&lt;P&gt;Result: Not success&lt;/P&gt;&lt;P&gt;I check log on firewall and see that this error&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="multicast.png" style="width: 802px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2531iF69A1D3BB0BBE231/image-size/large?v=v2&amp;amp;px=999" role="button" title="multicast.png" alt="multicast.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me&lt;/P&gt;&lt;P&gt;Thanks a alot!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 07:31:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ICMP-reply-does-not-match-a-previous-request/m-p/62792#M12718</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2019-09-15T07:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP reply does not match a previous request</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ICMP-reply-does-not-match-a-previous-request/m-p/62794#M12719</link>
      <description>&lt;DIV&gt;If SmartView Tracker shows that ICMP packets are dropped with "message_info: ICMP reply does not match a previous request" log.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;This drop is related to stateful inspection of ICMP. Due to a mismatch between the ID of ICMP Reply and the ID of the original recorded ICMP Request, Security Gateway will not find the original ICMP Request in the Connections table (id 8158) and will drop this ICMP Reply packet&amp;nbsp;as out-of-state.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Try to find out why the replying device (or what forwarding device) is changing the ID in the ICMP Reply packet.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;P&gt;As an immediate solution or workaround, disable the Stateful Inspection for ICMP to allow this traffic:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;In SmartDashboard, go to the&amp;nbsp;Policy&amp;nbsp;menu - click on the&amp;nbsp;Global Properties....&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In the left tree, click on the&amp;nbsp;Stateful Inspection.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Clear the box "Drop out of state ICMP packets" - click on OK&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;Install Policy&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Note: Disabling the Stateful Inspection will lower the security. This should be done with caution and only as the last resort.&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sun, 15 Sep 2019 09:49:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ICMP-reply-does-not-match-a-previous-request/m-p/62794#M12719</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-09-15T09:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP reply does not match a previous request</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ICMP-reply-does-not-match-a-previous-request/m-p/62795#M12720</link>
      <description>&lt;P&gt;Tks heiko a lot.&lt;/P&gt;&lt;P&gt;I do as your comment, ping now is OK,&lt;/P&gt;&lt;P&gt;one more question: if I set static NAT on firewall: IP router1--&amp;gt;translate to a.b.c.d&lt;/P&gt;&lt;P&gt;, when router1(multicast receiver) send "IGMP join" packet through firewall, I see that static nat does not work ( the source IP is not translated to a.b.c.d)&lt;/P&gt;&lt;P&gt;so i think checkpoint not support nat in multicast? Is this true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 10:15:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ICMP-reply-does-not-match-a-previous-request/m-p/62795#M12720</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2019-09-15T10:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP reply does not match a previous request</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ICMP-reply-does-not-match-a-previous-request/m-p/62823#M12732</link>
      <description>Not supported.&lt;BR /&gt;See: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk157854" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk157854&lt;/A&gt;</description>
      <pubDate>Mon, 16 Sep 2019 00:13:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ICMP-reply-does-not-match-a-previous-request/m-p/62823#M12732</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-16T00:13:54Z</dc:date>
    </item>
  </channel>
</rss>

