<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sqlnet1 Traffic Drop between Oracle hosts on same subnet. error: TCP First packet isn't SYN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/sqlnet1-Traffic-Drop-between-Oracle-hosts-on-same-subnet-error/m-p/64576#M13167</link>
    <description>For a Check Point gateway to accept a TCP connection, one of two things must happen:&lt;BR /&gt;&lt;BR /&gt;1. We need to see the entire TCP session from start to finish&lt;BR /&gt;2. You need to configure the gateway to allow "out-of-state" TCP connections (not recommended for security reasons).&lt;BR /&gt;&lt;BR /&gt;If the traffic is truly on the same VLAN, the security gateway should never see this traffic to begin with.&lt;BR /&gt;Perhaps there is some sort of ARP issue with the database server that is causing it to send traffic to the gateway instead of where it's supposed to go.&lt;BR /&gt;That's where I'd look if I were seeing this.</description>
    <pubDate>Tue, 08 Oct 2019 22:35:48 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-10-08T22:35:48Z</dc:date>
    <item>
      <title>sqlnet1 Traffic Drop between Oracle hosts on same subnet. error: TCP First packet isn't SYN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/sqlnet1-Traffic-Drop-between-Oracle-hosts-on-same-subnet-error/m-p/64563#M13164</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a cluster R80.30 which is being running as a a default gateway for many downstream VLANS.&lt;/P&gt;&lt;P&gt;One of my VLANS host Oracle Applications and Databases. My issue is that i receive the following error when an Oracle App tries to communicate with an Oracle DB &lt;STRONG&gt;on the same VLAN.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TCP packet out of state:First packet isn't SYN&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;TCP Flags: PUSH-ACK&lt;/STRONG&gt;&lt;BR /&gt;Source: 192.168.X1.X1&lt;BR /&gt;Source Port: 43950&lt;BR /&gt;Destination: 192.168.X1.X2&lt;BR /&gt;Destination Port: 1521&lt;BR /&gt;IP Protocol: 6&lt;/P&gt;&lt;P&gt;Blade: Firewall&lt;BR /&gt;Origin: Checkpoint-Core-FW1&lt;BR /&gt;Service: TCP/1521&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 1&lt;BR /&gt;Interface: bond21.X1&lt;BR /&gt;Description: sqlnet1 Traffic Dropped from 192.168.X1.X1 to 192.168.X1.X2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advise?&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 19:08:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/sqlnet1-Traffic-Drop-between-Oracle-hosts-on-same-subnet-error/m-p/64563#M13164</guid>
      <dc:creator>avramidisv</dc:creator>
      <dc:date>2019-10-08T19:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: sqlnet1 Traffic Drop between Oracle hosts on same subnet. error: TCP First packet isn't SYN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/sqlnet1-Traffic-Drop-between-Oracle-hosts-on-same-subnet-error/m-p/64576#M13167</link>
      <description>For a Check Point gateway to accept a TCP connection, one of two things must happen:&lt;BR /&gt;&lt;BR /&gt;1. We need to see the entire TCP session from start to finish&lt;BR /&gt;2. You need to configure the gateway to allow "out-of-state" TCP connections (not recommended for security reasons).&lt;BR /&gt;&lt;BR /&gt;If the traffic is truly on the same VLAN, the security gateway should never see this traffic to begin with.&lt;BR /&gt;Perhaps there is some sort of ARP issue with the database server that is causing it to send traffic to the gateway instead of where it's supposed to go.&lt;BR /&gt;That's where I'd look if I were seeing this.</description>
      <pubDate>Tue, 08 Oct 2019 22:35:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/sqlnet1-Traffic-Drop-between-Oracle-hosts-on-same-subnet-error/m-p/64576#M13167</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-08T22:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: sqlnet1 Traffic Drop between Oracle hosts on same subnet. error: TCP First packet isn't SYN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/sqlnet1-Traffic-Drop-between-Oracle-hosts-on-same-subnet-error/m-p/64585#M13170</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;By chance, are you load balancing your Oracle DB? I just had a customer which Oracle DB load sharing used two host which a different IP each. Fun thing was that both of them could reply to request of the other one and the GW dropped the traffic as out of state.&lt;/P&gt;&lt;P&gt;Do you always see the PUSH-ACK out of state? this flag my suggest time out, you may want to do some packet captures and maybe modify some TCP sessions.&lt;/P&gt;&lt;P&gt;If you cannot find the root cause of your issue I highly suggest to solutions from this post:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Management-Topics/Disabling-out-of-state-checks-between-certain-hosts/td-p/16022" target="_self"&gt;Disabling 'out of state' checks between certain hosts&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Never ever disable stateful inspectin completly.&lt;/P&gt;&lt;P&gt;Hope it helps&lt;/P&gt;&lt;P&gt;______&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 02:44:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/sqlnet1-Traffic-Drop-between-Oracle-hosts-on-same-subnet-error/m-p/64585#M13170</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-10-09T02:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: sqlnet1 Traffic Drop between Oracle hosts on same subnet. error: TCP First packet isn't SYN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/sqlnet1-Traffic-Drop-between-Oracle-hosts-on-same-subnet-error/m-p/64620#M13178</link>
      <description>&lt;P&gt;Thank you all for your advises.&lt;/P&gt;&lt;P&gt;It turned out that one of the machines had a&amp;nbsp; wrong subnet mask configured so the communication was directed through the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem solved.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 11:14:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/sqlnet1-Traffic-Drop-between-Oracle-hosts-on-same-subnet-error/m-p/64620#M13178</guid>
      <dc:creator>avramidisv</dc:creator>
      <dc:date>2019-10-09T11:14:27Z</dc:date>
    </item>
  </channel>
</rss>

