<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RFC 7413 TCP fast open in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/TCP-Fast-Open/m-p/71018#M14388</link>
    <description>Note I merged your question with another similar thread.&lt;BR /&gt;Short answer: it appears it is not supported since SYN packets with data (needed for TCP Fast Open) would be dropped.</description>
    <pubDate>Fri, 20 Dec 2019 20:46:29 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-12-20T20:46:29Z</dc:date>
    <item>
      <title>TCP Fast Open</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-Fast-Open/m-p/70985#M14382</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have recently been doing some research into the experimental TCP mechanism called 'TCP Fast Open'.&amp;nbsp; I wondered how Checkpoint deals with this traffic? Does the traffic get dropped because it does not comply with the TCP 3 way handshake mechanism because there is 'data' attached to the SYN.&lt;/P&gt;&lt;P&gt;I can see on the Internet that some other firewall vendors have some information/guidelines/suggestions on how 'they' deal with with this feature/setting; are there any plans to create similar documentation for Check Point?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Paul Norman&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2019 12:08:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-Fast-Open/m-p/70985#M14382</guid>
      <dc:creator>pnorman821</dc:creator>
      <dc:date>2019-12-20T12:08:05Z</dc:date>
    </item>
    <item>
      <title>RFC 7413 TCP fast open</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-Fast-Open/m-p/70976#M14387</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Any support for RFC 7413 TCP fast open on Checkpoint Firewalls?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2019 10:05:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-Fast-Open/m-p/70976#M14387</guid>
      <dc:creator>whitey</dc:creator>
      <dc:date>2019-12-20T10:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Fast Open</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-Fast-Open/m-p/70989#M14383</link>
      <description>&lt;P&gt;sorry I have just realised I have posted this to the wrong board - could it please be moved to the correct place?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2019 13:04:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-Fast-Open/m-p/70989#M14383</guid>
      <dc:creator>pnorman821</dc:creator>
      <dc:date>2019-12-20T13:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Fast Open</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-Fast-Open/m-p/71014#M14385</link>
      <description>&lt;P&gt;Not sure how the gateway would differentiate a legit TCP Fast Open from an illegitimate one, given the cryptographic nature of it.&lt;BR /&gt;I suspect (but don’t know for sure) that the initial SYN would be allowed but until the three way handshake completed, the data packets would be dropped due to “Out of State.”&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Edit:&lt;/STRONG&gt;&amp;nbsp;it appears, per some TAC cases, that we will drop SYN packets that include data, which means TCP Fast Open won’t be supported.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2019 19:19:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-Fast-Open/m-p/71014#M14385</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-20T19:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: RFC 7413 TCP fast open</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-Fast-Open/m-p/71018#M14388</link>
      <description>Note I merged your question with another similar thread.&lt;BR /&gt;Short answer: it appears it is not supported since SYN packets with data (needed for TCP Fast Open) would be dropped.</description>
      <pubDate>Fri, 20 Dec 2019 20:46:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-Fast-Open/m-p/71018#M14388</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-20T20:46:29Z</dc:date>
    </item>
  </channel>
</rss>

