<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R80.30 and HFA 195 - TCP state logging stopped working in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86624#M17379</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;after update from R80.30 HFA140 to R80.30 HFA195 I see that TCP state logging stopped working. In logs I see just &lt;SPAN&gt;“SYN sent” even if the TCP session is successful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to disable Secure XL (fwaccel off) and that resolves the issue. Problem is that in R80.30 option to disable SecureXl permanently simply doesn`t exist. Do you have any idea how to disable SecureXL permanently or have correct tcp state logging with SexureXL enabled? I would like to have working TCP state logging all the time which is crucial during quick troubleshooting basing on Smartlog (instead of packet capture). Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/BR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;MK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 May 2020 15:31:52 GMT</pubDate>
    <dc:creator>Maciej_Krol</dc:creator>
    <dc:date>2020-05-28T15:31:52Z</dc:date>
    <item>
      <title>R80.30 and HFA 195 - TCP state logging stopped working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86624#M17379</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;after update from R80.30 HFA140 to R80.30 HFA195 I see that TCP state logging stopped working. In logs I see just &lt;SPAN&gt;“SYN sent” even if the TCP session is successful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to disable Secure XL (fwaccel off) and that resolves the issue. Problem is that in R80.30 option to disable SecureXl permanently simply doesn`t exist. Do you have any idea how to disable SecureXL permanently or have correct tcp state logging with SexureXL enabled? I would like to have working TCP state logging all the time which is crucial during quick troubleshooting basing on Smartlog (instead of packet capture). Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/BR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;MK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 15:31:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86624#M17379</guid>
      <dc:creator>Maciej_Krol</dc:creator>
      <dc:date>2020-05-28T15:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 and HFA 195 - TCP state logging stopped working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86627#M17380</link>
      <description>We removed the ability to permanently disable SecureXL in R80.20.&lt;BR /&gt;If the solution to your problem involves disabling SecureXL, it's a bug and you should open a TAC case.</description>
      <pubDate>Thu, 28 May 2020 16:30:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86627#M17380</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-28T16:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 and HFA 195 - TCP state logging stopped working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86628#M17381</link>
      <description>&lt;P&gt;Thank you for the quick reply PhoneBoy. I`ve opened a case 22nd of May (just after an upgrade), but unfortunately I have to say that support is not very responsive :\. Support "ping-pong" as usual, no quick hints at all. If you could help regarding this then I can provide you a service request number. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 16:37:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86628#M17381</guid>
      <dc:creator>Maciej_Krol</dc:creator>
      <dc:date>2020-05-28T16:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 and HFA 195 - TCP state logging stopped working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86646#M17386</link>
      <description>Can you send me the TAC SR in a PM?&lt;BR /&gt;I'll have someone look at it.</description>
      <pubDate>Thu, 28 May 2020 20:15:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86646#M17386</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-28T20:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 and HFA 195 - TCP state logging stopped working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86661#M17390</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;, I`ve sent the SR number in a PM, Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 21:58:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86661#M17390</guid>
      <dc:creator>Maciej_Krol</dc:creator>
      <dc:date>2020-05-28T21:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 and HFA 195 - TCP state logging stopped working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86692#M17399</link>
      <description>&lt;P&gt;There are two options:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk162492" target="_blank"&gt;sk162492&lt;/A&gt;&amp;nbsp;or&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468" target="_blank"&gt;sk104468&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 07:34:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86692#M17399</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-05-29T07:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 and HFA 195 - TCP state logging stopped working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86703#M17400</link>
      <description>&lt;P&gt;Hi Valeri,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I`ve a quite simple scenario for testing this.&amp;nbsp; I`ve a tool which periodically does "telnet 1.2.3.4 443" over IPSEC tunnel to ensure that this is up. Source address is NAT`ed. The issue is very easy to replicate:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;GW1&amp;gt; fwaccel stat&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;|Id|Name |Status |Interfaces |Features |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;|0 |SND |disabled |eth1,eth2,eth3,Mgmt |Acceleration,Cryptography |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;| | | | |SHA1,NULL,3DES,DES,CAST, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;| | | | |CAST-40,AES-128,AES-256,ESP, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;| | | | |LinkSelection,DynamicVPN, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;| | | | |NatTraversal,AES-XCBC,SHA256 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;Accept Templates : enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;Drop Templates : disabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;NAT Templates : enabled&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Smartlog for the connection try:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Tcp State&amp;nbsp; &amp;nbsp; Both FIN&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;GW1&amp;gt; fwaccel on&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;SecureXL device enabled.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;GW1&amp;gt; fwaccel stat&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;|Id|Name |Status |Interfaces |Features |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;|0 |SND |enabled |eth1,eth2,eth3,Mgmt |Acceleration,Cryptography |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;| | | | |SHA1,NULL,3DES,DES,CAST, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;| | | | |CAST-40,AES-128,AES-256,ESP, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;| | | | |LinkSelection,DynamicVPN, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;| | | | |NatTraversal,AES-XCBC,SHA256 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;Accept Templates : enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;Drop Templates : disabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#339966"&gt;NAT Templates : enabled&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Smartlog for the connection try:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;Tcp State&amp;nbsp; &amp;nbsp; SYN sent&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Of course after "fwaccel on"&amp;nbsp;"telnet 1.2.3.4 443" is still successful, just Tcp State logging doesn`t show correct TCP state.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Case related to 1.2.3.4 is not just single address issue. When SecureXL is enabled we have problems with correct TCP state logging regarding many connections.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;thank you for the suggestions. I`ve reviewed the SK`s.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;sk162492&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Disabling the SecureXL immediately resolves the issue which in my opinion confirms that there is bug in HFA195. In HFA140 TCP state logging worked correctly with SecureXL enabled.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;sk104468&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;I would like to have correct TCP state logging for all traffic. I suspect that SecureXL exception for 0.0.0.0/0 is probably not a good idea?&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 10:10:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86703#M17400</guid>
      <dc:creator>Maciej_Krol</dc:creator>
      <dc:date>2020-05-29T10:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 and HFA 195 - TCP state logging stopped working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86707#M17401</link>
      <description>&lt;P&gt;1. If disabling acceleration fixed the issue, open TAC case at once.&lt;/P&gt;
&lt;P&gt;2. No, not a good idea at all &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 10:20:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86707#M17401</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-05-29T10:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: R80.30 and HFA 195 - TCP state logging stopped working</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86710#M17402</link>
      <description>&lt;P&gt;Sure, I opened a case just after upgrade to HFA195 on 22nd of May, but for now there is no resolution.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 10:42:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-30-and-HFA-195-TCP-state-logging-stopped-working/m-p/86710#M17402</guid>
      <dc:creator>Maciej_Krol</dc:creator>
      <dc:date>2020-05-29T10:42:10Z</dc:date>
    </item>
  </channel>
</rss>

