<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to turn around &amp;quot;ICMPv6 redirect packets are not allowed&amp;quot; messages in the logs ... in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90462#M18089</link>
    <description>Done:&lt;BR /&gt;&lt;BR /&gt;Last login: Fri Jul  3 08:22:07 2020 from .......................::4&lt;BR /&gt;[Expert@cp:0]# fw ctl get int fw_icmp_redirects&lt;BR /&gt;fw_icmp_redirects = 1&lt;BR /&gt;&lt;BR /&gt;*** It still produces 1000s of log entries with (aparently different error!) like:&lt;BR /&gt;&lt;BR /&gt;"ICMPv6 error does not match an existing connection"&lt;BR /&gt;&lt;BR /&gt;so:&lt;BR /&gt;&lt;BR /&gt;before it was:&lt;BR /&gt;&lt;BR /&gt;"ICMPv6 redirect packets are not allowed"&lt;BR /&gt;&lt;BR /&gt;now it is:&lt;BR /&gt;&lt;BR /&gt;"ICMPv6 error does not match an existing connection"&lt;BR /&gt;&lt;BR /&gt;tell me folks it isn't confusing and strange somehow ...</description>
    <pubDate>Fri, 03 Jul 2020 07:33:51 GMT</pubDate>
    <dc:creator>Jerry</dc:creator>
    <dc:date>2020-07-03T07:33:51Z</dc:date>
    <item>
      <title>How to turn around "ICMPv6 redirect packets are not allowed" messages in the logs ...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90392#M18075</link>
      <description>&lt;P&gt;hi chaps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; hope you're doing well and staying safe?&lt;/P&gt;
&lt;P&gt;quick question to our guru's - have you got any clue where-to turn on IPv6 redirects globally?&lt;/P&gt;
&lt;P&gt;please see enclosed, my Customer is being flooded with log messages like this one and would like to ENABLE IPv6 redirection - where about you'd potentially do that or by which file ?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Annotation 2020-07-02 112308.jpg" style="width: 956px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7077i91A724881D28030E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Annotation 2020-07-02 112308.jpg" alt="Annotation 2020-07-02 112308.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;ps. below is all you need to know in advance:&lt;/P&gt;
&lt;P&gt;This is Check Point CPinfo Build 914000202 for GAIA&lt;BR /&gt;[IDA]&lt;BR /&gt;No hotfixes..&lt;/P&gt;
&lt;P&gt;[MGMT]&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 48&lt;/P&gt;
&lt;P&gt;[CPFC]&lt;BR /&gt;No hotfixes..&lt;/P&gt;
&lt;P&gt;[FW1]&lt;BR /&gt;HOTFIX_GOT_TPCONF_MGMT_AUTOUPDATE&lt;BR /&gt;HOTFIX_GOT_TPCONF_AUTOUPDATE&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 48&lt;/P&gt;
&lt;P&gt;FW1 build number:&lt;BR /&gt;This is Check Point Security Management Server R80.40 - Build 019&lt;BR /&gt;This is Check Point's software version R80.40 - Build 088&lt;BR /&gt;kernel: R80.40 - Build 079&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 10:29:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90392#M18075</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2020-07-02T10:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to turn around "ICMPv6 redirect packets are not allowed" messages in the logs ...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90393#M18076</link>
      <description>aparently that splat inheritance does not work any longer ;.;.;&lt;BR /&gt;&lt;BR /&gt;ip redirect enable&lt;BR /&gt;no ip redirect&lt;BR /&gt;&lt;BR /&gt;hence I have no clue where on R80.xx you can turn-on redirects, &lt;BR /&gt;do you?</description>
      <pubDate>Thu, 02 Jul 2020 10:31:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90393#M18076</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2020-07-02T10:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to turn around "ICMPv6 redirect packets are not allowed" messages in the logs ...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90420#M18082</link>
      <description>&lt;P&gt;For IPv4 this behavior is controlled by the&amp;nbsp;&lt;STRONG&gt;fw_icmp_redirects&lt;/STRONG&gt; kernel variable which is set to 0 by default, see&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112772&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk112772: ICMP redirects drop&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I don't see a special IPv6 kernel variable for this, so setting&amp;nbsp;&lt;STRONG&gt;fw_icmp_redirects&lt;/STRONG&gt; to 1 should to the trick for all redirects including IPv6.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 16:56:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90420#M18082</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-07-02T16:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to turn around "ICMPv6 redirect packets are not allowed" messages in the logs ...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90461#M18088</link>
      <description>Thanks Tim, I'll test it and update you due course &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Fri, 03 Jul 2020 07:21:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90461#M18088</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2020-07-03T07:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to turn around "ICMPv6 redirect packets are not allowed" messages in the logs ...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90462#M18089</link>
      <description>Done:&lt;BR /&gt;&lt;BR /&gt;Last login: Fri Jul  3 08:22:07 2020 from .......................::4&lt;BR /&gt;[Expert@cp:0]# fw ctl get int fw_icmp_redirects&lt;BR /&gt;fw_icmp_redirects = 1&lt;BR /&gt;&lt;BR /&gt;*** It still produces 1000s of log entries with (aparently different error!) like:&lt;BR /&gt;&lt;BR /&gt;"ICMPv6 error does not match an existing connection"&lt;BR /&gt;&lt;BR /&gt;so:&lt;BR /&gt;&lt;BR /&gt;before it was:&lt;BR /&gt;&lt;BR /&gt;"ICMPv6 redirect packets are not allowed"&lt;BR /&gt;&lt;BR /&gt;now it is:&lt;BR /&gt;&lt;BR /&gt;"ICMPv6 error does not match an existing connection"&lt;BR /&gt;&lt;BR /&gt;tell me folks it isn't confusing and strange somehow ...</description>
      <pubDate>Fri, 03 Jul 2020 07:33:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90462#M18089</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2020-07-03T07:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to turn around "ICMPv6 redirect packets are not allowed" messages in the logs ...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90492#M18100</link>
      <description>&lt;P&gt;Is it possible that these ICMP redirects are somehow being sent to a broadcast or multicast address?&amp;nbsp; Use &lt;STRONG&gt;tcpdump -e&lt;/STRONG&gt; to check this.&amp;nbsp; If so the firewall would receive the redirects even though they aren't really intended for the firewall and it would have no matching connection.&amp;nbsp; I suppose you could try unchecking the "Drop out of state ICMP" checkbox on the Stateful Inspection screen under Global Properties and see what happens...&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 13:56:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90492#M18100</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-07-03T13:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to turn around "ICMPv6 redirect packets are not allowed" messages in the logs ...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90505#M18105</link>
      <description>&lt;P&gt;&lt;EM&gt;"Is it possible that these ICMP redirects are somehow being sent to a broadcast or multicast address?"&lt;/EM&gt; --- nop, the redirects happens on genuine point-2-point traffic (all IPv6 src/dst based while port remains "redirect6", will try Drop OOS ICMP and let you know. Just going on it and will report back. Concerning ... isn't it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;see enclosed.:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditorJerry_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Annotation 2020-07-03 190534.png" style="width: 880px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7100i916C5F8259B6118C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Annotation 2020-07-03 190534.png" alt="Annotation 2020-07-03 190534.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 18:08:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90505#M18105</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2020-07-03T18:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to turn around "ICMPv6 redirect packets are not allowed" messages in the logs ...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90507#M18106</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Annotation 2020-07-03 191520.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7101i634BCF69460644FC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Annotation 2020-07-03 191520.jpg" alt="Annotation 2020-07-03 191520.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this setup did the trick &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; thanks Tim! it was a good guess though!&lt;/P&gt;
&lt;P&gt;Drops - I don't mind, but 1000s of logs caused by this - no thanks &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have a lovely weekend !&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 18:16:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-turn-around-quot-ICMPv6-redirect-packets-are-not-allowed/m-p/90507#M18106</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2020-07-03T18:16:40Z</dc:date>
    </item>
  </channel>
</rss>

