<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dropped or not in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12405#M1973</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The main thing is that it&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;is dropped by IPS - i would start from there ...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:59:06 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-03-11T11:59:06Z</dc:date>
    <item>
      <title>Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12400#M1968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have come across a strange situation where my packets are both Accepted and Dropped at the same time. Can anyone help me determine what is the real outcome ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall Rule:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79969" class="image-2 jive-image" height="19" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79969_pastedImage_112.png" width="800" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Picture was unclear.Updated to clearly see policy has Drop*:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79971_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Output of the log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79968" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79968_pastedImage_111.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Description of the event:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;https Traffic Accepted from&amp;nbsp;&amp;lt;USER NAME&amp;gt; (&amp;lt;username&amp;gt;)(&amp;lt;internal_ip&amp;gt;) to 2.17.117.112 due to TCP segment out of maximum allowed sequence. Packet dropped.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Knowing that i found the packet that is simultaneously both accepted and dropped - I will just leave this here for reference:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://en.wikipedia.org/wiki/Schr%C3%B6dinger%27s_cat" title="https://en.wikipedia.org/wiki/Schr%C3%B6dinger%27s_cat"&gt;Schrödinger's cat - Wikipedia&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:27:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12400#M1968</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2019-03-11T08:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12401#M1969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What i can see is that your Access Rule "Block Crypto Miners" does accept the packet, then it is dropped by IPS Sanity checks ! Maybe&amp;nbsp;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122072&amp;amp;partition=Advanced&amp;amp;product=IPS,"&gt;sk122072: 'TCP &lt;STRONG&gt;out&lt;/STRONG&gt; of Sequence' logs in SmartView Tracker&lt;/A&gt;&amp;nbsp;can help ?&lt;SPAN class="" style="color: #e65785; margin: 0px 0px;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:52:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12401#M1969</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-03-11T09:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12402#M1970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It is accepted by policy but it is dropped by IPS. Are you getting this message continuously or for specific time. One of the reason is high memory usage as well.&lt;/P&gt;&lt;P&gt;SK66576 &amp;amp; SK114529 will be helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:23:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12402#M1970</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2019-03-11T10:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12403#M1971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My mistake - the rule is configured to DROP but this was not clear in the first picture. I corrected.&lt;/P&gt;&lt;P&gt;Yet the logs say Rule 18, descriptions says Accepted. Protection says Dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79972_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:08:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12403#M1971</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2019-03-11T11:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12404#M1972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why is it accepted by the policy when the action on the rule is Drop?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:10:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12404#M1972</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2019-03-11T11:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12405#M1973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The main thing is that it&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;is dropped by IPS - i would start from there ...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:59:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12405#M1973</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-03-11T11:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12406#M1974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this for any specific traffic?&lt;/P&gt;&lt;P&gt;Please run zdebug and fw monitor for more troubleshooting&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:27:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12406#M1974</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2019-03-11T12:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12407#M1975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My issue is that the firewall log for rule 18 says &lt;STRONG&gt;"Accepted"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I can agree that apps can only be detected and classified &lt;STRONG&gt;ONLY&lt;/STRONG&gt; after allowing the connection to be initiated.&lt;/P&gt;&lt;P&gt;Does this mean that the unified policy is misleading? &lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Does this mean that this traffic is passed through the next firewall rules? &lt;STRONG&gt;I don't know&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;My customer is asking me to advise on how to build the ruleset considering that his rules are "avoided". I would agree that if there is an explicit drop, i would much appreciate not seeing any kind of log saying it was allowed as this creates confusion. Especially If the Firewall is claiming my rule 18 matched this traffic -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only supposition i have is that because it's somehow fragmented it cannot be inspected... but still it is accepted and on a rule with Coinhive.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other perculiar thing is that on the same rule i have both this example https traffic and SMTP traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:58:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12407#M1975</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2019-03-11T12:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12408#M1976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would involve TAC - although i would suggest that an Accept here just means that this rule did not match, as then it would drop the packet instead. The message is from IPS, so that is the key here !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:05:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12408#M1976</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-03-11T13:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12409#M1977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly the same suggestion was given by TAC. After reading the SKs i can see that setting this protection to Detect makes it be bypassed by other IPS protections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However my issue is with the log stating Accept.&amp;nbsp;Is this passed to the next rule or simply allowed?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:33:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/12409#M1977</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2019-03-11T20:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/46886#M9094</link>
      <description>&lt;P&gt;1. I am updating with more information. I have tested this signature on different setup, everything works. This means that the app "Coinhive" itself has no issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The rule on this particular SMS/vSEC Gateway has been deleted, policy installed. Re-created, policy installed again. The result is similar:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&amp;nbsp;Traffic is &lt;STRONG&gt;dropped &lt;/STRONG&gt;as intended:&amp;nbsp;&lt;EM&gt;;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=6 10.10.202.44:50534 -&amp;gt; 86.105.182.5:443 dropped by fw_send_log_drop Reason: Rulebase drop - on layer "Network" rule 18;&lt;/EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;There is no log of this happening. Looked historically and things went bad on the 3rd of March when i have the last Application Control log working for this:&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 776px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/49i1061DC68281E735F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;The bogus logs for SMTP Bypass and Accepted HTTPS dropped by Inspection were there all along.&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Example (rule numbe changes as i moved it around):&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/50iAADABF3CFE511079/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;For the SMTP bypass support claims it is sourced by&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120964&amp;amp;partition=General&amp;amp;product=Security#Debug%20Procedures" target="_self"&gt;sk120964&lt;/A&gt;. However i cannot get my head around why would this SMTP bypass log trail around my rule 18 every single time i create or delete&amp;nbsp;it. Why doesn't it pop on rule 10 or 11 or 50?&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;For HTTPS with Accept message and Dropped Description there is no explanation yet. I have checked and inspection settings according to&amp;nbsp;SK66576 &amp;amp; SK114529 , that have been brought&amp;nbsp;into discussion earlier are set to Drop and Log.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;There is no proper Inspection Setting Log and regarding this or i don;t yet know where i would see inspection setting logs, as they seem more part of the firewall rather than IPS starting R80.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Unrelated Note:&lt;/STRONG&gt; The new interface for Check Mates makes editing a complicated mess. It was much better before. Hope it was worth it. I just noticed while trying to make this post. You can't even paste pictures anymore. Let alone "quote" text. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Makes me think it now looks awfully&amp;nbsp;aligned with the new Support Interface. Not everything is supposed to be a feed, sometimes i would like to be able to track my cases by just scrolling&amp;nbsp;down, not having replies in my SR's arranged by "relevance" and "likes". Somebody actually hired some PR/Marketing guys to keep shifting interfaces around?!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 08:54:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/46886#M9094</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2019-03-14T08:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/46893#M9095</link>
      <description>great post I like it a lot ! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Thu, 14 Mar 2019 09:10:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/46893#M9095</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-03-14T09:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped or not</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/46992#M9113</link>
      <description>There should be a "quote" button on the right side of the toolbar. I'll see if we can enable pasting photos into the editor as, I agree, that is quite useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Fri, 15 Mar 2019 04:28:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dropped-or-not/m-p/46992#M9113</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-15T04:28:26Z</dc:date>
    </item>
  </channel>
</rss>

