<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Some traffic is being prevented but it looks like it's getting through on logs in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105580#M20249</link>
    <description>&lt;P&gt;Some further screenshots and log output&lt;/P&gt;</description>
    <pubDate>Wed, 16 Dec 2020 10:25:26 GMT</pubDate>
    <dc:creator>rmothers</dc:creator>
    <dc:date>2020-12-16T10:25:26Z</dc:date>
    <item>
      <title>Some traffic is being prevented but it looks like it's getting through on logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105563#M20245</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I have a deployment of 2 x 5400 Checkpoint Appliances in HA pair running R80.40 and no separate management server (yet).&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;I have just deployed these firewalls to replace a pair of 4400 appliances which are end of life and would not upgrade.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;SPAN&gt;I'm seeing some rather strange behaviour with certain traffic across these firewalls.&amp;nbsp; I have attached an overview of the network topology.&amp;nbsp; Each LAN (1-7) is connected to a VLAN interface which is set as a cluster, the topology is set&amp;nbsp; as 'This Network (Internal) with specific subnets that reside within and beyond the individual LANs (LAN 1 for example has itself and a second class C network) &lt;/SPAN&gt;&lt;SPAN&gt;identified as a network group; the security zone is set to 'user defined' and anti spoofing is set Prevent and Log.&amp;nbsp; The CONFIG LAN interface is a cluster, its topology is external and set to lead to Internet (although it doesn't go to the internet itself it routes through to Corporate via another set of firewalls), the security zone is user defined and topology is set to detect and log.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;SPAN&gt;In the LAN identified as CONFIG LAN I have an Active Directory (AD) with 2 way trusts down to each AD in the individual LANs.&amp;nbsp; When I route the traffic between the CONFIG LAN and any of the other individual LANs through these Checkpoints the trusts can no longer validate and DNS cannot resolve a ping to any of the individual LANs.&amp;nbsp; The logs do show the DNS request passing across the Checkpoints.&amp;nbsp; However, this trust was established and working on the recently decommissioned firewalls. An IP to IP ping works without issue as does tracert.&amp;nbsp; I have one or two other applications which exhibit the same behaviour (LAN 5 to LAN 7 on TCP port 8100 - can see it in the logs but the devices at each end aren't able to communicate).&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;SPAN&gt;As part of the swap out I implemented some temporary firewalls to route the Information LAN traffic away from the Checkpoints so there was no interruption to that particular traffic flow.&amp;nbsp; I am able to route the AD Trust traffic across the temporary firewall setup with no issue.&amp;nbsp; However, there is no redundancy or resiliency within that temporary setup and the devices have very poor logging facility.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;SPAN&gt;I replicated the set up on the 4400s to the 5400s with a bit of rule tidying (obsolete rules removed and objects grouped appropriately) see screen capture attached - I'm just looking for places to start to investigate really so any suggestions will be welcome.&amp;nbsp; Waiting for support provider to get back to me as well.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I have tried opening the rules wide open to allow the CONFIG LAN domain controllers and the LAN domain controllers to use any service and application but to no effect.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 08:50:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105563#M20245</guid>
      <dc:creator>rmothers</dc:creator>
      <dc:date>2020-12-16T08:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Some traffic is being prevented but it looks like it's getting through on logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105566#M20246</link>
      <description>&lt;P&gt;Any drop logs/debugs for this traffic?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 09:05:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105566#M20246</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-12-16T09:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Some traffic is being prevented but it looks like it's getting through on logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105567#M20247</link>
      <description>&lt;P&gt;Hi Val&lt;/P&gt;&lt;P&gt;That's one of the issues there is no dropped traffic showing - I'll post some logs up in a bit - I'll have to reroute some traffic to accommodate&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 09:07:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105567#M20247</guid>
      <dc:creator>rmothers</dc:creator>
      <dc:date>2020-12-16T09:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: Some traffic is being prevented but it looks like it's getting through on logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105576#M20248</link>
      <description>&lt;P&gt;Updated topology attached (forgot connections to LANs 5 &amp;amp; 6)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 10:16:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105576#M20248</guid>
      <dc:creator>rmothers</dc:creator>
      <dc:date>2020-12-16T10:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Some traffic is being prevented but it looks like it's getting through on logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105580#M20249</link>
      <description>&lt;P&gt;Some further screenshots and log output&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 10:25:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105580#M20249</guid>
      <dc:creator>rmothers</dc:creator>
      <dc:date>2020-12-16T10:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: Some traffic is being prevented but it looks like it's getting through on logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105582#M20250</link>
      <description>&lt;P&gt;I think you are missing the point. Did you run any trace and debugs on your security gateways to see what's going on? There are two possibilities:&lt;/P&gt;
&lt;P&gt;1. Either packets are getting lost somewhere outside of your GW, or&lt;/P&gt;
&lt;P&gt;2. They are being silently dropped by GW.&lt;BR /&gt;&lt;BR /&gt;Traces with "fw monitor" and "fw ctl debug" with "drop" option should give you a direction where to looks&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 10:44:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105582#M20250</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-12-16T10:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: Some traffic is being prevented but it looks like it's getting through on logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105644#M20254</link>
      <description>&lt;P&gt;Issue is now resolved as support provider got in touch and immediately suggested applying Jumbo Hotfix (Take 89) as they were still on base build.&amp;nbsp; I hadn't realised the build I'd used did not have the relevant hotfix bundled with it.&amp;nbsp; Took a while to get them there but now the traffic is flowing as expected.&amp;nbsp; If you made it this far thanks for reading.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 16:27:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Some-traffic-is-being-prevented-but-it-looks-like-it-s-getting/m-p/105644#M20254</guid>
      <dc:creator>rmothers</dc:creator>
      <dc:date>2020-12-16T16:27:15Z</dc:date>
    </item>
  </channel>
</rss>

