<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Excessive traffic between digicert IP's and checkpoint gateway in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/107017#M20488</link>
    <description>&lt;P&gt;Dear Nandhu,&lt;BR /&gt;&lt;BR /&gt;How did it go with this case? We face something similar here, yet it seems that the connection is initiated by the firewall itself and not something internal and NATted to it, because of the curl_cli that is related.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;[Expert@fw1:0]# lsof -n -i :80&lt;/P&gt;&lt;P&gt;COMMAND&amp;nbsp;&amp;nbsp;&amp;nbsp; PID&amp;nbsp;&amp;nbsp; USER&amp;nbsp;&amp;nbsp; FD&amp;nbsp;&amp;nbsp; TYPE&amp;nbsp;&amp;nbsp; DEVICE SIZE NODE NAME&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;curl_cli&lt;/STRONG&gt;&amp;nbsp; 2343&amp;nbsp; admin&amp;nbsp; &amp;nbsp;10u&amp;nbsp; IPv4 33694501&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP &amp;lt;fwIP&amp;gt;:47426-&amp;gt;93.184.220.29:http (ESTABLISHED) ( ---&amp;gt; ocsp.digicert.com )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any updates regarding this?&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jan 2021 13:18:35 GMT</pubDate>
    <dc:creator>krit</dc:creator>
    <dc:date>2021-01-05T13:18:35Z</dc:date>
    <item>
      <title>Excessive traffic between digicert IP's and checkpoint gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98601#M19259</link>
      <description>&lt;P&gt;We are working on an issue with one of our remote office. The site has two 5600 appliances in a cluster, the issue occurring is in regards to a sudden spike of traffic from the checkpoint gateway's external interface talking out to digicert over port 80. The return traffic tends to be excessive enough to cause the cisco edge switch to start dropping packets. This causes the sslvpn to go down causing disconnections for the remote workforce out there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not really sure why the gateway would be receiving so much traffic from digicert.&amp;nbsp; Anyone seen this behavior before?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 21:07:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98601#M19259</guid>
      <dc:creator>Nandhu</dc:creator>
      <dc:date>2020-10-08T21:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive traffic between digicert IP's and checkpoint gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98604#M19260</link>
      <description>&lt;P&gt;If you have HTTPS Inspection enabled and/or the gateway is R80.40, I suspect it’s because we are validating certificates in flight.&lt;BR /&gt;That is done out-of-band.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 22:58:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98604#M19260</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-08T22:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive traffic between digicert IP's and checkpoint gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98606#M19261</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;Dameon,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;No https inspection and running 80.10. It looks like the IP resolves to ocsp.digicert.com&lt;/P&gt;&lt;P&gt;So i am guessing this is something going wrong with ocsp every few hours. The issue lasts for about 5 to 10 minutes before going away. It seems to happen approximately every 4 hours but sometimes misses the 4 hour mark.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nandhu&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 23:01:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98606#M19261</guid>
      <dc:creator>Nandhu</dc:creator>
      <dc:date>2020-10-08T23:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive traffic between digicert IP's and checkpoint gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98624#M19262</link>
      <description>&lt;P&gt;That’s definitely CRL validation.&lt;BR /&gt;I recommend a TAC case to assist in investigation.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 02:35:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98624#M19262</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-09T02:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive traffic between digicert IP's and checkpoint gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98649#M19263</link>
      <description>&lt;P&gt;Are you sure traffic source is your gateway, not something behind from the internal network which will be NATed?&lt;/P&gt;&lt;P&gt;Maybee some suspicious clients they do excessive CRL validations.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 11:12:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98649#M19263</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-10-09T11:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive traffic between digicert IP's and checkpoint gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98651#M19264</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;Dameon and Wolfgang,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are looking at some of the automation scripts that the QA teams use. But the timing of their requests and traffic on the firewall does not match up.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We do have a TAC case open and I am in the process of collecting debugs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nandhu&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 11:23:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/98651#M19264</guid>
      <dc:creator>Nandhu</dc:creator>
      <dc:date>2020-10-09T11:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive traffic between digicert IP's and checkpoint gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/107017#M20488</link>
      <description>&lt;P&gt;Dear Nandhu,&lt;BR /&gt;&lt;BR /&gt;How did it go with this case? We face something similar here, yet it seems that the connection is initiated by the firewall itself and not something internal and NATted to it, because of the curl_cli that is related.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;[Expert@fw1:0]# lsof -n -i :80&lt;/P&gt;&lt;P&gt;COMMAND&amp;nbsp;&amp;nbsp;&amp;nbsp; PID&amp;nbsp;&amp;nbsp; USER&amp;nbsp;&amp;nbsp; FD&amp;nbsp;&amp;nbsp; TYPE&amp;nbsp;&amp;nbsp; DEVICE SIZE NODE NAME&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;curl_cli&lt;/STRONG&gt;&amp;nbsp; 2343&amp;nbsp; admin&amp;nbsp; &amp;nbsp;10u&amp;nbsp; IPv4 33694501&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP &amp;lt;fwIP&amp;gt;:47426-&amp;gt;93.184.220.29:http (ESTABLISHED) ( ---&amp;gt; ocsp.digicert.com )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any updates regarding this?&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;BR /&gt;&lt;BR /&gt;Best Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 13:18:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/107017#M20488</guid>
      <dc:creator>krit</dc:creator>
      <dc:date>2021-01-05T13:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Excessive traffic between digicert IP's and checkpoint gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/107024#M20493</link>
      <description>&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;We pulled digicert certs from the firewall, followed by a jumbo and reboot. Seems to have cleared out the issue on our end. We added back the cert for one of our sslvpn firewalls and are not seeing the behavior anymore.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem now is that we do not know which of the 3 things we did solved the issue. I wish I could have been more helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nandhu&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 13:48:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Excessive-traffic-between-digicert-IP-s-and-checkpoint-gateway/m-p/107024#M20493</guid>
      <dc:creator>Nandhu</dc:creator>
      <dc:date>2021-01-05T13:48:36Z</dc:date>
    </item>
  </channel>
</rss>

