<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traceroute Issue in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Traceroute-Issue/m-p/125584#M23158</link>
    <description>&lt;P&gt;Our customer setup is rather like:&lt;/P&gt;
&lt;P&gt;Client ==&amp;gt; Internal router ==&amp;gt; Firewall ==&amp;gt; External router ==&amp;gt; {Internet}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Aug 2021 12:05:23 GMT</pubDate>
    <dc:creator>Hugo_vd_Kooij</dc:creator>
    <dc:date>2021-08-03T12:05:23Z</dc:date>
    <item>
      <title>Traceroute Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traceroute-Issue/m-p/115680#M21530</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We are seeing a very weird behavior when we do the traceroute from the Source to destination behind the firewall. Checkpoint Hop is shown twice in the trace. Shows 2nd Hop as checkpoint and next hop would be based on the routing. Then again 5th Hop is shown as Checkpoint and destination.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 12:35:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traceroute-Issue/m-p/115680#M21530</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-04-09T12:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traceroute-Issue/m-p/115701#M21532</link>
      <description>&lt;P&gt;Sounds like a weird routing/NAT issue.&lt;BR /&gt;What version/JHF?&lt;BR /&gt;A network diagram would probably be helpful as well.&lt;BR /&gt;But I suspect this will require detailed network information to resolve and you might be better off engaging with the TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 15:23:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traceroute-Issue/m-p/115701#M21532</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-09T15:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traceroute-Issue/m-p/115704#M21534</link>
      <description>&lt;P&gt;Thank you for helping me on this.&lt;/P&gt;&lt;P&gt;R80.30 and Take 227 is what we are running the firewalls. Captured traffic using fw monitor and i can clearly see it is reaching only once to the firewall. So as you said may be we need to involve TAC and also check the peer directly connected devices as well.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 16:23:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traceroute-Issue/m-p/115704#M21534</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-04-09T16:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traceroute-Issue/m-p/125582#M23157</link>
      <description>&lt;P&gt;Interresting. I have seen the same thing with R80.40 as well. But only on traceroute from Windows (ICMP) and not from Linux (UDP).&lt;/P&gt;
&lt;P&gt;ICMP packets with TTL=0 and TTL=1 are only seen on the client side interface with fw monitor (`fw monitor -F 0,0,0,0,1`) .&lt;/P&gt;
&lt;P&gt;My guess is that on ICMP the TTL count is lowered by 2 instead of 1. As the steps beyond the firewall are always consistent and do show the expected hops.&lt;/P&gt;
&lt;P&gt;As we determined that this is just an unexpected thing but otherwise harmless we did not create a ticket for this. I might do it if I can build a lab that shows the same issue. But it would most likely just be for entertainment purposes for now.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 12:01:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traceroute-Issue/m-p/125582#M23157</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2021-08-03T12:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traceroute-Issue/m-p/125584#M23158</link>
      <description>&lt;P&gt;Our customer setup is rather like:&lt;/P&gt;
&lt;P&gt;Client ==&amp;gt; Internal router ==&amp;gt; Firewall ==&amp;gt; External router ==&amp;gt; {Internet}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 12:05:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traceroute-Issue/m-p/125584#M23158</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2021-08-03T12:05:23Z</dc:date>
    </item>
  </channel>
</rss>

