<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Difference between 2 packet captures in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199623#M33338</link>
    <description>&lt;P&gt;We have a public facing Application for both mobile and web. We have captured tcpdump on our gateway for both working and not working Public IP's. Can any one differentiate both captures?&lt;/P&gt;&lt;P&gt;Your help is much appreciated. Below you can find both working and notworking packet captures.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Dec 2023 12:11:07 GMT</pubDate>
    <dc:creator>gemechisd</dc:creator>
    <dc:date>2023-12-04T12:11:07Z</dc:date>
    <item>
      <title>Difference between 2 packet captures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199623#M33338</link>
      <description>&lt;P&gt;We have a public facing Application for both mobile and web. We have captured tcpdump on our gateway for both working and not working Public IP's. Can any one differentiate both captures?&lt;/P&gt;&lt;P&gt;Your help is much appreciated. Below you can find both working and notworking packet captures.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 12:11:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199623#M33338</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-12-04T12:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between 2 packet captures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199640#M33342</link>
      <description>&lt;P&gt;First off, both captures are incomplete and only showing traffic in one direction.&amp;nbsp; How did you take these captures?&lt;/P&gt;
&lt;P&gt;For the not-working capture: the only difference for SYN is that the initiating system is not requesting the TCP timestamp option and also asking for a slightly smaller TCP scale factor &amp;amp; window, neither of which should cause this packet to be dropped by the firewall.&lt;/P&gt;
&lt;P&gt;Until I can see communication in both directions it is tough to say what is wrong, as I can't even see if the SYN-ACK is returning to the firewall at all in the not-working capture.&amp;nbsp; Try running "fw ctl zdebug drop" on the gateway, then try to make the application fail, this command will show you if anything in the Check Point code dropped either the SYN or the SYN-ACK for the not-working capture scenario.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 14:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199640#M33342</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-12-04T14:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between 2 packet captures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199641#M33343</link>
      <description>&lt;P&gt;Im with Tim on this one. I also examined both of captures you attached and we only see one direction traffic, nothing the other way around.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 14:53:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199641#M33343</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-04T14:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between 2 packet captures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199650#M33347</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you for the quick reply.&lt;BR /&gt;&lt;BR /&gt;Let me drop a traffic on both flows. From Public to The Node, and From the node to Public.&lt;BR /&gt;&lt;BR /&gt;Below you can find it.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 16:39:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199650#M33347</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-12-04T16:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between 2 packet captures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199651#M33348</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the reply. I have attached on the reply for&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;. Kindly, check it&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 16:41:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199651#M33348</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-12-04T16:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between 2 packet captures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199654#M33349</link>
      <description>&lt;P&gt;Thanks, will do. Just working on some Microsoft Azure stuff now, but will have a look soon.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 16:50:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199654#M33349</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-04T16:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between 2 packet captures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199655#M33350</link>
      <description>&lt;P&gt;Those captures when combined show both directions but they are for different TCP connections (source port numbers do not match) so the ability to determine what is wrong is limited.&amp;nbsp; I need to see a single capture that has all the packets in both directions for a single connection.&amp;nbsp; So I'll ask again: how are you taking this capture?&lt;/P&gt;
&lt;P&gt;It looks like the SYN-ACK is reaching the gateway but being dropped for some reason; I don't see anything wrong with the SYN-ACK itself so it must be a stateful inspection thing that is dropping it.&amp;nbsp; Search your logs for "out of state" drops or run &lt;STRONG&gt;fw ctl zdebug drop&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;If this is a high volume transaction without sufficiently diverse source ports, it is possible the occasional failures could be due to source port reuse, see here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk24960" target="_blank" rel="noopener"&gt;sk24960: "Smart Connection&amp;nbsp;Reuse" feature modifies some SYN packets&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I'm not willing to speculate further without a full capture of both directions for the same connection.&amp;nbsp; Is this traffic subject to NAT?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 16:54:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199655#M33350</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-12-04T16:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between 2 packet captures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199661#M33351</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Kindly have a look at it.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 17:12:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199661#M33351</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-12-04T17:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between 2 packet captures</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199665#M33352</link>
      <description>&lt;P&gt;It might be wiser if you do remote with TAC and they can probably check it faster. All I see is bunch of retransmissions, but hard to say for sure why its happening. Did you check to see if there is any difference as far as that other IP that fails? Did it ever work? Can you do zdebug and grep for that IP?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 17:48:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Difference-between-2-packet-captures/m-p/199665#M33352</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-04T17:48:26Z</dc:date>
    </item>
  </channel>
</rss>

