<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/225604#M37577</link>
    <description>&lt;P&gt;Hi Don,&lt;/P&gt;
&lt;P&gt;TAC investigated nothing, I had to do everything myself. Anyway I found two issues.&lt;/P&gt;
&lt;P&gt;Issue one,&amp;nbsp;&lt;SPAN&gt;sk122072 -&amp;nbsp;'TCP out of Sequence' logs in SmartView Tracker&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;the GW is marking keep-alive as a drop out of state which should not do. We have a ticket.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Issue two, a lot of ACKs are disappearing in the customer network making the retransmission Invalid and out of state, because server has data and sends ACK, FW accepts ACK, process it and after that ACK disappears. Client makes retransmission and the FW drops it because ACK has been seen and its already out of state with old seq number.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Sep 2024 09:55:30 GMT</pubDate>
    <dc:creator>Martin_Raska</dc:creator>
    <dc:date>2024-09-04T09:55:30Z</dc:date>
    <item>
      <title>https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet dat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179439#M29911</link>
      <description>&lt;P&gt;Trying to understand what the exact cause/s for this PSL drop might be.&lt;/P&gt;&lt;P&gt;Anyone else seen it and found out more?&lt;/P&gt;&lt;P&gt;Log image attached. SK reference image attached.&lt;/P&gt;&lt;P&gt;"https Traffic Dropped from ... to ... due to Out of sequence TCP packet retransmission. Stripping all packet data. Please refer to sk172266."&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 15:49:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179439#M29911</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2023-04-28T15:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179441#M29912</link>
      <description>&lt;P&gt;I had this issue with customers couple times and below is what we did to fix it. Not saying it would work for you, but thats what did work in our case. Just need to put in affected IPs/subnets in both src/dst&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20689i759582B47254CDA4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 16:06:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179441#M29912</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-28T16:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179444#M29914</link>
      <description>&lt;P&gt;Nice. Thanks!&lt;/P&gt;&lt;P&gt;I'm looking at SK122072&amp;nbsp;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk122072" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk122072&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;Solution&lt;BR /&gt;These logs can be safely ignored and disabled by setting the following kernel parameter:&lt;/P&gt;&lt;P&gt;# fw ctl set int psl_disable_keepalive_logs 1&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;But also thinking about MTUs, ring buffer sizes and also elephant flow (Hyperflow).&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk42181" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk42181&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT:&lt;/P&gt;&lt;P&gt;+ This is about image files being transferred over the network.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 16:14:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179444#M29914</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2023-04-28T16:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179445#M29915</link>
      <description>&lt;P&gt;Well, here is my logic about this, and not only this, but really any traffic problem...so IF those logs are indication of the actual issue, then it needs to be addresses. However, if you see them, but you are simply curious why they are there (but no any other problems), then those SKs would make sense.&lt;/P&gt;
&lt;P&gt;Also, all tcp out of state means, in most simple terms, is this...communication is broken somewhere, along the way...3-way handshake is not happening properly.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 16:35:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179445#M29915</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-28T16:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179447#M29917</link>
      <description>&lt;P&gt;ACK. Agree.&lt;BR /&gt;&lt;BR /&gt;Did you confuse&amp;nbsp;Out of Sequence with Out of State? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 16:40:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179447#M29917</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2023-04-28T16:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179448#M29918</link>
      <description>&lt;P&gt;I did, sorry lol. Did not get much sleep, had Fortigate cutover at 4.30 am, so my apologies.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 16:45:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179448#M29918</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-28T16:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179449#M29919</link>
      <description>&lt;P&gt;But here is bigger question...is there an ACTUAL traffic issue, or are you simply concerned about the logs you see?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 16:44:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/179449#M29919</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-28T16:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/214286#M35428</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;do you have more info why it is happening? We have a lot of these drops at the customer, it is HTTPS traffic from user to Internet and in the logs is always&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Invalid segment retransmission. Packet dropped. Please refer to sk172266. Streaming Engine: TCP Invalid Retransmission&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and its causing issues.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is it related to brotli encoding or is it a general issue? -&amp;nbsp;sk181282&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_71acee3bda0800Martin_Raska_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_71acee3bda0800Martin_Raska_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 07:42:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/214286#M35428</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2024-05-15T07:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/220506#M36747</link>
      <description>&lt;P&gt;Hi Martin,&lt;BR /&gt;Apologies for the late reply.&lt;/P&gt;
&lt;P&gt;It may be best to open a ticket with TAC so that they can gather all the missing information (version, load &amp;amp; performance, and current configuration (including enabled blades and protections enabled, and cluster config), along with maybe packet captures).&lt;BR /&gt;&lt;BR /&gt;I don't have any more information on this and only have the SKs to refer to but you could look at the Inspection Settings and look to add exceptions (screenshot attached).&lt;BR /&gt;If PSL is dropping (because it offers some attack prevention before IPS signature matching) then it could point to a real problem, but otherwise it might need an exception somewhere or a Check Point Hot Fix maybe(?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Don&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 11:24:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/220506#M36747</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2024-07-12T11:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/225604#M37577</link>
      <description>&lt;P&gt;Hi Don,&lt;/P&gt;
&lt;P&gt;TAC investigated nothing, I had to do everything myself. Anyway I found two issues.&lt;/P&gt;
&lt;P&gt;Issue one,&amp;nbsp;&lt;SPAN&gt;sk122072 -&amp;nbsp;'TCP out of Sequence' logs in SmartView Tracker&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;the GW is marking keep-alive as a drop out of state which should not do. We have a ticket.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Issue two, a lot of ACKs are disappearing in the customer network making the retransmission Invalid and out of state, because server has data and sends ACK, FW accepts ACK, process it and after that ACK disappears. Client makes retransmission and the FW drops it because ACK has been seen and its already out of state with old seq number.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 09:55:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/225604#M37577</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2024-09-04T09:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/225611#M37581</link>
      <description>&lt;P&gt;How did you solve the issue?&lt;/P&gt;
&lt;P&gt;Issue one, I have changed&amp;nbsp;&lt;STRONG&gt;&lt;CODE&gt;fw ctl set int psl_disable_keepalive_logs 1&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;But no effect. Also curious how you solved issue 2.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 10:18:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/225611#M37581</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-09-04T10:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/226112#M37737</link>
      <description>&lt;P&gt;For us this worked -&amp;nbsp;&lt;STRONG&gt;&lt;CODE&gt;fw ctl set int psl_disable_keepalive_logs 1,&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;we dont see keep-alives as a Drops.&lt;/P&gt;
&lt;P&gt;Issue two, we don't know where, but it has to be the customer environment, probably core router or Asym routing which is there as we found out.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 08:16:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/226112#M37737</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2024-09-10T08:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: https Traffic Dropped ... due to Out of sequence TCP packet retransmission. Stripping all packet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/226113#M37738</link>
      <description>&lt;P&gt;if it does not work for you -&amp;nbsp;&lt;STRONG&gt;&lt;CODE&gt;fw ctl set int psl_disable_keepalive_logs 1&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;then its probably not keep-alive traffic and something else which is making TCP retransmission out of sequence&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 08:19:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/https-Traffic-Dropped-due-to-Out-of-sequence-TCP-packet/m-p/226113#M37738</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2024-09-10T08:19:03Z</dc:date>
    </item>
  </channel>
</rss>

