<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Streaming Issue on Spark (How Fuzzy Saved Chrismas) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Streaming-Issue-on-Spark-How-Fuzzy-Saved-Chrismas/m-p/236735#M39570</link>
    <description>&lt;P&gt;Awesome post! Btw, National Lampoons, in my opinion, best Christmas movie &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 23 Dec 2024 17:43:04 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-12-23T17:43:04Z</dc:date>
    <item>
      <title>Streaming Issue on Spark (How Fuzzy Saved Chrismas)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Streaming-Issue-on-Spark-How-Fuzzy-Saved-Chrismas/m-p/236734#M39569</link>
      <description>&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;STRONG&gt;&lt;FONT size="6"&gt;Hello again and Merry Christmas!&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Recently been working with setting up a 1500 series gateway for a home lab to learn more about the Spark platform. Thought I would share something interesting I learned. The problem I ran into can be a little difficult to diagnose so it seemed like a good one for a post.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;STRONG&gt;Background&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;My home network is pretty simple. Single ISP, some 2.4Ghz and some 5Ghz only wifi devices and single server on a wired LAN port. The gear running it is pretty stale though. I have some shiny new digital drip coming in the new year to rebuild the whole setup, but that isn't here yet. So I thought, if I am building this lab anyway might as well throw everything in it.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Now I do recognize the danger of scoping in your personal gear in a "lab" setup. But labs can be sterile and often it is hard to get any "real-world" data/traffic in them. I wanted to get feel for how some of these features work, Like IoT protect for example, and the best way to do that is to have real devices and real data. Besides, I thought to myself, "what's the worst that could happen"?&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;STRONG&gt;The Setup&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I decided to try out the new R81.10.15 image, and side note, I really like what they have done with the interface.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="R81.10.15_GUI.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28982iDEF757F7BA577E43/image-size/large?v=v2&amp;amp;px=999" role="button" title="R81.10.15_GUI.png" alt="R81.10.15_GUI.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I clicked through the basic device setup and network configurations easily and for the most part everything worked just fine. I haven't spent much time on the SMB side of the product line so most of this is new to me but pleasantly surprised by how intuitive it is and easy to click around and find what you are looking for. After the initial setup and first day of testing I was beginning to think I might be done.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Meme_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28983i319BE96ABECCD048/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Meme_1.png" alt="Meme_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;STRONG&gt;The problem&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Later that evening, I sat down with the fam to stream a Christmas movie. Launched the Prime app from my Roku, searched through the catalog till we found what we wanted and clicked play. Then it happened, the spinning icon of doom for a full minute then the classic&amp;nbsp; "something went wrong" error message. Not good.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;The kids were not impressed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kids1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28984i921E83D82FF18045/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kids1.png" alt="kids1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;In retrospect, I probably should have done better end user communication, as the wife and kids had no idea I had changed up the wireless connections on all their devices and were a little less understanding. (Also maybe wiping the configs on my old gear right away was premature) I jumped into action and began troubleshooting while they all stared at me. Didn't take long to realize this wasn't going to be a simple fix, so I made my apologies and posted a system outage notification to the user base. My wife grabbed a book, the kids dispersed back to their twitch streams and Minecraft and I set out to get to the bottom of the issue that I hoped would take maybe 15-20mins.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Meme_2.png" style="width: 337px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28985iADD461F206BA642F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Meme_2.png" alt="Meme_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Now the way this issue manifested was strange for a couple of reasons. First, I had tested all of our streaming apps already and everything worked fine. I had just tested them on my laptop instead of the Roku. Second, some of the channels on the Roku did work. YouTube, Netflix, and others worked just fine. But the Amazon Prime app did not, but even so, it wasn't completely broken. You could log in and browse the catalog, and occasionally the auto-preview would even play when looking at a selection, but when you tried to start a stream it would never load.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Looking at the security logs there were no clear drop/deny actions that could explain what was going on. So I began testing things that I suspected might be the cause.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I tried all sorts of things&lt;/FONT&gt;&lt;/P&gt;
&lt;UL style="direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Disabling the IoT service&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Turning off SSL inspection (categorization)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Creating a Server Object (for the NAT rules)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Turning off App &amp;amp; URL Filtering&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Disabling SD-WAN (I had set it up for testing)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Fast Accel&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;UL style="direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="circle"&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Smart Accel On/Off&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Bypassing based on source IP&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Turning off Threat Protection blades&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI lang="en-US" style="margin-top: 0; margin-bottom: 0; vertical-align: middle;"&gt;&lt;FONT face="arial,helvetica,sans-serif" size="3"&gt;&lt;SPAN&gt;Turning off NAT all together (desperation time)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Honestly got a little frustrated at this point. Just seemed like nothing I tweaked or messed with had any effect. By now I am a couple hours in and I starting to consider tearing it down and rebuilding the old gear. Trouble was I knew that was at least another hour of messing around. Taking stock, I realized movie time had passed, the kids had moved on and the wife was enjoying her book, so really the only one upset was me. Best bet was to unplug and look at it with fresh eyes another day. (sigh)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="meme_3.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28986i63CEACBCA2DB9412/image-size/medium?v=v2&amp;amp;px=400" role="button" title="meme_3.png" alt="meme_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;STRONG&gt;The Solution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;This was a wise choice. With a clearer head the next morning, I sat with my coffee staring at my screen and realized I sort of skipped the basic troubleshooting best practices in my flurry of tweaking and testing. I had been looking at the security logs but I really hadn't analyzed how the traffic was being handled in any detail. Time to get serious.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;So I dug out my troubleshooting command line reference notes and dropped into the CLI.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I started with:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif" color="#0000FF"&gt;fw monitor -m o -e 'src=192.168.x.x,accept;'&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk30583" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk30583&lt;/A&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Normally with this command I would scope in the source and destination. However given the nature of this issue I really wasn't sure which destination was at issue. Remember the app sort of worked, you could log in, browse, search, even preview content. It wasn't till a stream started that things didn't work. That meant there were multiple Amazon/AWS looking Ips that were being connected to.&amp;nbsp; (all successfully)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;My hope was that this would help me narrow it down, but didn't much traction here.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;Moved on to the next:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3" color="#0000FF"&gt;fw ctl zdebug + drop&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk167457" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk167457&lt;/A&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Got sidetracked here for a bit. My habit is to drop the output here to a txt file, then use SCP to transfer it back to my workstation so I can view in a nice txt editor. However that doesn't work unless the default shell for the admin is changed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;STRONG&gt;Hey did you know?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;The command to change the default shell is different on Spark vs Gaia.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Gaia = &lt;FONT color="#0000FF"&gt;set user admin shell /bin/bash&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Spark = &lt;FONT color="#0000FF"&gt;bashUser on&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Turns out that was just a waste of time because there wasn't that much activity in the log anyway. (Benefit of early morning testing on Christmas break, 90% of the end users are still asleep) But, once I got back to the task at hand, there were some interesting messages in here. Primarily:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;dropped by fwmultik_process_f2p_cookie_inner Reason: fwmultik_f2p_cookie_outbound_and_routing failed&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;dropped by fw_first_packet_state_checks Reason: First packet isn't SYN&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;After doing some online sleuthing from these clues I found this:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk167953" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk167953&lt;/A&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;This lead me to look at the MTU settings.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Device -&amp;gt; Advanced Settings&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I tried a couple custom settings there, tried enabling Jumbo Frames and it all made no difference. Was beginning to wonder if this was a red herring. How can the MTU size negotiation be failing if the problem with it failing was specifically fixed in a previous version as it says in the SK?&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;But then I noticed something the I missed at first glance. The PMTUD is actually disabled by default! The process is not failing because of some internal error, it is failing because it is turned off.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Changed the value to:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Run as Daemon&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MTU.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28987i7AB4E90FBBB17534/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MTU.png" alt="MTU.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Now I did get hung up on this at first, because it didn't seem to make any difference. But before I gave up on it I realized that perhaps the service might not start until the next boot up. So I rebooted the gateway, and just like that, it all started working!&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Now I don't want to brag, but I basically saved Christmas. They will probably make a movie about this adventure that will become a holiday classic like Die Hard or National Lampoons Christmas Vacation. You will then have the added joy of telling your family "I remember when this was just a post on CheckMates". Lol.&amp;nbsp; Hopefully, my misadventure here will help someone else save a little time someday.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I wonder who they will get to play my part? shame Chris Farley isn't around anymore…&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Fuzzy_movie.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28988i6B8556F16B86A89E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Fuzzy_movie.jpg" alt="Fuzzy_movie.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: 'Segoe UI'; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 17:30:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Streaming-Issue-on-Spark-How-Fuzzy-Saved-Chrismas/m-p/236734#M39569</guid>
      <dc:creator>FuzzyLogic</dc:creator>
      <dc:date>2024-12-23T17:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: Streaming Issue on Spark (How Fuzzy Saved Chrismas)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Streaming-Issue-on-Spark-How-Fuzzy-Saved-Chrismas/m-p/236735#M39570</link>
      <description>&lt;P&gt;Awesome post! Btw, National Lampoons, in my opinion, best Christmas movie &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 17:43:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Streaming-Issue-on-Spark-How-Fuzzy-Saved-Chrismas/m-p/236735#M39570</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-23T17:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: Streaming Issue on Spark (How Fuzzy Saved Chrismas)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Streaming-Issue-on-Spark-How-Fuzzy-Saved-Chrismas/m-p/236751#M39578</link>
      <description>&lt;P&gt;As long as you don't have to live in a van down by the river, it'll be ok. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 21:31:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Streaming-Issue-on-Spark-How-Fuzzy-Saved-Chrismas/m-p/236751#M39578</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-23T21:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Streaming Issue on Spark (How Fuzzy Saved Chrismas)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Streaming-Issue-on-Spark-How-Fuzzy-Saved-Chrismas/m-p/236770#M39581</link>
      <description>&lt;P&gt;Thanks for sharing, I really enjoyed the story. Happy holidays&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 07:57:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Streaming-Issue-on-Spark-How-Fuzzy-Saved-Chrismas/m-p/236770#M39581</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-12-24T07:57:58Z</dc:date>
    </item>
  </channel>
</rss>

