<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stateful Inspection on Gateways in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25955#M5235</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;"Note that these are the default settings for the circled options, so it's clear they were adjusted by someone else."&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Yes, I found the logs in smartView tracker in the Management Tab.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch Abernathy&lt;/A&gt;‌ you save me big time. Much appreciated.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Sep 2018 17:37:16 GMT</pubDate>
    <dc:creator>Di_Junior</dc:creator>
    <dc:date>2018-09-11T17:37:16Z</dc:date>
    <item>
      <title>Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25944#M5224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Mates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need your help with regards to an issue that we faced in our environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have replaced a former administrator in the company, and in the day he left, some of the critical services in the company stopped working. The first thing I did was to go to the &lt;STRONG&gt;Management&lt;/STRONG&gt; Tab in the SmartView Tracker and check all the changes that was made on the day the problem started.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found many changes, and one of the them was ralated to &lt;STRONG&gt;UDP stateful inspection&lt;/STRONG&gt;. He swicthed off this firewall property in the &lt;STRONG&gt;global configuration mode&lt;/STRONG&gt;. Since the service that was impacted uses UDP ports 2123, and 2152, this service was having problems and our clients were not able to establish connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once we switched back on the UDP statefull inspection in the global configuration, everything started working just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I now need a a technical explanation to present to the Management as to how unchecking UDP Statefull inspection caused the issue. That&amp;nbsp; is why I wish to ask if you can share more information about Statefull Inspection, or refer me to a documentation that I can read.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 08:21:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25944#M5224</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-11T08:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25945#M5225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103084&amp;amp;partition=Advanced&amp;amp;product=Security"&gt;sk103084 How to configure the Security Gateway to drop Out of State UDP packets&lt;/A&gt; and&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102491"&gt;sk102491 How to configure the Security Gateway to drop Out of State TCP packets&lt;/A&gt; - but this is not statefull inspection, but to drop out-of-state packets...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 08:36:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25945#M5225</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-09-11T08:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25946#M5226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so you really in essense asking what does it mean "Check Point Firewall" to be frank.&lt;/P&gt;&lt;P&gt;stateful inspection whether UDP or TCP is part of the essense of the FW1 since 25y rerally.&lt;/P&gt;&lt;P&gt;reading about the Stateful Inspection and DPI enginering is like reading about history of CP Firewall architecture.&lt;/P&gt;&lt;P&gt;I think above sk's should help but I believe more or less explanatory as to what the SPI to the UDP/TCP in either drop-out-of-sate etc. is all "googleble" if you know what I mean.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 08:49:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25946#M5226</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-09-11T08:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25947#M5227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.checkpoint.com/migrated-users/50148"&gt;Jerry Szpinak&lt;/A&gt;‌, yes it is googleble, but this situation is going to court, so I need as much information as possible from trusted source. But thanks Anyways&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 08:54:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25947#M5227</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-11T08:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25948#M5228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you switched on UDP stateful inspection means you enabled (&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;check the box&lt;/SPAN&gt;)&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt;Accept stateful UDP replies for unknown services &lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;in&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;EM&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;global properties?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More info firewall packet flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3061-security-gateway-packet-flow-and-acceleration-with-diagrams" target="_blank"&gt;https://community.checkpoint.com/docs/DOC-3061-security-gateway-packet-flow-and-acceleration-with-diagrams&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:13:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25948#M5228</guid>
      <dc:creator>Laxi_D</dc:creator>
      <dc:date>2019-06-21T09:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25949#M5229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ah ok, I didn't know that it is about that serious, my apologize for a vague response then.&lt;/P&gt;&lt;P&gt;with regards to the official docs - please stick the the CP sk's as they'are vendor-specific well crafted documentation uses by the whole community and highly recognized within the network security landscape - if I were you and I was about to support the court-case I would definitely use the sk's mentioned earlier as a starting point.&lt;/P&gt;&lt;P&gt;when needed you can always use the wikipedia and cpug to support theoretical architecture of the SPI/DPI etc.&lt;/P&gt;&lt;P&gt;hope it helps and ... my 5 cents "poor ex-employee" &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/silly.png" /&gt;&amp;nbsp; I wish him good luck &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/grin.png" /&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 08:59:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25949#M5229</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-09-11T08:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25950#M5230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Under these circumstances i would involve TAC to get a deep technical explanation of the background of these settings and the issues caused !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 09:29:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25950#M5230</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-09-11T09:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25951#M5231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would be better if you posted a screenshot of exactly the option(s) changed.&lt;/P&gt;&lt;P&gt;From there we can refer you to the correct documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further, if there are (potential) court cases involved, please ensure you are gathering evidence under the guidance of legal council.&lt;/P&gt;&lt;P&gt;There are rules related to digital evidence that must be followed if it is to be admissible in court.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 14:33:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25951#M5231</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-11T14:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25952#M5232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. I guess that is what I am going to do.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 14:44:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25952#M5232</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-11T14:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25953#M5233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the picture, the circled options were unchecked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70167_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 15:35:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25953#M5233</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-11T15:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25954#M5234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you click on the question mark in the upper right corner of this screen, you will see the online help that describes these options.&lt;/P&gt;&lt;P&gt;They are also described in the product documentation and SK.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note that these are the default settings for the circled options, so it's clear they were adjusted by someone else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following are my explanations of how these features work and should not be construed as "official documentation."&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unlike TCP, which tracks connection state as part of the protocol, UDP does not.&lt;/P&gt;&lt;P&gt;If &lt;SPAN&gt;Accept Stateful UDP Replies for Unknown Services is ticked (or the "Accept replies" option in the service definition) the way we determine if a UDP packet is part of a valid session is if we see a response to it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;A response would depend on how the outgoing request is constructed.&lt;/P&gt;&lt;P&gt;Assume that I am host A talking to host B on UDP port X.&lt;/P&gt;&lt;P&gt;Host A would initiate that connection from source port Y via UDP to Host B to destination port X.&lt;/P&gt;&lt;P&gt;If Host B responds with a packet from source port X to Host A on destination port Y, then a "virtual session" is established.&lt;/P&gt;&lt;P&gt;Packets that come from Host A on source port&amp;nbsp;Y Host B to destination port X and from Host B on source port X to host A will continue to be allowed until no packets are seen on this "session" for the UDP virtual session timeout.&lt;/P&gt;&lt;P&gt;Then the session will be closed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Drop Out Of State TCP packets will drop TCP packets that appear to be unrelated to a connection seen by the Security Gateway.&lt;/P&gt;&lt;P&gt;For the gateway to consider a connection "seen" it must observe the three-way handshake that occurs when the TCP connection is established.&lt;/P&gt;&lt;P&gt;The initial SYN packet would be checked against the Access Policy.&lt;/P&gt;&lt;P&gt;Once the connection is established, the connection is tracked until it closes or the connection "times out" (no packets on the connection seen for the TCP timeout).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ICMP,&amp;nbsp;similar to UDP, doesn't really have "state" associated with it.&lt;/P&gt;&lt;P&gt;That said, based on traffic that is permitted, you can infer what would be expected in terms of an ICMP response.&lt;/P&gt;&lt;P&gt;Provided such packets are sent within the ICMP virtual session timeout, they are permitted.&lt;/P&gt;&lt;P&gt;For example, if I permit an ICMP Echo Request (ping) through the gateway, you might expect to see an ICMP Echo Reply or ICMP Host/Network Unreachable message as a response.&lt;/P&gt;&lt;P&gt;An ICMP Host Unreachable or TTL Time Expired might be expected if I'm doing a traceroute somewhere.&lt;/P&gt;&lt;P&gt;This is not an exhaustive list, but it gives you an idea of what this option is intended for.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 16:51:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25954#M5234</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-11T16:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Stateful Inspection on Gateways</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25955#M5235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;"Note that these are the default settings for the circled options, so it's clear they were adjusted by someone else."&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Yes, I found the logs in smartView tracker in the Management Tab.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch Abernathy&lt;/A&gt;‌ you save me big time. Much appreciated.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 17:37:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stateful-Inspection-on-Gateways/m-p/25955#M5235</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-11T17:37:16Z</dc:date>
    </item>
  </channel>
</rss>

