<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R75.47 SPLAT and FTP Issues in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R75-47-SPLAT-and-FTP-Issues/m-p/26068#M5274</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So before I get "upgrade please!!!" we are getting new R80.10 boxes in the next year but intill those are up i am seeing a issue with many FTP sites not finishing the handshake over the firewalls. When i connect just past the firewall on the same device it is working. Logs, FW monitor, and zdebug drop are all showing no blocks and that all trafiic is allowed. Wireshark just shows TCP retransmits due to the incomplete handshake. Anyone fight this issue before and can offer up some insight ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 May 2018 15:25:56 GMT</pubDate>
    <dc:creator>Jonathan_Diegan</dc:creator>
    <dc:date>2018-05-25T15:25:56Z</dc:date>
    <item>
      <title>R75.47 SPLAT and FTP Issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R75-47-SPLAT-and-FTP-Issues/m-p/26068#M5274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So before I get "upgrade please!!!" we are getting new R80.10 boxes in the next year but intill those are up i am seeing a issue with many FTP sites not finishing the handshake over the firewalls. When i connect just past the firewall on the same device it is working. Logs, FW monitor, and zdebug drop are all showing no blocks and that all trafiic is allowed. Wireshark just shows TCP retransmits due to the incomplete handshake. Anyone fight this issue before and can offer up some insight ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2018 15:25:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R75-47-SPLAT-and-FTP-Issues/m-p/26068#M5274</guid>
      <dc:creator>Jonathan_Diegan</dc:creator>
      <dc:date>2018-05-25T15:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: R75.47 SPLAT and FTP Issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R75-47-SPLAT-and-FTP-Issues/m-p/26069#M5275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are not seeing SynACKs from the destination (FTP servers) at all, check your NAT for the sources: if it is static and manual, you may have to define proxy ARP entries. If it is automatic and either "Hide" or "Static" in the object's properties, check the routing on the destination, if these are your servers.&lt;/P&gt;&lt;P&gt;Verify that your NAT settings are accurate: i.e. if you have Hide NAT for HTTP/S access to ANY, but have a manual rule with different NATed IP for FTP and that IP is wrong, the replies will get lost.&lt;/P&gt;&lt;P&gt;If the destination is not under your control, check tcpdump and fw monitor on external interfaces of the firewall to see if you are receiving &lt;SPAN&gt;SynACKs&lt;/SPAN&gt; there.&lt;/P&gt;&lt;P&gt;It would also help, if you are addressing the FTP servers by name and not the IP from inside of the firewall, to check if they are being resolved to the same IPs as when you are trying it on the outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2018 18:52:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R75-47-SPLAT-and-FTP-Issues/m-p/26069#M5275</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-05-25T18:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: R75.47 SPLAT and FTP Issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R75-47-SPLAT-and-FTP-Issues/m-p/26070#M5276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, testing the above yeilded the same results &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2018 19:31:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R75-47-SPLAT-and-FTP-Issues/m-p/26070#M5276</guid>
      <dc:creator>Jonathan_Diegan</dc:creator>
      <dc:date>2018-05-25T19:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: R75.47 SPLAT and FTP Issues</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R75-47-SPLAT-and-FTP-Issues/m-p/26071#M5277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would be helpful if you could post the text output of tcpdump -eni ifname while the traffic is traversing.&lt;/P&gt;&lt;P&gt;Verify the destination MAC shown actually matches your interface (this will verify the gateway is actually receiving the traffic).&lt;/P&gt;&lt;P&gt;You might also try, as a troubleshooting step, disabling SecureXL briefly (fwaccel off) and testing as well, but do this during a low traffic period.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 May 2018 03:34:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R75-47-SPLAT-and-FTP-Issues/m-p/26071#M5277</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-26T03:34:52Z</dc:date>
    </item>
  </channel>
</rss>

