<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP port reuse between Check Point Remote Access Gateway and Loadbalancer in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31614#M6621</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That might cause the issue you saw in the logs &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 10 Feb 2019 04:56:33 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-02-10T04:56:33Z</dc:date>
    <item>
      <title>TCP port reuse between Check Point Remote Access Gateway and Loadbalancer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31609#M6616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Mates&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need a hand.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently having an issue with one of our application that is accessed through Check Point Endpoint Security. The application is behind a loadbalancer which then distributes the traffic to the servers where the applications are running.&lt;/P&gt;&lt;P&gt;We are doing NAT of the Office Pool with the VPN gateway internal address. So the IP that reaches the Load balancer is the IP of the VPN Gateway, which is then NATTed by the load balancer.&lt;/P&gt;&lt;P&gt;The issue is that the application sometimes works and other times it stops working. I did capture the traffic when it stops working, and the message i see is:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[Expert Info (Note/Sequence): A new tcp session is started with the same ports as an earlier session in this trace]&lt;/STRONG&gt;&lt;BR /&gt; &lt;STRONG&gt;[A new tcp session is started with the same ports as an earlier session in this trace]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78258_pastedImage_2.png" /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;10.25.193.214 is the IP of the Loadbalancer&lt;/P&gt;&lt;P&gt;192.168.1.1 is the IP of the RA VPN gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need an help to know if the port is being reused by the Firewall or the LoadBalancer. and How this situation could be resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2019 17:41:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31609#M6616</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2019-02-07T17:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: TCP port reuse between Check Point Remote Access Gateway and Loadbalancer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31610#M6617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The client is the one who determines what source port is being used.&lt;/P&gt;&lt;P&gt;When HIDE NAT is being used, it's a combination of the client and the NAT gateway.&lt;/P&gt;&lt;P&gt;Specifically, the NAT gateway will allocate a new port when a new connection is established through the gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Presumably, in the case where the client reuses the same source ip/port to the same destination ip/port, you are triggering "connection reuse."&lt;/P&gt;&lt;P&gt;Do you see any messages related to this in your logs?&lt;/P&gt;&lt;P&gt;Maybe this feature needs to be disabled.&lt;/P&gt;&lt;P&gt;See:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk24960" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk24960"&gt;"Smart Connection Reuse" feature modifies some SYN packets&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2019 20:48:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31610#M6617</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-08T20:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: TCP port reuse between Check Point Remote Access Gateway and Loadbalancer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31611#M6618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Check Point does indeed re-use ports, please check out the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk24960&amp;amp;partition=Advanced&amp;amp;product=Security" style="max-width: 840px;"&gt;sk24960: "&lt;STRONG&gt;Smart&lt;/STRONG&gt; &lt;STRONG&gt;Connection&lt;/STRONG&gt; &lt;STRONG&gt;Reuse&lt;/STRONG&gt;" feature modifies some SYN packets&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103656&amp;amp;partition=General&amp;amp;product=CoreXL%22" style="max-width: 840px;"&gt;sk103656: Dynamic &lt;STRONG&gt;NAT&lt;/STRONG&gt; port allocation feature&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For that second SK, you'll want to look at the&amp;nbsp;&lt;STRONG&gt;&lt;CODE&gt;fwx_nat_dynamic_port_allocation_entry_timeout&lt;/CODE&gt;&lt;/STRONG&gt; variable specifically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;"IPS Immersion Training" Self-paced Video Class&lt;BR /&gt;&lt;SPAN&gt;Now Available at &lt;/SPAN&gt;&lt;A class="" href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2019 20:55:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31611#M6618</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-02-08T20:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: TCP port reuse between Check Point Remote Access Gateway and Loadbalancer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31612#M6619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp;&lt;A _jive_internal="true" data-avatarid="2196" data-externalid="" data-online="false" data-presence="null" data-userid="2075" data-username="cfe6e688-522c-305c-adaa-194bd7a7becc" href="https://community.checkpoint.com/people/cfe6e688-522c-305c-adaa-194bd7a7becc" style="color: inherit; background-color: #ffffff; border: 0px; font-weight: bold; text-decoration: underline; font-size: 14px;"&gt;Dameon Welch-Abernathy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I now check the log and the traffic is logged as shown bellow.&lt;/P&gt;&lt;P&gt;Any idea on how this could be overcomed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78309_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Feb 2019 21:31:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31612#M6619</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2019-02-09T21:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: TCP port reuse between Check Point Remote Access Gateway and Loadbalancer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31613#M6620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After an interaction with Check Point TAC, it was discovered that the http traffic was not being synchronized between the cluster members (&lt;EM&gt;we use LS unicat mode&lt;/EM&gt;).&lt;/P&gt;&lt;P&gt;After changing the protocol propertiies, the application started working as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78310_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Feb 2019 00:22:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31613#M6620</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2019-02-10T00:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: TCP port reuse between Check Point Remote Access Gateway and Loadbalancer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31614#M6621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That might cause the issue you saw in the logs &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Feb 2019 04:56:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31614#M6621</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-10T04:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: TCP port reuse between Check Point Remote Access Gateway and Loadbalancer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31615#M6622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, disabling state sync for services in any kind of Load Sharing deployment is not a good idea.&amp;nbsp; In HA (active/standby) it can be used to reduce utilization in the sync network and CPU overhead quite a bit.&amp;nbsp; Also don't try to upgrade your gateway to R80.20, as both forms of ClusterXL Load Sharing are not supported at this time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;"IPS Immersion Training" Self-paced Video Class&lt;BR /&gt;&lt;SPAN&gt;Now Available at &lt;/SPAN&gt;&lt;A class="" href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Feb 2019 15:44:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-port-reuse-between-Check-Point-Remote-Access-Gateway-and/m-p/31615#M6622</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-02-10T15:44:31Z</dc:date>
    </item>
  </channel>
</rss>

