<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP packet out of state: First packet isn't SYN; tcp_flags: SYN-ACK&amp;quot; log in SmartView Tracker in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37169#M7879</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Timothy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response i am trying all these step but issue is still same i am also trying to remove Sophos FW and terminate cable directly on&amp;nbsp; Checkpoint 5600 appliance unmark URL filtering blade create one policy that is source LAN destination any services any allow with log enable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 07 Jul 2018 06:46:58 GMT</pubDate>
    <dc:creator>Ramawatar_Maury</dc:creator>
    <dc:date>2018-07-07T06:46:58Z</dc:date>
    <item>
      <title>TCP packet out of state: First packet isn't SYN; tcp_flags: SYN-ACK" log in SmartView Tracker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37166#M7876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have 5600 appliance running on Gaia R77.30 that is behind Sophos IPS and Sophos IPS is in bridge mode.&lt;/P&gt;&lt;P&gt;I am installing all latest hot fix but issue is still same some website is not accessible and in SmartView tracker that is showing&amp;nbsp;&lt;CODE style="color: #000000; font-size: 14px;"&gt;TCP packet out of state: First packet isn't SYN; tcp_flags: SYN-ACK&lt;/CODE&gt;&lt;SPAN&gt;" .@&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2018 17:54:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37166#M7876</guid>
      <dc:creator>Ramawatar_Maury</dc:creator>
      <dc:date>2018-07-06T17:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: TCP packet out of state: First packet isn't SYN; tcp_flags: SYN-ACK" log in SmartView Tracker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37167#M7877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might need to start by traffic captures and check the traffic flow after that you might start looking at timers for tcp connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2018 20:51:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37167#M7877</guid>
      <dc:creator>Houssameddine_1</dc:creator>
      <dc:date>2018-07-06T20:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: TCP packet out of state: First packet isn't SYN; tcp_flags: SYN-ACK" log in SmartView Tracker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37168#M7878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please see my response in the thread below for guidance about how to troubleshoot this message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="link-titled" href="https://community.checkpoint.com/message/9300-re-first-packet-isnt-sync?commentID=9300#comment-9300" title="https://community.checkpoint.com/message/9300-re-first-packet-isnt-sync?commentID=9300#comment-9300"&gt;https://community.checkpoint.com/message/9300-re-first-packet-isnt-sync?commentID=9300#comment-9300&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2018 21:29:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37168#M7878</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-07-06T21:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: TCP packet out of state: First packet isn't SYN; tcp_flags: SYN-ACK" log in SmartView Tracker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37169#M7879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Timothy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response i am trying all these step but issue is still same i am also trying to remove Sophos FW and terminate cable directly on&amp;nbsp; Checkpoint 5600 appliance unmark URL filtering blade create one policy that is source LAN destination any services any allow with log enable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2018 06:46:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37169#M7879</guid>
      <dc:creator>Ramawatar_Maury</dc:creator>
      <dc:date>2018-07-07T06:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: TCP packet out of state: First packet isn't SYN; tcp_flags: SYN-ACK" log in SmartView Tracker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37170#M7880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I'm understanding your reply correctly, you are removing a Sophos firewall and trying to replace it with a Check Point.&amp;nbsp; The instant the Check Point is connected you will get a flurry of "out of state" messages, since all the existing connections at the time of replacement are not known to the Check Point, and by default will be dropped.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can blunt the impact of this replacement by unchecking "Drop out of state TCP packets" under Global Properties...Stateful Inspection and reinstalling policy to the firewall prior to the cutover.&amp;nbsp; Unchecking this box will cause the firewall to attempt to "resurrect" the existing connections back into the state table and allow them to continue.&amp;nbsp; You can also switch off the dropping of out of state TCP packets "on the fly" by running this command on the gateway: &lt;EM&gt;&lt;STRONG&gt;fw ctl set int fw_allow_out_of_state_tcp 1&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Do not forget to recheck the "Drop out of state TCP packets" checkbox once the firewall replacement is complete and you have successfully executed your test plan.&amp;nbsp; This setting should not be left disabled!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Jul 2018 14:03:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37170#M7880</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-07-08T14:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: TCP packet out of state: First packet isn't SYN; tcp_flags: SYN-ACK" log in SmartView Tracker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37171#M7881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Timothy&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response its work for me.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2018 06:22:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TCP-packet-out-of-state-First-packet-isn-t-SYN-tcp-flags-SYN-ACK/m-p/37171#M7881</guid>
      <dc:creator>Ramawatar_Maury</dc:creator>
      <dc:date>2018-07-09T06:22:12Z</dc:date>
    </item>
  </channel>
</rss>

