<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: First packet isn't sync in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7025#M796</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would first check routing. Make sure, out and in packets use same route and same checkpoints inerface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Oct 2017 07:00:24 GMT</pubDate>
    <dc:creator>MK9</dc:creator>
    <dc:date>2017-10-04T07:00:24Z</dc:date>
    <item>
      <title>First packet isn't SYN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7021#M792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;my gateway R80.10 and multicast cluster working. but internet is very slow and didnot drop any packet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;only one drop packet is below picture. how can i solve this issue?&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="59486" alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/59486_Example.png" style="width: 620px; height: 543px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Oct 2017 02:44:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7021#M792</guid>
      <dc:creator>batmunkh_unubuk</dc:creator>
      <dc:date>2017-10-04T02:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't sync</title>
      <link>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7022#M793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For TCP connections, the first packet the Security Gateway expects to see is a TCP SYN.&lt;/P&gt;&lt;P&gt;This packet would then be evaluated by the rulebase to determine whether or not the connection is permitted.&lt;/P&gt;&lt;P&gt;If it sees a TCP packet that is not a SYN and it can be associated with an existing allowed connection, then the packet will pass.&lt;/P&gt;&lt;P&gt;In the case where the TCP packet is NOT a SYN and&amp;nbsp;&lt;STRONG&gt;cannot&lt;/STRONG&gt; be associated with an existing connection, you see this error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you search on the phrase "First packet isn't SYN" in&amp;nbsp;&lt;A href="http://supportcenter.checkpoint.com/"&gt;SecureKnowledge&lt;/A&gt;, there are several possible reasons this might occur.&lt;/P&gt;&lt;P&gt;In your case, it looks like a FIN-ACK packet has been received.&lt;/P&gt;&lt;P&gt;These are associated with closing a TCP connection gracefully.&lt;/P&gt;&lt;P&gt;The Security Gateway had already aged out the connection from the connections table, which happens after the TCP End Timeout (40 seconds by default, as I recall).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Oct 2017 04:50:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7022#M793</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-04T04:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't sync</title>
      <link>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7023#M794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How can we resolve this ? do we increase the TCP end timeout?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Oct 2017 05:06:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7023#M794</guid>
      <dc:creator>dorj_erdeneochi</dc:creator>
      <dc:date>2017-10-04T05:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't sync</title>
      <link>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7024#M795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, this would be an option to consider and try.&lt;/P&gt;&lt;P&gt;Another option would be configuring and exception as described in &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk11088"&gt;sk11088&lt;/A&gt; with &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk98239"&gt;sk98239&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Oct 2017 05:50:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7024#M795</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2017-10-04T05:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't sync</title>
      <link>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7025#M796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would first check routing. Make sure, out and in packets use same route and same checkpoints inerface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Oct 2017 07:00:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7025#M796</guid>
      <dc:creator>MK9</dc:creator>
      <dc:date>2017-10-04T07:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't sync</title>
      <link>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7026#M797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;create a new service for the interested connections and increase his session timeout if it is really needed &lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/59482_pastedImage_2.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;do not modify stateful inspection settings or any file on your management &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/grin.png" /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Oct 2017 07:40:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7026#M797</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2017-10-04T07:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't sync</title>
      <link>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7027#M798</link>
      <description>&lt;P&gt;If I see an "out of state" error and the TCP flags involved are FIN and/or RST, I generally ignore them as they tend to be harmless in the majority of cases.&amp;nbsp; It simply indicates that the subject connection was not terminated cleanly as far as the firewall is concerned; this can be caused by many things including poorly-written applications and transient network and/or system problems.&amp;nbsp; However if these "out of state" logs for RST/FIN are conclusively correlated with application performance problems, TCP state logging (sk101221) and sending a TCP RST upon connection expiration (sk19746) can be useful here.&amp;nbsp; The former SK was covered in my book, while the latter SK was mentioned in the addendum to my book available for free at the URL below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But the following combinations in an "out of state" error message will tend to get my attention:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SYN-ACK - Strong indicator of asymmetric routing on the forward path (from the connection's perspective), where the firewall is only seeing the return direction of the TCP 3-way handshake.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ACK all by itself - Probably asymmetric routing on the return path (from the connection's perspective). &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ACK accompanied by PSH (or perhaps just ACK by itself) - The connection was timed out by the firewall due to inactivity.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--&lt;BR /&gt;My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt;now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank" rel="noopener"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jul 2019 21:03:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7027#M798</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-07-06T21:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: First packet isn't SYN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7028#M799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The issue with FIN-ACK can also arise if you have software blades (HTTPS interception,...) on that check the content.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For HTTPS see:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk118415&amp;amp;partition=Advanced&amp;amp;product=HTTPS" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk118415&amp;amp;partition=Advanced&amp;amp;product=HTTPS"&gt;TCP [FIN-ACK] packets for HTTPS traffic are dropped as out-of-state after enabling HTTPS Inspection&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2018 13:13:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7028#M799</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-07-07T13:13:55Z</dc:date>
    </item>
  </channel>
</rss>

