<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro return traffic dropped by other SGM in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/129766#M610</link>
    <description>&lt;P&gt;Same issue here on &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170114" target="_self"&gt;R81 JHF 42&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;We set up a new Maestro single-site environment with two 7000 appliances running in Active/Active mode.&lt;BR /&gt;Return packets are dropped, even in Active/Down mode via &lt;CODE&gt;clusterXL_admin down&lt;/CODE&gt;.&lt;/P&gt;
&lt;P&gt;Stopping the other SG member via &lt;CODE&gt;cpstop&lt;/CODE&gt; temporarily fixes the issue.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Drop reason for SSH return packets:
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="color: red;"&gt;action:Drop sport:443 ssh_version_2-Protocol-Signature&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Drop reason for VPN return packets (&lt;EM&gt;separate 3rd party VPN server in a DMZ&lt;/EM&gt;)&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="color: red;"&gt;action:Drop sport:4500 snmp-Protocol-Signature&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 831px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13747i9CC3C202B6C8F270/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The drops seem to appear from the other member that is not correctly synced.&lt;/P&gt;
&lt;P&gt;Load Balancing / Distribution mode is set to &lt;STRONG&gt;policy&lt;/STRONG&gt; (&lt;EM&gt;Default&lt;/EM&gt;).&lt;BR /&gt;The VPN symptoms only appear if we change distribution mode on the relavent interface to &lt;STRONG&gt;network&lt;/STRONG&gt; (&lt;EM&gt;we are doing this because of &lt;A href="https://community.checkpoint.com/t5/Maestro/Maestro-R81-has-issues-in-Active-Active-mode-with-Identity/m-p/129157/highlight/true#M609" target="_self"&gt;other Maestro issues&lt;/A&gt;&lt;/EM&gt;).&lt;/P&gt;</description>
    <pubDate>Mon, 20 Sep 2021 10:13:46 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2021-09-20T10:13:46Z</dc:date>
    <item>
      <title>Maestro return traffic dropped by other SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/102718#M377</link>
      <description>&lt;P&gt;We have a strange issue where we have a server indirectly attached to a Maestro VSX environment and the VS has a host route for this host. Now when this host pings a specific host on the other side of the VS we see the traffic pass through, lets say SGM 1_2, but we see the return traffic being dropped by SGM 1_4.&lt;/P&gt;
&lt;P&gt;With SSH and RDP sessions we sometimes see them completing and working and about 30% of the time also the return traffic is dropped.&lt;/P&gt;
&lt;P&gt;The weird thing is that this is only happening between these specific hosts.&lt;/P&gt;
&lt;P&gt;Other sessions all seem to work just fine.&lt;/P&gt;
&lt;P&gt;Version MHO: R80.20SP JHF 304&lt;/P&gt;
&lt;P&gt;Version SGM: R80.30SP JHF 49&lt;/P&gt;
&lt;P&gt;Distribution mode: Auto Topology/L4 enabled, however L4 disabled has also been tested, same result.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 17:57:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/102718#M377</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-11-19T17:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro return traffic dropped by other SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/102724#M378</link>
      <description>&lt;P&gt;What's the actual drop reason? No matching rule for return traffic? That is B -&amp;gt; A? It's been couple of months since I touched scalable platform and it was R76SP but feels like flow correction is failing for some reason? Can you manually calculate which SGMs are supposed to be involved? Not too sure though how it looks in R80.. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 18:26:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/102724#M378</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-11-19T18:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro return traffic dropped by other SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/102733#M379</link>
      <description>&lt;P&gt;The ping reply was dropped with a no corresponding ICMP request and for the other connections we get a out of state packet drop. We had the same idea that for some reason only for this specific pair the flow correction is just not working.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 22:29:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/102733#M379</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-11-19T22:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro return traffic dropped by other SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/102785#M381</link>
      <description>&lt;P&gt;On the environment you mentioned, I did a test where I only allowed 1 SGM to be active, meaning that I disabled all the other SGM's. The traffic was flowing fine without any problems! Once I enabled the other SGM's again, the errors came back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An example error:&lt;/P&gt;&lt;P&gt;On SGM 1_3 an Echo Request came from server A to server B. In the same second an Echo Reply came from SGM 1_1 that server B to server A that was dropped because of the message "ICMP reply does not match a previous request".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I changed the Distribution Mode from Auto Topology to Manual General, traffic was flowing fine and the issue was resolved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Eamon Jones&lt;/P&gt;</description>
      <pubDate>Mon, 22 Nov 2021 10:53:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/102785#M381</guid>
      <dc:creator>Jones</dc:creator>
      <dc:date>2021-11-22T10:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro return traffic dropped by other SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/129766#M610</link>
      <description>&lt;P&gt;Same issue here on &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170114" target="_self"&gt;R81 JHF 42&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;We set up a new Maestro single-site environment with two 7000 appliances running in Active/Active mode.&lt;BR /&gt;Return packets are dropped, even in Active/Down mode via &lt;CODE&gt;clusterXL_admin down&lt;/CODE&gt;.&lt;/P&gt;
&lt;P&gt;Stopping the other SG member via &lt;CODE&gt;cpstop&lt;/CODE&gt; temporarily fixes the issue.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Drop reason for SSH return packets:
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="color: red;"&gt;action:Drop sport:443 ssh_version_2-Protocol-Signature&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Drop reason for VPN return packets (&lt;EM&gt;separate 3rd party VPN server in a DMZ&lt;/EM&gt;)&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="color: red;"&gt;action:Drop sport:4500 snmp-Protocol-Signature&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 831px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13747i9CC3C202B6C8F270/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The drops seem to appear from the other member that is not correctly synced.&lt;/P&gt;
&lt;P&gt;Load Balancing / Distribution mode is set to &lt;STRONG&gt;policy&lt;/STRONG&gt; (&lt;EM&gt;Default&lt;/EM&gt;).&lt;BR /&gt;The VPN symptoms only appear if we change distribution mode on the relavent interface to &lt;STRONG&gt;network&lt;/STRONG&gt; (&lt;EM&gt;we are doing this because of &lt;A href="https://community.checkpoint.com/t5/Maestro/Maestro-R81-has-issues-in-Active-Active-mode-with-Identity/m-p/129157/highlight/true#M609" target="_self"&gt;other Maestro issues&lt;/A&gt;&lt;/EM&gt;).&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 10:13:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/129766#M610</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2021-09-20T10:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro return traffic dropped by other SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/140499#M781</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Is there any fix or solution for this issue?&lt;/P&gt;&lt;P&gt;I have exactly the same issue - new installation of maestro environment version R81.10 HFA #22.&lt;/P&gt;&lt;P&gt;Thanks for reply,&lt;/P&gt;&lt;P&gt;Zbynek&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 12:32:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/140499#M781</guid>
      <dc:creator>Zbynek</dc:creator>
      <dc:date>2022-02-04T12:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro return traffic dropped by other SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/140502#M782</link>
      <description>&lt;P&gt;The solution is described &lt;A href="https://community.checkpoint.com/t5/Maestro/Question-about-distribution-mode-settings/m-p/136992/highlight/true#M703" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 12:55:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/140502#M782</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2022-02-04T12:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro return traffic dropped by other SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/150060#M931</link>
      <description>&lt;P&gt;I have quite a similar issue.&lt;/P&gt;&lt;P&gt;Dual site, dual MHO&amp;nbsp; with 8 SGMs and two SGs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SG1 has only one SGM from site1&lt;/P&gt;&lt;P&gt;SG2 has one SGM from site 1 and one SGM from site 2 -&amp;gt; working fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in SG1 when I add another SGM (it doesn't matter if it's from site 1 or site 2) some strange traffic issues are reported. Some connections (ping, http, rdp, ssh) are not working but only for some users and not for all of them.&lt;/P&gt;&lt;P&gt;As I could not identify issue with logging (as I can't (or I don't know) how to filter for members (like 1_1 or 1_2) I could not relate this to a return traffic issue.&lt;/P&gt;&lt;P&gt;I do have to mention that &lt;STRONG&gt;all&lt;/STRONG&gt; interfaces are &lt;STRONG&gt;bond&lt;/STRONG&gt; with Active/Standby (Activ in MHO1, Standby in MHO2) - identical for both site1 and site 2.&lt;/P&gt;&lt;P&gt;Also L4 distribution is disabled and Distribution mode is auto (per-port).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea on how to start the investigation ?&lt;/P&gt;&lt;P&gt;Really appreciate your effort.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 20:34:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/150060#M931</guid>
      <dc:creator>melkool</dc:creator>
      <dc:date>2022-06-02T20:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro return traffic dropped by other SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/150978#M945</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. what is the topology of the interfaces (inbound and outbound) involved to the communication?&lt;/P&gt;
&lt;P&gt;2. did you check the routing? Is asymmetric routing in place?&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;What are the C2S interfaces in the communication flow,&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;what are the S2C interfaces in the communication flow?&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Did you perform g_tcpdump for this traffic?&lt;/P&gt;
&lt;P&gt;3. General question: Is the chassis performing Number of Hide NAT sessions?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Jochen&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 16:23:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/150978#M945</guid>
      <dc:creator>Jochen_Hoechner</dc:creator>
      <dc:date>2022-06-15T16:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro return traffic dropped by other SGM</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/180122#M1557</link>
      <description>&lt;P&gt;Could you be kind and explain to me like I am 5 on how to resolve this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My scenario&lt;/P&gt;
&lt;P&gt;Site to Site vpn. From the same subnet on checkpoint I can connect to one of the remote subnets no problem, but to another subnet all the return traffic is dropped.&lt;/P&gt;
&lt;P&gt;The working one the traffic goes out and back via SG1_02&lt;/P&gt;
&lt;P&gt;Broken subnet it goes out via SG1_02 but comes back via SG1_03 and all protocols get dropped with an out of state error&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;New to Maestro so not really understanding what I need to do to fix. thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show distribution configuration&lt;BR /&gt;Distribution Mode: auto-topology (per-port)&lt;/P&gt;</description>
      <pubDate>Sat, 06 May 2023 03:53:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-return-traffic-dropped-by-other-SGM/m-p/180122#M1557</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2023-05-06T03:53:49Z</dc:date>
    </item>
  </channel>
</rss>

