<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cyclic series of blocked connections hanging network in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29220#M1189</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Certainly all of this stuff is "in scope."&lt;/P&gt;&lt;P&gt;Maybe not in this space, but it's related to this discussion, so it's fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're troubleshooting issues, logging can be your friend &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;That said, too much logging makes it harder to see what's actually going on.&lt;/P&gt;&lt;P&gt;Historically, I've "accepted and not logged" things like:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SMB traffic to the LAN broadcast segment&lt;/LI&gt;&lt;LI&gt;DHCP-related traffic&lt;/LI&gt;&lt;LI&gt;VRRP-related traffic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;But to make a general statement that everyone shouldn't log these things ignores many factors that may be relevant in some circumstances.&lt;/P&gt;&lt;P&gt;That said, for an end-user consumer, that advice is probably reasonable.&lt;/P&gt;&lt;P&gt;In your network, you might find other things that are "noise" that can be safely not logged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally speaking, the few IoT devices I do have are mostly on a seperate WiFi network from my end users.&lt;/P&gt;&lt;P&gt;Chromecasts and other "streaming media" devices are a little more difficult to do that with since they need another device from the local network to say what streams to it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would heavily log what these devices do at first and turn the logging down as you are comfortable with what they're doing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 03 Feb 2019 21:35:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-02-03T21:35:49Z</dc:date>
    <item>
      <title>Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29210#M1179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm having an issue with a cyclic series of blocked connections. I'm not sure this is the right place to ask this question, or if I should even ask.&amp;nbsp; Since I'm not industry-experienced yet I use a licensed GAIA appliance on my home network without a support contract, I've never bothered anyone at this level.&amp;nbsp; However I'm at a loss as to what's happening on my network, and without some understanding, I'm not going to be able to resolve the issue. If there is a better place to ask this question please point me there.&amp;nbsp; If I'm out of line, say so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #000000; font-family: verdana,geneva,lucida,'lucida grande',arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;I'm not necessarily asking to have the problem solved for me, but to help me understand the dynamic so I can solve it. &lt;/SPAN&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #000000; font-family: verdana,geneva,lucida,'lucida grande',arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;This started happening two evenings ago where the firewall is blocking the traffic shown in the attached screenshots. At times this gets so intense it functions like a DOS attack.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #000000; font-family: verdana,geneva,lucida,'lucida grande',arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt; &lt;/SPAN&gt;&lt;BR style="color: #000000; font-family: verdana,geneva,lucida,&amp;amp;quot; lucida grande&amp;amp;quot;,arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;" /&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #000000; font-family: verdana,geneva,lucida,'lucida grande',arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt; The first pic is of the blocked connections, the second is active connections, and the third is active devices on the network.&amp;nbsp;&lt;/SPAN&gt;&lt;BR style="color: #000000; font-family: verdana,geneva,lucida,&amp;amp;quot; lucida grande&amp;amp;quot;,arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;" /&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #000000; font-family: verdana,geneva,lucida,'lucida grande',arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt; &lt;/SPAN&gt;&lt;BR style="color: #000000; font-family: verdana,geneva,lucida,&amp;amp;quot; lucida grande&amp;amp;quot;,arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;" /&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #000000; font-family: verdana,geneva,lucida,'lucida grande',arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt; The 100.72.0.2 is attempting to contact an IANA Root Server at 224.0.0.18, and is on the same subnet as my WAN IP (100.72.0.85). &lt;/SPAN&gt;&lt;BR style="color: #000000; font-family: verdana,geneva,lucida,&amp;amp;quot; lucida grande&amp;amp;quot;,arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;" /&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #000000; font-family: verdana,geneva,lucida,'lucida grande',arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt; &lt;/SPAN&gt;&lt;BR style="color: #000000; font-family: verdana,geneva,lucida,&amp;amp;quot; lucida grande&amp;amp;quot;,arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;" /&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #000000; font-family: verdana,geneva,lucida,'lucida grande',arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;My LAN gateway is 192.168.2.0, and 192.168.2.4 is a WD MyCloud EX2 (installed a Jan/2019 FW update yesterday after reading about vulnerabilities - nothing changed) that is using NetBIOS and getting accepted at 192.168.2.255. It's also making UDP connections to an external IP address that ICANN returns null when I run a reverse IP lookup.&lt;/SPAN&gt;&lt;BR style="color: #000000; font-family: verdana,geneva,lucida,&amp;amp;quot; lucida grande&amp;amp;quot;,arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;" /&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #000000; font-family: verdana,geneva,lucida,'lucida grande',arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt; &lt;/SPAN&gt;&lt;BR style="color: #000000; font-family: verdana,geneva,lucida,&amp;amp;quot; lucida grande&amp;amp;quot;,arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;" /&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #000000; font-family: verdana,geneva,lucida,'lucida grande',arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt; The 0.0.0.0 trying to connect to 255.255.255.255 simply baffles me.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="display: inline !important; float: none; background-color: #ffffff; color: #000000; font-family: verdana,geneva,lucida,'lucida grande',arial,helvetica,sans-serif; font-size: 13.33px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;This 730 NGTP WiFi appliance will not operate dual-band, therefore I have my old SG640 bridged to its LAN on 192.168.2.1 so that I can utilize 2.4 MHz WiFi. Firewall and WAN are turned off on the SG640.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 18:30:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29210#M1179</guid>
      <dc:creator>Steven_Prester</dc:creator>
      <dc:date>2019-01-31T18:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29211#M1180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First, the 730 is an &lt;A href="https://community.checkpoint.com/space/2036"&gt;SMB and SMP&lt;/A&gt;‌ product, so this post should go in the appropriate space.&lt;/P&gt;&lt;P&gt;Second, there's nothing in these logs that is particularly unusual.&lt;/P&gt;&lt;P&gt;Maybe the volume of these packets is creating an issue.&lt;/P&gt;&lt;P&gt;Creating explicit rules that don't log the traffic below&amp;nbsp;might help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;224.0.0.18 is&amp;nbsp;a multicast address associated with&amp;nbsp;&lt;A class="link-titled" href="https://en.wikipedia.org/wiki/Virtual_Router_Redundancy_Protocol" title="https://en.wikipedia.org/wiki/Virtual_Router_Redundancy_Protocol"&gt;Virtual Router Redundancy Protocol&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Your ISP is likely using it to provide redundancy for&amp;nbsp;the default route.&lt;/P&gt;&lt;P&gt;These are not directed at you, but your 730 is receiving them.&lt;/P&gt;&lt;P&gt;You can safely ignore/not log these.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your&amp;nbsp;WD MyCloud EX2 supports SMB/Windows filesharing, then seeing traffic sent to the broadcast address (.255) from it is perfectly normal and not worth logging.&lt;/P&gt;&lt;P&gt;As for your&amp;nbsp;WD MyCloud EX2 reaching out and touching the Internet,&amp;nbsp;you should contact them to find out why it's doing it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;0.0.0.0 contacting 255.255.255.255 is the first packet in a DHCP exchange.&lt;/P&gt;&lt;P&gt;Most likely, you're seeing traffic from everyone else who shares the same segment as you on your ISP.&lt;/P&gt;&lt;P&gt;These packets can be safely ignored (and not logged).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Feb 2019 03:48:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29211#M1180</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-02T03:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29212#M1181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate your reply and I will follow your directives.  I don’t care to use the MyCloud except for local storage so I will see what I have to do to cut its access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don’t frequently check my logs but over the past couple weeks I’ve had interruptions in service, so when I looked I recognized these were not previously being logged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That these requests are normal, or at least acceptable, and are now being logged, tells me something probably changed in a FW update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I’ve been on Allo Comm fiber for the past year and have been forced to reboot the router maybe twice.  However, I’ve recently had issues with WiFi (most of my connections are copper) dropping out, and that’s required a reboot of the 720.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I’ll se if I can relocate this post and if not I’ll remove it.  Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2019 04:28:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29212#M1181</guid>
      <dc:creator>Steven_Prester</dc:creator>
      <dc:date>2019-02-03T04:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29213#M1182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I moved the post already, no action on your part required.&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;WiFi "dropping out" is definitely a different issue than your initial description of the issue implied.&lt;/P&gt;&lt;P&gt;That, in theory, would not be caused by externally received traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWIW the current version of firmware is&amp;nbsp;R77.20.85 (990172731), though I believe a new build is planned shortly.&lt;/P&gt;&lt;P&gt;If you don't have a support agreement in place, you won't be able to download from our support site, though the device should eventually be offered the latest firmware in the WebUI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2019 04:59:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29213#M1182</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-03T04:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29214#M1183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I just seen that you moved it. No, I wasn’t implying I thought the WiFi was related to what’s happening in the logs. I guess I was just explaining what got me poking around.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I’ve had 3 licensed, CP SMB appliances since 2011 and I’m now in the 2nd year of a 3-yr license on this 730. I guess what I mean is I have blade subscriptions, but no support agreement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Honestly, over the past 8 years I’ve had no significant issues, peace of mind and a clean network. I would never go back to a consumer-level routing device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2019 05:11:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29214#M1183</guid>
      <dc:creator>Steven_Prester</dc:creator>
      <dc:date>2019-02-03T05:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29215#M1184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I’m on R77.20.81 (990172541).  I’m assuming this will auto update sometime soon.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2019 05:14:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29215#M1184</guid>
      <dc:creator>Steven_Prester</dc:creator>
      <dc:date>2019-02-03T05:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29216#M1185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have successfully quelled everything but the 0.0.0.0  to  255.255.255.255.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My rules are in the 2nd screenshot.  Any thought on why I’m not silencing this request?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2019 05:52:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29216#M1185</guid>
      <dc:creator>Steven_Prester</dc:creator>
      <dc:date>2019-02-03T05:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29217#M1186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Change the source in Rule 5 to Any.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2019 07:15:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29217#M1186</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-03T07:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29218#M1187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you bought a 3 year blade subscription for the SMB appliances, you also have a support contact.&lt;/P&gt;&lt;P&gt;That's what your UserCenter account says you have. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;This means you should be able to access &lt;A href="https://usercenter.checkpoint.com"&gt;UserCenter&lt;/A&gt;&amp;nbsp;and download the latest firmware.&lt;/P&gt;&lt;P&gt;See:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk140193" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk140193"&gt;R77.20.85 for Small and Medium Business Appliances&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2019 07:23:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29218#M1187</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-03T07:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29219#M1188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That worked.  It’s now interesting to coherently visualize the remaining traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What qualifies any given “Accept“ traffic to get logged?  Do I want to be logging traffic such as a Dropbox data sync between clients?  Where should I draw the line for logging presumably legitimate internal network traffic on a private network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the security log is crammed with legit or extraneous traffic it seems to me it renders the log rather useless for looking at the real-time health of the network.  I realize I can search the log but that still isn’t the same as seeing real-time patterns of traffic that may be causing issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I’m also wondering what a balanced approach would be as I begin to deploy a significant number of custom IoT devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I’m assuming Cyber Security Evangelism is concerned with the health of the internet as IoT devices proliferate in the hands of the Cyber laity.  I’m retired from Healthcare IT consulting (software) where I was never responsible for the network, yet I know enough to have a healthy respect for cyber security, and it genuinely concerns me there can become so many unsecured nooks and crannies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this question is out of the scope of our discussion, can you point me to a place where it would be in scope?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2019 18:37:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29219#M1188</guid>
      <dc:creator>Steven_Prester</dc:creator>
      <dc:date>2019-02-03T18:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29220#M1189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Certainly all of this stuff is "in scope."&lt;/P&gt;&lt;P&gt;Maybe not in this space, but it's related to this discussion, so it's fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're troubleshooting issues, logging can be your friend &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;That said, too much logging makes it harder to see what's actually going on.&lt;/P&gt;&lt;P&gt;Historically, I've "accepted and not logged" things like:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SMB traffic to the LAN broadcast segment&lt;/LI&gt;&lt;LI&gt;DHCP-related traffic&lt;/LI&gt;&lt;LI&gt;VRRP-related traffic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;But to make a general statement that everyone shouldn't log these things ignores many factors that may be relevant in some circumstances.&lt;/P&gt;&lt;P&gt;That said, for an end-user consumer, that advice is probably reasonable.&lt;/P&gt;&lt;P&gt;In your network, you might find other things that are "noise" that can be safely not logged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generally speaking, the few IoT devices I do have are mostly on a seperate WiFi network from my end users.&lt;/P&gt;&lt;P&gt;Chromecasts and other "streaming media" devices are a little more difficult to do that with since they need another device from the local network to say what streams to it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would heavily log what these devices do at first and turn the logging down as you are comfortable with what they're doing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2019 21:35:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29220#M1189</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-03T21:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cyclic series of blocked connections hanging network</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29221#M1190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Again, just what I was looking for.&lt;/P&gt;&lt;P&gt;Much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Get Outlook for iOS&amp;lt;https://aka.ms/o0ukef&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2019 16:09:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cyclic-series-of-blocked-connections-hanging-network/m-p/29221#M1190</guid>
      <dc:creator>Steven_Prester</dc:creator>
      <dc:date>2019-02-04T16:09:04Z</dc:date>
    </item>
  </channel>
</rss>

