<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R1200 Gateway Monitor Interface  in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29906#M1227</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that as been tried.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point here is that even in monitor mode we need to see the&amp;nbsp; TCP 3 way handshake to detect a session being formed. After this we can see the scada commands inside the TCP session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if the gateway reboots for example, you will loose visibility on the already established sessions.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This will force the costumer to reset the TCP sessions on the scada devices or at least to have someone looking on them, rebooting them, and so on...&lt;BR /&gt;&lt;BR /&gt;In very large environments that is not pratical in the costumer perspective&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Aug 2018 20:24:37 GMT</pubDate>
    <dc:creator>Marco_Vicente1</dc:creator>
    <dc:date>2018-08-01T20:24:37Z</dc:date>
    <item>
      <title>R1200 Gateway Monitor Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29897#M1218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a R1200 gateway with a interface running in monitor mode with a mirror on a switch pointing to the monitor interfaces. We notice that after we connect the interface to the switch all the tcp session that where already estabilshed dont see in the logs or application categorization, only tcp sessions that the syn-synack and ack was seen in the monitor mode appers in the log/events. Is this behavior normal for a monitor interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Patricio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Jun 2018 22:24:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29897#M1218</guid>
      <dc:creator>Patricio_Cachac</dc:creator>
      <dc:date>2018-06-09T22:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: R1200 Gateway Monitor Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29898#M1219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By default, connections where the TCP handshake is not observed are considered "out of state" and would be dropped if the gateway were inline.&lt;/P&gt;&lt;P&gt;As such, what you're seeing is expected behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can disable this "out of state" check a couple of ways:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102491" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102491"&gt;How to configure the Security Gateway to drop Out of State TCP packets&lt;/A&gt;&amp;nbsp;(if managed by SmartCenter)&lt;/LI&gt;&lt;LI&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117374" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117374"&gt;How to enable/disable Out of State inspection on a Security Gateway without performing a policy installation&lt;/A&gt;&amp;nbsp;(should work even if locally managed, but setting does not survive a reboot)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Note this applies for all interfaces (not just mirror port).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jun 2018 00:37:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29898#M1219</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-10T00:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: R1200 Gateway Monitor Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29899#M1220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. We already have use that option but with no success. The setup that we have is the R1200 with a interface in monitor mode capturing all the traffic from the switch, the traffic is a mix from tcp and udp, for udp we don’t have this issue but for tcp we don’t see any traffic as all the sessions are already stablished and we can not reset then as this is an industrial environment with SCADA traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help,&lt;/P&gt;&lt;P&gt;Patricio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jun 2018 13:01:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29899#M1220</guid>
      <dc:creator>Patricio_Cachac</dc:creator>
      <dc:date>2018-06-10T13:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: R1200 Gateway Monitor Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29900#M1221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;UDP traffic is stateless, so that makes sense.&lt;/P&gt;&lt;P&gt;Are you managing the 1200R locally or using a SmartCenter management?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2018 01:23:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29900#M1221</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-11T01:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: R1200 Gateway Monitor Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29901#M1222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are managing with smart center.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2018 05:58:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29901#M1222</guid>
      <dc:creator>Patricio_Cachac</dc:creator>
      <dc:date>2018-06-11T05:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: R1200 Gateway Monitor Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29902#M1223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm -5.65pt 2.0pt 42.55pt;"&gt;You did configure it using &lt;EM&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112572&amp;amp;partition=General&amp;amp;product=Small"&gt;sk112572 Monitor Mode on SMB appliances running Gaia Embedded OS &lt;/A&gt;&lt;/EM&gt;?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2018 12:31:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29902#M1223</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-06-12T12:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: R1200 Gateway Monitor Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29903#M1224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checkpoint cant decode estabilished sessions working on monitor mode, this is big problem for scada.&lt;/P&gt;&lt;P&gt;On SCADA tcp sessions&amp;nbsp; ,can last open , for months or years , since the RFP&amp;nbsp; don't seems to enforce any timeout, is up to the SCADA vendor to define.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the end if you put checkpoint in monitor mode and connect to scada network via port mirror .... YOU WILL SEE NOTHING !!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2018 23:02:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29903#M1224</guid>
      <dc:creator>Paulo_Rosa</dc:creator>
      <dc:date>2018-07-13T23:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: R1200 Gateway Monitor Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29904#M1225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Application Control can only identify traffic it sees enough traffic on in order to make a determination.&lt;/P&gt;&lt;P&gt;It's quite possible that there is so little traffic being seen that it's unable to say, conclusively, "it's Application X."&lt;/P&gt;&lt;P&gt;Please get packet traces of the relevant traffic and open a TAC case so we can investigate.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2018 16:13:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29904#M1225</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-16T16:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: R1200 Gateway Monitor Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29905#M1226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you by chance try this?&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102296" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102296"&gt;How to activate inspection on internal traffic on 600/700/1100/1200R/1400 appliances&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2018 17:41:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29905#M1226</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-01T17:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: R1200 Gateway Monitor Interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29906#M1227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that as been tried.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point here is that even in monitor mode we need to see the&amp;nbsp; TCP 3 way handshake to detect a session being formed. After this we can see the scada commands inside the TCP session.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if the gateway reboots for example, you will loose visibility on the already established sessions.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This will force the costumer to reset the TCP sessions on the scada devices or at least to have someone looking on them, rebooting them, and so on...&lt;BR /&gt;&lt;BR /&gt;In very large environments that is not pratical in the costumer perspective&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2018 20:24:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/R1200-Gateway-Monitor-Interface/m-p/29906#M1227</guid>
      <dc:creator>Marco_Vicente1</dc:creator>
      <dc:date>2018-08-01T20:24:37Z</dc:date>
    </item>
  </channel>
</rss>

