<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fwconn_init_links (INBOUND) failed in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/141007#M6361</link>
    <description>&lt;P&gt;This worked for me Heiko.&lt;BR /&gt;&lt;BR /&gt;Customer's cisco was initiating the RTP connection with the Known port 8208 as sPort (opposite to using it as dPort as it should I assume)&lt;BR /&gt;The Ckp was Natting-Patting IP and port, but then the RTP provider was returning the packet with 8208 again.&lt;/P&gt;&lt;P&gt;Since there are no valid symlinks for a return packet on 8208 we were getting "&lt;SPAN&gt;fwconn_init_links (INBOUND) failed"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Having applied the outbound Drop, the connection is always initaited from the provider, which initiates the connection correctly, matches static nat inbound, and works fine.&lt;BR /&gt;&lt;BR /&gt;Juan&lt;/P&gt;</description>
    <pubDate>Wed, 09 Feb 2022 12:23:37 GMT</pubDate>
    <dc:creator>Juan_</dc:creator>
    <dc:date>2022-02-09T12:23:37Z</dc:date>
    <item>
      <title>fwconn_init_links (INBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/51302#M2004</link>
      <description>&lt;P&gt;Has anyone come across a problem with Skype (VoIP calls) working intermittently through a 1400?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes it works perfectly.&amp;nbsp; Other times it doesn't.&amp;nbsp; There's no apparent pattern to when it will or won't work.&lt;/P&gt;&lt;P&gt;The customer has a centrally managed cluster of 1470 appliances and to date we've upgraded the firewall from R77.20.60 to R77.20.86, disabled SecureXL as a test and disabled Protocol Inspection on port 5060 but none of these changes have resolved the issue. The issue manifests itself as follows;&lt;/P&gt;&lt;P&gt;When we call inbound, e.g. mobile phone to Skype DDI&lt;BR /&gt;• Skype rings&lt;BR /&gt;• you can answer the call&lt;BR /&gt;• there is 5-10 seconds of silence (neither party can hear each other)&lt;BR /&gt;• the call disconnects&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When we call outbound,&amp;nbsp; e.g. Skype to a mobile phone&lt;BR /&gt;• we hear the Skype internal ring tone for roughly 5 seconds.&lt;BR /&gt;• the call disconnects.&lt;BR /&gt;• error logged on Check Point (zdebug)&amp;nbsp; &amp;nbsp;fw_log_drop_ex: Packet proto=17 172.30.241.26:51306 -&amp;gt; xx.xx.xx.xx:3478 dropped by fw_handle_first_packet Reason: fwconn_key_init_links (INBOUND) failed;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error seen on the Active cluster member;&lt;BR /&gt;[Expert@rdg3corpfw01]# fw ctl zdebug drop | grep 172.30.241.26&lt;BR /&gt;;[cpu_1];[fw4_1];fw_log_drop_ex: Packet proto=17 172.30.241.26:51306 -&amp;gt; xx.xx.xx.xx:3478 dropped by fw_handle_first_packet Reason: fwconn_key_init_links (INBOUND) failed;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We see the drops every time it fails.&amp;nbsp; When it works there's nothing in zdebug.&amp;nbsp; There are no drops in Tracker that seem relevant either.&lt;/P&gt;&lt;P&gt;I note sk86984, but that refers to custom protocols, so I don't think that applies in this case?&lt;/P&gt;&lt;P&gt;Anyone got any thoughts?&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 19:22:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/51302#M2004</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2019-04-18T19:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: fwconn_init_links (INBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/51303#M2005</link>
      <description>&lt;P&gt;I had that problem, too. I have described it in this article, how you can solve it.&lt;BR /&gt;This is also valid for real gateways and not only for SMB appliances.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/VoIP-Issue-and-SMB-Appliance-600-1000-1200-1400/td-p/40613" target="_self"&gt;VoIP Issue and SMB Appliance (600/1000/1200/1400)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 19:27:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/51303#M2005</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-04-18T19:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: fwconn_init_links (INBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/51304#M2006</link>
      <description>&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64418_pastedImage_1.png" border="0" width="583" height="205" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue debug:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;On the firewall you see a typical issue with the following message if you start: # fw ctl zdebug drop&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue message:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;fwconn_key_init_links (INBOUND) failed&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Solution:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;There are two different Servers on the SIP/RTP provider's side that take part in the process of establishing the SIP/RTP call:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Server for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;SIP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(Management and control)&lt;/LI&gt;
&lt;LI&gt;Server for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;RTP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(Media and Voice Data)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Make sure that the UDP high ports from the internal&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;RTP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;VoIP telephone system to the provider RTP server on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;RTP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;provider's side are dropped by the rule base on appliance:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;RTP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;rules:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create a service for the UDP high ports and use it in an incoming Accept rule, which also has to allow the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;RTP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;ports.&lt;/LI&gt;
&lt;LI&gt;Create a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;drop rule&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;to block&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;outgoing connecti&lt;/STRONG&gt;ons from the Internal RTP server (VoIP telephone system) to the provider's&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;RTP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;server on high UDP ports&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;SIP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;rule:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Create an allow rule for incoming and outgoing&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;SIP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;traffic on UDP port 5060&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64419_pastedImage_1.png" border="0" width="962" height="190" /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 19:29:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/51304#M2006</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-04-18T19:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: fwconn_init_links (INBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/51305#M2007</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;thanks for your quick reply.&amp;nbsp; I don't have access to their phones to test afterwards so I'll forward this on to the customer and ask them to implement the change and then test it&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2019 19:42:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/51305#M2007</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2019-04-18T19:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: fwconn_init_links (INBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/51313#M2008</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Write me if this worked.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;Thanks&lt;/DIV&gt;
&lt;DIV&gt;Heiko&lt;/DIV&gt;</description>
      <pubDate>Thu, 18 Apr 2019 20:03:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/51313#M2008</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-04-18T20:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: fwconn_init_links (INBOUND) failed</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/141007#M6361</link>
      <description>&lt;P&gt;This worked for me Heiko.&lt;BR /&gt;&lt;BR /&gt;Customer's cisco was initiating the RTP connection with the Known port 8208 as sPort (opposite to using it as dPort as it should I assume)&lt;BR /&gt;The Ckp was Natting-Patting IP and port, but then the RTP provider was returning the packet with 8208 again.&lt;/P&gt;&lt;P&gt;Since there are no valid symlinks for a return packet on 8208 we were getting "&lt;SPAN&gt;fwconn_init_links (INBOUND) failed"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Having applied the outbound Drop, the connection is always initaited from the provider, which initiates the connection correctly, matches static nat inbound, and works fine.&lt;BR /&gt;&lt;BR /&gt;Juan&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 12:23:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/fwconn-init-links-INBOUND-failed/m-p/141007#M6361</guid>
      <dc:creator>Juan_</dc:creator>
      <dc:date>2022-02-09T12:23:37Z</dc:date>
    </item>
  </channel>
</rss>

