- Products
- Learn
- Local User Groups
- Partners
- More
What's New in Check Point SASE
Wednesday, 9 September @ 5pm CET / 11am EDT
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hi
From the begining, I'm networking guy not "VoIP telephony" guy.
One VPN is fully functional, except SIP Traffic. My host sends SIP Invite. Packet arrive to destination. The other host Answer to SIP invite, but the pachet is dropped on checkpoint site. I ran fw ctl zdebug drop | grep d.d.d.2
Packet proto=17 a.a.a.2:5060 -> d.d.d.123:5066 dropped by fw_one_way_enforcement Reason: conn oneway violated
What I did: I defined a rulebase traffic between hosts to be accepted on custom defined services on UDP port 5060 and 5066. I unchecked "MatchAny" on custom service definition and also I checked "Accept Replies".
I put in exception for traffic inspection... nothing is working.
What shall I do more?
I know, I feel the same, haha. VOIP has to be my least favorite "subject" when it comes to any vendor, honestly. I hate to tell you this, but if you have TAC case going on, I am 100% positive they will ask you to review below and see what applies to you:
Now, let me take a "stab at this". So, logically, based on your drop message, we can see its dropping traffic on port 5066, since all we really care is destination port. Can you send a screenshot how you defined it?
Ok, so let me ask you this...which scenario from the sk applies to you?
SIP Proxy to SIP Proxy but there is no NAT involoved and communication between SIP proxies is thru a VPN.
so 7-1-C section?
Yes. This is the section
Are you able to send rule screenshot please?
Services look different than whats defined in the sk.
In 2nd example, it only shows you would have single service as it defines word or, not and.
even with a single sip service, the error is the same
dropped by fw_one_way_enforcement Reason: conn oneway violated
Ok, fair enough...in that case, I would reach out to TAC to debug it further. That error, to me anyway, logically would indicate that it does not like something either about the service property settings and connection gets terminated. Please share here once you find the solution.
Thank you anyhow.
No worries. One other thing I would do is run fw monitor to make sure it takes correct path at least. If it does, then yea, Im pretty sure debugs might be needed.
Below is all I found on that error on support site, but Im sure you already seen those.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 11 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 |
Tue 08 Sep 2026 @ 10:00 AM (CEST)
Keeping Pace with AI-Powered Threats: A New Approach to Closing Security Gaps Faster - EMEATue 08 Sep 2026 @ 05:00 PM (CEST)
Keeping Pace with AI-Powered Threats: A New Approach to Closing Security Gaps Faster - AmericasWed 09 Sep 2026 @ 11:00 AM (EDT)
What's New in Check Point SASE: Extending Secure Connectivity to China and BeyondTue 08 Sep 2026 @ 10:00 AM (CEST)
Keeping Pace with AI-Powered Threats: A New Approach to Closing Security Gaps Faster - EMEATue 08 Sep 2026 @ 05:00 PM (CEST)
Keeping Pace with AI-Powered Threats: A New Approach to Closing Security Gaps Faster - AmericasThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY