- Products
- Learn
- Local User Groups
- Partners
- More
The industry's first AI Network Firewall
Securing AI traffic, everywhere
On-Premises SD-WAN Management
Watch Here AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
No Attack Required
Hi
From the begining, I'm networking guy not "VoIP telephony" guy.
One VPN is fully functional, except SIP Traffic. My host sends SIP Invite. Packet arrive to destination. The other host Answer to SIP invite, but the pachet is dropped on checkpoint site. I ran fw ctl zdebug drop | grep d.d.d.2
Packet proto=17 a.a.a.2:5060 -> d.d.d.123:5066 dropped by fw_one_way_enforcement Reason: conn oneway violated
What I did: I defined a rulebase traffic between hosts to be accepted on custom defined services on UDP port 5060 and 5066. I unchecked "MatchAny" on custom service definition and also I checked "Accept Replies".
I put in exception for traffic inspection... nothing is working.
What shall I do more?
I know, I feel the same, haha. VOIP has to be my least favorite "subject" when it comes to any vendor, honestly. I hate to tell you this, but if you have TAC case going on, I am 100% positive they will ask you to review below and see what applies to you:
Now, let me take a "stab at this". So, logically, based on your drop message, we can see its dropping traffic on port 5066, since all we really care is destination port. Can you send a screenshot how you defined it?
Ok, so let me ask you this...which scenario from the sk applies to you?
SIP Proxy to SIP Proxy but there is no NAT involoved and communication between SIP proxies is thru a VPN.
so 7-1-C section?
Yes. This is the section
Are you able to send rule screenshot please?
Services look different than whats defined in the sk.
In 2nd example, it only shows you would have single service as it defines word or, not and.
even with a single sip service, the error is the same
dropped by fw_one_way_enforcement Reason: conn oneway violated
Ok, fair enough...in that case, I would reach out to TAC to debug it further. That error, to me anyway, logically would indicate that it does not like something either about the service property settings and connection gets terminated. Please share here once you find the solution.
Thank you anyhow.
No worries. One other thing I would do is run fw monitor to make sure it takes correct path at least. If it does, then yea, Im pretty sure debugs might be needed.
Below is all I found on that error on support site, but Im sure you already seen those.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 120 | |
| 94 | |
| 15 | |
| 12 | |
| 11 | |
| 8 | |
| 8 | |
| 6 | |
| 6 | |
| 6 |
Thu 06 Aug 2026 @ 11:00 AM (EDT)
Tipis and Tricks 2026 #10: Zero‑Downtime Migration to Smart‑1 CloudThu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 06 Aug 2026 @ 11:00 AM (EDT)
Tipis and Tricks 2026 #10: Zero‑Downtime Migration to Smart‑1 CloudThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 25 Aug 2026 @ 05:00 PM (CEST)
The State of Ransomware Q2 2026: This Quarter's Trends, and Their Impact on Your DefensesThu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de SeguridadAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY