cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted
Nickel

After firewall restart many logs with DROP action appeared on port 8116.

Good afternoon sirs.
After a scheduled maintenance, the firewall was restarted. From this point the firewall started to generate many DROP logs on port 8116 (range_udp_1024-65535). Source IP addresses start with 0.0.0.x toward the corporate network. When opening one of the logs I saw that the reason was EARLY DROP (SK111643). The rule that made the drop was the CPEarlyDrop. Analyzing SK111643 I saw that the firewall can discard packets based on a unified policy column, but I do not understand why this behavior with packets coming from these strange addresses (0.0.0.x) towards the corporate network and that port 8116 is used by Check Point to cluster. Anyone have an idea?
0 Kudos
4 Replies
Highlighted
Admin
Admin

Re: After firewall restart many logs with DROP action appeared on port 8116.

UDP port 8116 is CCP packets related to ClusterXL.
Are you seeing traffic from 0.0.0.x on the wire (e.g. with tcpdump) or just in your logs?
Also, what version/jumbo hotfix level of code are we talking about?
Highlighted
Nickel

Re: After firewall restart many logs with DROP action appeared on port 8116.

Sirs, sorry for the delay in answering. After searching i discovered that the firewall was not using the traditional MULTICAST address (224.0.0.0 - 239.255.255.255) to exchange packets from CLUSTER (CCP). I ran the fwha_ccp_use_mcast_base = 1 command in the two CLUSTER boxes and the problem was deleted. Thanks.

 

https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&eve...

0 Kudos
Highlighted

Re: After firewall restart many logs with DROP action appeared on port 8116.

Please check if you are using Drop Templates

Highlighted
Nickel

Re: After firewall restart many logs with DROP action appeared on port 8116.

Sorry for the delay. After research I discovered that the firewalls were not using the traditional MULTICAST address (224.0.0.0 - 239.255.255.255) in the cluster packet exchange (CCP). I ran the fwha_ccp_use_mcast_base = 1 command and the problem was deleted. Thanks. I used sk115142.

0 Kudos