Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
wislleym
Contributor

After firewall restart many logs with DROP action appeared on port 8116.

Good afternoon sirs.
After a scheduled maintenance, the firewall was restarted. From this point the firewall started to generate many DROP logs on port 8116 (range_udp_1024-65535). Source IP addresses start with 0.0.0.x toward the corporate network. When opening one of the logs I saw that the reason was EARLY DROP (SK111643). The rule that made the drop was the CPEarlyDrop. Analyzing SK111643 I saw that the firewall can discard packets based on a unified policy column, but I do not understand why this behavior with packets coming from these strange addresses (0.0.0.x) towards the corporate network and that port 8116 is used by Check Point to cluster. Anyone have an idea?
0 Kudos
4 Replies
PhoneBoy
Admin
Admin

UDP port 8116 is CCP packets related to ClusterXL.
Are you seeing traffic from 0.0.0.x on the wire (e.g. with tcpdump) or just in your logs?
Also, what version/jumbo hotfix level of code are we talking about?
wislleym
Contributor

Sirs, sorry for the delay in answering. After searching i discovered that the firewall was not using the traditional MULTICAST address (224.0.0.0 - 239.255.255.255) to exchange packets from CLUSTER (CCP). I ran the fwha_ccp_use_mcast_base = 1 command in the two CLUSTER boxes and the problem was deleted. Thanks.

 

https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&eve...

0 Kudos
_Val_
Admin
Admin

Please check if you are using Drop Templates

wislleym
Contributor

Sorry for the delay. After research I discovered that the firewalls were not using the traditional MULTICAST address (224.0.0.0 - 239.255.255.255) in the cluster packet exchange (CCP). I ran the fwha_ccp_use_mcast_base = 1 command and the problem was deleted. Thanks. I used sk115142.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events