Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
HeikoAnkenbrand
MVP Diamond
MVP Diamond

Check Inbound and Outbound TCP Sequece Numbers on R80.20+

Incoming and outgoing TCP sequence numbers should not be changed at the Check Point firewall. I have always asked myself how this can be explained and I have come to the following solution!

This can be checked with the following one-liner:

 

fw ctl zdebug + packet |grep -A 5 "==I\|==O" |grep -B 5 '<IP-ADDRESS>' |grep "==I\|==O\|Device"

 

Change the <IP-ADDRESS> in the one-liner to your device.


SEQUENZ.png

Please note that "fw ctl zdebug" can cause performance problems on firewalls.

More see here:
"fw ctl zdebug" Helpful Command Combinations

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips
1 Reply
Ilan_Khoushy
Explorer

The oneliner is a little different at R77.30.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 24 Feb 2026 @ 04:30 PM (EST)

    Las Vegas: MDR/XMDR

    Wed 25 Feb 2026 @ 04:30 PM (MST)

    Tempe, AZ: MDR/MXDR

    Wed 11 Mar 2026 @ 12:00 PM (MDT)

    CheckMates Live Denver!
    CheckMates Events