Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
HeikoAnkenbrand
Champion Champion
Champion

Check Inbound and Outbound TCP Sequece Numbers on R80.20+

Incoming and outgoing TCP sequence numbers should not be changed at the Check Point firewall. I have always asked myself how this can be explained and I have come to the following solution!

This can be checked with the following one-liner:

 

fw ctl zdebug + packet |grep -A 5 "==I\|==O" |grep -B 5 '<IP-ADDRESS>' |grep "==I\|==O\|Device"

 

Change the <IP-ADDRESS> in the one-liner to your device.


SEQUENZ.png

Please note that "fw ctl zdebug" can cause performance problems on firewalls.

More see here:
"fw ctl zdebug" Helpful Command Combinations

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips
1 Reply
Ilan_Khoushy
Explorer

The oneliner is a little different at R77.30.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events