Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
pradeep_paka1
Participant

Checkpoint IDC is getting frequently disconnected from ISE admin Node

Hi All,

 

Need help..

Checkpoint IDC is getting frequently disconnected from ISE admin Node.

every time i need to restart service to make connection up again and after that it will get disconnected after 5 to 10 min.

 

Is there any solution for this?

I logs i can see below. "deny tcp (no connection) flags rst on interface "

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

Is there any firewall between the two?
Its possible you will need a TAC case to troubleshoot this.

0 Kudos
pradeep_paka1
Participant

Yes there is Cisco FW in between both and we see deny logs like "deny tcp (no connection) flags rst on interface".

All required ports are already allowed. Also IDC's are upgraded to 81.0018.0000 version.

0 Kudos
PhoneBoy
Admin
Admin

That error suggests a possible asymmetric routing issue, which any stateful firewall is going to have issues with.
See: https://community.cisco.com/t5/network-security/deny-tcp-no-connection/td-p/2685271

0 Kudos
pradeep_paka1
Participant

This is solved after TAC gave hotfix.

Thanks..

0 Kudos
MichaelGur
Explorer

Can you tell me please, what hotfix solved this issue?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events