- CheckMates
- :
- Products
- :
- General Topics
- :
- ICMP reply does not match a previous request
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ICMP reply does not match a previous request
Hello friends,
I have multicast topology like this:
Router1(receiver multicast)------>Checkpoint R80------->Router2-----Router3(Multicast sender)
All devices run PIM-SM mode.
On router1: I join group 239.9.9.9
On router2: ping to 239.9.9.9
Result: Not success
I check log on firewall and see that this error
Please help me
Thanks a alot!!
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As an immediate solution or workaround, disable the Stateful Inspection for ICMP to allow this traffic:
-
In SmartDashboard, go to the Policy menu - click on the Global Properties....
-
In the left tree, click on the Stateful Inspection.
-
Clear the box "Drop out of state ICMP packets" - click on OK
- Install Policy
Note: Disabling the Stateful Inspection will lower the security. This should be done with caution and only as the last resort.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As an immediate solution or workaround, disable the Stateful Inspection for ICMP to allow this traffic:
-
In SmartDashboard, go to the Policy menu - click on the Global Properties....
-
In the left tree, click on the Stateful Inspection.
-
Clear the box "Drop out of state ICMP packets" - click on OK
- Install Policy
Note: Disabling the Stateful Inspection will lower the security. This should be done with caution and only as the last resort.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Tks heiko a lot.
I do as your comment, ping now is OK,
one more question: if I set static NAT on firewall: IP router1-->translate to a.b.c.d
, when router1(multicast receiver) send "IGMP join" packet through firewall, I see that static nat does not work ( the source IP is not translated to a.b.c.d)
so i think checkpoint not support nat in multicast? Is this true
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
