- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello all:
I'm relatively new at Check Point things and I have almost one year as a security administrator and currently pursuing the CCSA R80 🙂
About two months ago, my SOC colleagues have noticed that it was a dropped traffic alert. When investigating a little further, I noticed that there was dropped traffic from one Security Gatewat to itself (Stealth rule matched), from and to the same source / destination ports, like the example below:
(src_IP;src_port, dst_IP:dst_port)
Security_GW_IP:56651 Security_GW_IP:56651
Security_GW_IP:38264 Security_GW_IP:38264
Security_GW_IP:44991 Security_GW_IP:44991
Security_GW_IP:53525 Security_GW_IP:53525
Security_GW_IP:38650 Security_GW_IP:38650
Security_GW_IP:65155 Security_GW_IP:65155
Security_GW_IP:40397 Security_GW_IP:40397
Security_GW_IP:58272 Security_GW_IP:58272
Security_GW_IP:57116 Security_GW_IP:57116
Security_GW_IP:37972 Security_GW_IP:37972
Security_GW_IP:48424 Security_GW_IP:48424
Security_GW_IP:37001 Security_GW_IP:37001
Security_GW_IP:46269 Security_GW_IP:46269
Security_GW_IP:47290 Security_GW_IP:47290
Security_GW_IP:40848 Security_GW_IP:40848
Security_GW_IP:62771 Security_GW_IP:62771
Security_GW_IP:40749 Security_GW_IP:40749
Security_GW_IP:35696 Security_GW_IP:35696
Security_GW_IP:64525 Security_GW_IP:64525
Security_GW_IP:47796 Security_GW_IP:47796
+++++++++++++++++++++++++++++++++++++++++++++++++++++++
More info:
In the rulebase regarding the implied Security GW, there is first one rule that allows traffic from the security GW to any destination, and then there is the stealth rule.
--
At the moment, I have no found anything that can become clearer the reason of that type of traffic. Do you know if there is any kind of service to which we can attribute this behavior. BTW, I have also noticed that it occurs just to Standby security GWs, within a Active / Standby operation mode.
Rather than solve a job requirement, I want to learn 🙂
Heine_Vargas
Hello Phoneboy, nice to read you:
I got the logs from the SmartConsole Logs tab.
Greetings
I'm gonna take your advice in account and suggest to my customer to opening a TAC case to investigate.
As an additional info -And the most weird, IMHO- , I have tried to track the Smarconsole traffic mentioned above by issuing fw monitor and tcpdump, and I have no found that traffic within the .pcap file (through wireshark).
I tell you how the case is going ASAP.
Thank you!
Heine
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY