- Products
- Learn
- Local User Groups
- Partners
- More
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Hi Mates!
The customer is experiencing intermittent ICMP DOWN alert events reported by SolarWinds, i checked on the firewall site but i dont'see nothing realted, have any idea?
Orion polls ICMP every 3 minutes.
What address is being probed is there a VPN involved or is the gateway under load?
Orion go out through a cluster, there is no VPN involved
Hey brother,
Are there any relevant logs in Smart Console you can see about this?
the only thing that i see it is that:
dropped by fw_first_packet_state_checks Reason: ICMP reply does not match a previous request;
https://support.checkpoint.com/results/sk/sk66443
yeah brother, i know about that, but the main purpose it's to understand why it happens
My most educated guess is assymetric routing. Thats what I always experienced, since R55 days.
Hey bro,
Just curious. when did this issue happen?
one month ago brother
Can you find any relevant logs around that time that could potentially help us figure out why this may have happened?
Any aggressive aging active log messages or cluster failover events that correspond?
I'm sorry, I don't understand your question.
Its aggressive aging protection, brother, check out below.
Happened to me once due to asymetric routing,
I'd suggest to check the revisions and look at the changes that were probably made around the time the issue started.
Hey brother,
I did some more research on this and found some notes about this tool when I worked with one of our customers few years ago on some alerts and it turned out to be false positive. Can you check with the client if thats a possibility?
Is this just polling a standard gateway or VSX?
Only issue I've seen is when you attempt to ping the cluster IP and a real IP on the node.
standard gw, what you mean by the real IP
If you are ping the cluster IP and the real IP it likely won't work on the active gateway (See SK26874), I specifically experienced this on VSX, so may not be relevant.
But is it cluster or single gw?
Hey brother,
Any news about this?
hey brother,
seems to be Asymmetric routing
Thats what we initially thought as well.
Did you resolve it then?
nope not yet, what kind of actions do you usually take to determine whether the issue is caused by asymmetric routing?
Hey bro,
I would double check interface topology, if not sure, just set it per routing option, thats default anyway and recommended too. Now, obviously, goes without saying, dont make any changes if not sure, as it would break things.
Maybe do ip r g command to relevant IP address. Example ip r g 8.8.8.8
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 |
Tue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY