- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi Mates!
The customer is experiencing intermittent ICMP DOWN alert events reported by SolarWinds, i checked on the firewall site but i dont'see nothing realted, have any idea?
Orion polls ICMP every 3 minutes.
What address is being probed is there a VPN involved or is the gateway under load?
Orion go out through a cluster, there is no VPN involved
Hey brother,
Are there any relevant logs in Smart Console you can see about this?
the only thing that i see it is that:
dropped by fw_first_packet_state_checks Reason: ICMP reply does not match a previous request;
https://support.checkpoint.com/results/sk/sk66443
yeah brother, i know about that, but the main purpose it's to understand why it happens
My most educated guess is assymetric routing. Thats what I always experienced, since R55 days.
Hey bro,
Just curious. when did this issue happen?
one month ago brother
Can you find any relevant logs around that time that could potentially help us figure out why this may have happened?
Any aggressive aging active log messages or cluster failover events that correspond?
I'm sorry, I don't understand your question.
Its aggressive aging protection, brother, check out below.
Happened to me once due to asymetric routing,
I'd suggest to check the revisions and look at the changes that were probably made around the time the issue started.
Hey brother,
I did some more research on this and found some notes about this tool when I worked with one of our customers few years ago on some alerts and it turned out to be false positive. Can you check with the client if thats a possibility?
Is this just polling a standard gateway or VSX?
Only issue I've seen is when you attempt to ping the cluster IP and a real IP on the node.
standard gw, what you mean by the real IP
If you are ping the cluster IP and the real IP it likely won't work on the active gateway (See SK26874), I specifically experienced this on VSX, so may not be relevant.
But is it cluster or single gw?
Hey brother,
Any news about this?
hey brother,
seems to be Asymmetric routing
Thats what we initially thought as well.
Did you resolve it then?
nope not yet, what kind of actions do you usually take to determine whether the issue is caused by asymmetric routing?
Hey bro,
I would double check interface topology, if not sure, just set it per routing option, thats default anyway and recommended too. Now, obviously, goes without saying, dont make any changes if not sure, as it would break things.
Maybe do ip r g command to relevant IP address. Example ip r g 8.8.8.8
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 |
Wed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Fri 10 Apr 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 45: Harmony SASE updateWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Fri 10 Apr 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 45: Harmony SASE updateTue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY