Create a Post
Showing results for 
Search instead for 
Did you mean: 

Strange Firewall logic for DHCP discover packets

Using R77.30 firewall we were trying to allow DHCP discover packets to our gateway which had been configured as DHCP server. We have found DHCP discover packets drop on our firewall. These packets had source IP and destination So, we made a permissive rule with  respective source and destination and service bootp. Firewall still drops the packets. TAC recommended us to change source to any, we did it and firewall accepted those packets. On the next step I have created IP address range object with first IP and last IP, added it to source instead of any and negated source cell. As a result - firewall accepts our DHCP discover packets. When I change first IP in range to, firewall drops DHCP discover packets. Can somebody explain, why we can not use as source host to accept this traffic but when we exclude every IP address except from source, it works properly? 

3 Replies

The IP address has several special meanings on computer networks. However, it can not be used as a general-purpose device address. Probably therefore CP don't understand the range. 

Read more here :

0 Kudos
Champion Champion

I programmed tcpdump drivers years ago. 

The problem is that is used as any address in many IP stacks. The IP address is sometimes called a wildcard address, unspecified address or INADDR_ANY.



# define INADDR_ANY ((unsigned long int) 0x00000000)

Therefore the address is not used as a real IP address. Furthermore, in some old IP stacks there are mathematical problems with, so it would never be allowed as real IP.

I think Check Point firewalls also intercepts the address I would even prevent the SmartConsole software from entering the address. But I haven't tried the input yet to see if it works.

At R77.30 you can enter the IP What side effects this will have:-)




Check Point will also drop your traffic if it has source or destination port defined as 0. It is done for similar reasons and for security.

SmartView Tracker drop logs show "Invalid TCP packet - source / destination port 0"... 


Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events