Hello fellow CheckMates.
We have encountered some strange issues after upgrading R80.40 above Take93/Take94.
We see that ICMP is NOT passing through the gateway, it starts to work ONLY after a TCP packet has been sent ...
This happens in local attached networks, over routed networks and also over VPN ...
It doesnt matter if SecureXL is ON/OFF ...
Regardless if openserver or appliance
what we see:
only an echo / never a replay
[vs_0][fw_4] eth4:i[44]: 172.XX.66.228 -> 172.ZZ.10.43 (ICMP) len=96 id=30804
ICMP: type=8 code=0 echo request id=64388 seq=0
[vs_0][fw_4] eth4:I[44]: 172.XX.66.228 -> 172.ZZ.10.43 (ICMP) len=96 id=30804
ICMP: type=8 code=0 echo request id=64388 seq=0
[vs_0][fw_5] eth4:i[44]: 172.XX.66.228 -> 172.ZZ.10.43 (ICMP) len=96 id=30829
ICMP: type=8 code=0 echo request id=64388 seq=1
[vs_0][fw_5] eth4:I[44]: 172.XX.66.228 -> 172.ZZ.10.43 (ICMP) len=96 id=30829
ICMP: type=8 code=0 echo request id=64388 seq=1
We see only small "i" and big "I" ... never small "o", big "O"
We know this destination is ALIVE.
When we send an TCP packet, immediatley an ARP request is made and an ARP entry is created then the ICMP works!!!
This happens also over VPN!
On the DESTINATION IP we checked with tcpdump, NOTHING was received until the first TCP SYN was sent, then the ICMP followed!
No drops seen with fw ctl zdebug / no drops seen on Smartlog
When the ping works, is sometimes stops after 60 seconds! (ARP timeout = 60?)
This happens mostly to "silent" device which do not have permanent TCP sessions runnings becasue TCP "heals" the connection.
Several CP Cases are ongoing, and alot of R80.40 installations are affected ...
And we had numerous remote sessions with TAC to proove the issue is real and not a hoax.
yes there is this SK for example ...
When SecureXL is enabled, no ARP is sent and traffic fails (checkpoint.com) sk152093
it decribes the exact opposite ...
what is your experience from the field?
best regards
Thomas