Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
bkee9175
Participant
Jump to solution

Traffic Dropped and in logs rule name/number columns empty, I don't know why traffic was dropped.

 

cp_rule.JPG

I'm wondering if anyone can help me. I'm troubleshooting traffic that is being dropped. The access rule name/number is empty. In the past when I see this behaviour it was an indications of Asymmetrical traffic. To confirm this I could add TCP related columns which would confirm that the packets were dropped for not being the first in a TCP stream. In this case I am not seeing that.

Would anyone be able to recommend some troubleshooting I can perform to help ID what is causing the drops? Are there other columns I can add to logging to help understand the block reason?

Hardware is Checkpoint Appliance R80 Code

0 Kudos
1 Solution

Accepted Solutions
Chris_Atkinson
Employee Employee
Employee

Correct. Address spoofing appears to be the cause here.

So the gateway is seeing traffic from a host it doesn't expect to see on this interface.

Depending on the specifics of your topology the potential non-malicious reasons could be due to routing or simply missing configuration where spoofing parameters are defined statically. 

CCSM R77/R80/ELITE

View solution in original post

4 Replies
Chris_Atkinson
Employee Employee
Employee

Can you please open one of the entries and provide a screenashot here with any sensitive detail removed?

CCSM R77/R80/ELITE
bkee9175
Participant

spoofing.JPG

I didn't know you could click into each entry for more information. I'm pretty new to this GUI. It seems "address spoofing" is the reason, right? Looks like I have some more reading to do on how to assess this situation.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Correct. Address spoofing appears to be the cause here.

So the gateway is seeing traffic from a host it doesn't expect to see on this interface.

Depending on the specifics of your topology the potential non-malicious reasons could be due to routing or simply missing configuration where spoofing parameters are defined statically. 

CCSM R77/R80/ELITE
bkee9175
Participant

Thank you Chris, very much appreciated. I will take a look at the network configuration and topology and see how everything is setup.

This article looks useful.
"Address spoofing" drop log (checkpoint.com)

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events