Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gongya_Yu
Collaborator
Jump to solution

how to explain the following ?

CPEarlyDrop-1.PNG

why does CP treat them differetly ? 

The second and the  third packets are dropped ?

 

thanks !!

0 Kudos
32 Replies
Tal_Paz-Fridman
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Check out a newer SK on this issue:

Logs from a Security Gateway show "Connection terminated before" in the "Reason" field

https://support.checkpoint.com/results/sk/sk113479

 

Make sure to look at the section:

Improvements in versions R81.10 and higher

 

0 Kudos
the_rock
MVP Diamond
MVP Diamond

I had remote last night with a colleague troubleshooting this exact issue. Its always interesting to see how things behave, though people have 100% the right rules, but, order does matter. The gist of it was that customer discovered with the scan people who connect to their wireless guest were able to detect some internal devices, but they just could not connect to any of them, since rule was there to block them from accessing anything related to RFC-1918. But, since rule was there above it to allow dhcp services, that was the reason, so we just move rfc 1918 rule to be the first in that inline layer and then logs showing cpnotenough data disappeared and even doing nc -zv command was also failing, as it should have.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
PhoneBoy
Admin
Admin

CPNotEnoughDataForRuleMatch logs are the way we indicate the connection terminated on its own before we could fully classify it.
In other words, you're assumption is correct.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events