- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
I have a cluster R80.30 which is being running as a a default gateway for many downstream VLANS.
One of my VLANS host Oracle Applications and Databases. My issue is that i receive the following error when an Oracle App tries to communicate with an Oracle DB on the same VLAN.
TCP packet out of state:First packet isn't SYN
TCP Flags: PUSH-ACK
Source: 192.168.X1.X1
Source Port: 43950
Destination: 192.168.X1.X2
Destination Port: 1521
IP Protocol: 6
Blade: Firewall
Origin: Checkpoint-Core-FW1
Service: TCP/1521
Product Family: Access
Logid: 1
Interface: bond21.X1
Description: sqlnet1 Traffic Dropped from 192.168.X1.X1 to 192.168.X1.X2
Any advise?
Thank you in advance.
Thank you all for your advises.
It turned out that one of the machines had a wrong subnet mask configured so the communication was directed through the firewall.
Problem solved.
thanks
Hello,
By chance, are you load balancing your Oracle DB? I just had a customer which Oracle DB load sharing used two host which a different IP each. Fun thing was that both of them could reply to request of the other one and the GW dropped the traffic as out of state.
Do you always see the PUSH-ACK out of state? this flag my suggest time out, you may want to do some packet captures and maybe modify some TCP sessions.
If you cannot find the root cause of your issue I highly suggest to solutions from this post: Disabling 'out of state' checks between certain hosts
Never ever disable stateful inspectin completly.
Hope it helps
______
Thank you all for your advises.
It turned out that one of the machines had a wrong subnet mask configured so the communication was directed through the firewall.
Problem solved.
thanks
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY