Hi Mark,
I'm sorry for my late response - the notification mails were sacked as spam....
One of them is a 5900-HPP VRRP-Cluster with R77.30
The other one is a 3100 ClusterXL with R88.20
Both internal appliances are Checkpoint, our managment firewall is an interoperable device, but the drops are seen on Checkpoint side.
Topology is set to best practice (address spoofing enabled based on topology, internal nets, external net, dmz net und transfernets are marked)
This is the drop message:
Best Regards
Johannes