Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
surajshinde
Contributor

what will be the impact if enable Out of State TCP & ICMP Packets are dropped in global properties

Hello Team,

Out of State TCP & ICMP Packets are drop is not enabled in global prosperities. what will be the impacts if i enable it.

If any documents please share.  

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

You may see more drops in the logs, particularly if you have asymmetric routing in your environment.
However, it's a significantly more secure setting.

0 Kudos
mcatanzaro
Employee
Employee

Any traffic that matches that inspection setting would be dropped. The result could be very impactful if you have traffic currently hitting on that inspection setting.

Those settings are enabled by default so a good guess is that there once was traffic witnessed with this behavior. Best practice would be to identify out of state traffic and attempt to remediate it. If you are unable to remediate due to your network architecture, you can limit allowing out of state traffic to certain hosts/networks. 

Tim has a great post here describing how you can test your network for this scenario: https://community.checkpoint.com/t5/Security-Gateways/TCP-Out-of-State-Drops-Hidden-Monitor-Mode/td-...

I would advise a maintenance window for performing this task. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events