- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
I have one question regarding checkpoint Satefull inspection feature. I have rule that allows Server A to be accessed from public, and in the firewall as I know there is only one rule needed for such traffic due to checkpoint Satefull inspection. My concern is if the TCP session by any means fails, is adding a rule from server A to any make this TCP session to reestablish by the server ?
Thanks,
If the TCP session fails, i would assume that the client needs to establish a new connection to the server - it usually does not make sense for a server to reach out for a client to re-establish a connection 😉 Also authentication would be an issue here.
If the TCP session fails, i would assume that the client needs to establish a new connection to the server - it usually does not make sense for a server to reach out for a client to re-establish a connection 😉 Also authentication would be an issue here.
What is the expected behavior, what are you trying to achieve?
The thing is the server access from public failed in the middle of no where. so, I taught whenever the tcp session failed writing a rule in the reverse direction (i.e from server to any) may allow the server to reestablish the tcp session
A reverse rule won't solve this issue as you will get a TCP packet out of state message: https://support.checkpoint.com/results/sk/sk31382
Or something like "First Packet isn't SYN" from: https://support.checkpoint.com/results/sk/sk11088
You can disable these checks for specific flows by using the procedure in sk11088.
This is generally not recommended for security reasons, though.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY