hi,
we migrated from 23800er ClusterXL R81.20 Take92 to Maestro with 1SG and 2 Gateways 9800 R81.20 Take92.
Since the migration we have an issue with an ftps-connection. Some time the connection is working, most of the time not.
The control connection is on port 6618 and the data connection is between 7000 and 7500.
All ports are opened for the specific destination.
If the connection is working, all is fast and directory browsing is no problem. But when it fails, directory listing fails with timeout.
In the logs. There are only some drops with „first packet isnt syn“. No other drops or blocks.
I disabled layer4 distribution within maestro, no change. I set 1 gw manually down, no change.
I captured the traffic on internal and external interface and got an working connection and 1 not working.
The difference i can see in the pcacp – when it is not working there is an „client hello“ from destination back to client on outside interface, but this packet is missing on inside interface. see attached images.
I rund an fw ctl zdebug, only the „1st packet isnt syn“ is logged.
In the smart logs, there is an detect-message from urlf, the ftps-cert isnt from an trusted CA. but that was also before we migrated to maestro.
i have no idea wtf is going on, and why sometimes it is working. any ideas?
thanks
daniel