- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
Is there a way to filter out logs for websites that have a drop for "First packet isn't SYN"?
I'm trying to find whether a website was blocked due to the firewall, and sort out the logs by username/not action:accept, but the "First Packet isn't SYN" logs are burying the logs I want to see.
Hardware: 6000 series
Smb: Smart-1 410
Version: R81.10 take 79
Thanks!
Sorry, apologies mate, I dont have access to the dashboard now, but I recall doing similar filter before and you can do something like this -> NOT "First packet isnt SYN" or if you look at any logs containing that message, find the column containing those words and then right click on it and select the filter, that works as well.
Sorry, apologies mate, I dont have access to the dashboard now, but I recall doing similar filter before and you can do something like this -> NOT "First packet isnt SYN" or if you look at any logs containing that message, find the column containing those words and then right click on it and select the filter, that works as well.
Thanks @the_rock, you rock!
I thought I tried it that way (123.456.789 and NOT "First packet isn't SYN") but maybe I had something off. That works.
Glad it helped mate! By the way, I just like to think Im like REAL Rock (Dwayne Johnson), but in reality, compared to him, Im more Mr Pebble ; - )
Cheers.
I would try to get rid of the First packet isn't SYN messages first, does not look healthy at all !
@G_W_Albrecht Thanks, I'm really confused about the First packet isn't SYN errors. I've read so much about it; I don't know which to believe anymore.
I even opened a case with support previously about it, and they told me its regular to see those. Some threads here even say its normal. Is there a way you suggest I can get rid of them? I wouldn't even know how to get a hold of some of the web developers for the sites that are showing these "blocks" for First packet isn't SYN.
Note: I don't have https inspection checked yet.
Man, thats tricky one...whoever says those messages are normal, I would not say they are right, BUT, they are not wrong either. It really depends the situation...you will see those messages ANY TIME when connection is out of order. So as we all know, you got 3-way handshake, SYN <-> SYN-ACK<-> ACK. So, at the end of the day, message clearly tells you thats not happening, the hardest part is figuring out WHY NOT.
Usually, this is caused by asymmetrical routing - e.g. same connection packets arriving from different IFs.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 28 | |
| 20 | |
| 15 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY