Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
DannyCor
Newcomer

First Packet Isn't SYN drop

I am new to Checkpoint firewall and have been dealing with "First Packet Isn't SYN" issue for the last few weeks. This is happening between interface and one of application server, both server communicate on port 4000. The odd thing I see only first 3 packets are dropped then the 4th allowed to get through.

 

At the moment, I only have access to logs only, not configuration. Any configuration changes need to be communicated with other team.

Anything place I can start to troubleshoot the issue?

 

 

0 Kudos
3 Replies
the_rock
Legend
Legend

That can sometimes be bit tricky to troubleshoot. I would say, run tcpdump and fw monitor to see whats happening with the traffic. Also, I would do ip r g command to make sure route is right. Say IP is 10.9.8.7, you can run ip r g 10.9.8.7 from the expert mode.

Hope that helps.

Andy

0 Kudos
AkosBakos
Leader Leader
Leader

Hi @DannyCor 

  • If you check the name of the incoming interface at the first packet what do you see? (eg.: eth1)
  • The interface is the same by that packet which is dropped?

Here is a screenshot what to check:

2025-01-10 09_22_45-10.211.190.100-R81.20-SmartConsole.png

If not the same, we are facing with asymmetrical routing.

Akos

 

----------------
\m/_(>_<)_\m/
the_rock
Legend
Legend

Routing usually comes to mind with this sort of error.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events