- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
I am new to Checkpoint firewall and have been dealing with "First Packet Isn't SYN" issue for the last few weeks. This is happening between interface and one of application server, both server communicate on port 4000. The odd thing I see only first 3 packets are dropped then the 4th allowed to get through.
At the moment, I only have access to logs only, not configuration. Any configuration changes need to be communicated with other team.
Anything place I can start to troubleshoot the issue?
That can sometimes be bit tricky to troubleshoot. I would say, run tcpdump and fw monitor to see whats happening with the traffic. Also, I would do ip r g command to make sure route is right. Say IP is 10.9.8.7, you can run ip r g 10.9.8.7 from the expert mode.
Hope that helps.
Andy
Hi @DannyCor
Here is a screenshot what to check:
If not the same, we are facing with asymmetrical routing.
Akos
Routing usually comes to mind with this sort of error.
Both dropped and allowed traffic coming from same interface.
I checked them, it uses same interface.
I wanted to add. Tnterface server is communicating with several different application servers located on multiple different VLANs. This issue only happening on this one particular application server.
Check the routing table of the affected server. There will be the problem.
First question is always, are these drops causing any issues? Are there issue reported of this connection flow or you just saw them?
And what is the issue? If they setup new connection is it slow? Or they get timeout after like 1 hour and have to rebuild connection.
In my case, it causes encoders not responding to PMS requests cutting room keys.
In this case please check the routing and the interface of the accepted and droppet packet. Itt might help
Will the request work after some time or they never work? Or it works first few minutes and then stops working after an hour or so?
> Or it works first few minutes and then stops working after an hour or so?
Or, does it work "right away', then, if no new traffic is passing, does it work after 1 hour?
"Such things" might happen in, for example, the following cases:
- Asymmetrical routing, when the "reply" packet follows a different path then the "query" one. In this case the connection can not be established.
- New packets after TCP timeout. If there are no packets for 1 hour, the firewall removes the entry from the connection table. If any of the communicating side decides to send more packets, the firewall will drop them with an error "First Packet out of syn".
This can be solved in several ways:
- Just ignore it, if no issues noticed
- Increase the timeout for the service (SmartDashboard)
- Globally increase the TCP timeout for all TCP connections on the firewalls (SmartDashboard)
- Set the TCP heartbeat/keepalives to less than 3600 seconds on the communicating parties (Kernel)
- Configure the firewall to send RST to the parties, when the TCP timeout occurs (Kernel)
Which method to choose - depends on the application, for example, if it can recover from either connection reset or connection timeout.
After server reboot, I have seen multiple packets allowed to pass, then after sometimes (hours), the FW starts dropping packets again.
Here we go. Exactly what I said above.
I am new to Checkpoint firewall and have been dealing with "First Packet Isn't SYN" issue for the last few weeks. This is happening between interface and one of application server, both server communicate on port 4000. The odd thing I see only first 3 packets are dropped then the 4th allowed to get through.
At the moment, I only have access to logs only, not configuration. Any configuration changes need to be communicated with other team.
Anything place I can start to troubleshoot the issue?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
9 | |
6 | |
5 | |
5 | |
4 | |
3 | |
3 | |
2 | |
2 |
Wed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksWed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY