Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ikafka
Collaborator
Jump to solution

First Packet isn't SYN

Hi,

 

I have looked through similiar post here but it is not exactly the same problem, I wanted to open a post. 

The 192.168.100.0/24 network is constantly generating traffic. I know this traffic (SCADA generated). I blocked this 192.168.100.0/24 network by writing  a rule from the firewall and  did not wan to log. I left it as NONE.

But when I look at logs on the firewall, it shows as a drop but it does not match my rule. Anr rule drops without matching. Too many logs are generated. How can I drop this traffic and make it not keep logs? 

Screenshot of a log record. 

fECYroZA0o.png

 

 

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin
7 Replies
PhoneBoy
Admin
Admin

You can disable these logs via: https://support.checkpoint.com/results/sk/sk102491

ikafka
Collaborator

Thank you @PhoneBoy for your replying. I set it to not log. Sometimes it is necessary to look at such logs. I can open it again when necessary. 

0 Kudos
the_rock
Legend
Legend

In layman's terms, all that error means, regardless of the firewall vendor used, is literally that 3 way handshake is not completing, why, thats another question. You need to run tcpdump and fw monitor to find out.

To help with the flags, check out this site my colleague made while back, it gives you the command you can copy directly based on the filter (it also uses multiple vendors)

Andy

www.tcpdump101.com

 

0 Kudos
ikafka
Collaborator

Thank you for this site. It is a very nice and useful site. 

(1)
the_rock
Legend
Legend

Super useful...my colleague made that in his free time over the years. 

Andy

Zolocofxp
Collaborator

I have experienced this before and every single time, it had to do with asymmetric routing. SYN packet reached the destination host without going through the firewall and SYN-ACK was returning through the firewall. 

(1)
the_rock
Legend
Legend

What you said is literally the case 99% of the time.

Andy

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events