- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Harmony Mobile 4:
New Version, New Capabilities
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hey everyone. I have a new CPGW R81.10 and I have one workstation that's dropping traffic 3 to 4 times a second with the following issue:
TCP packet out of state: First packet isn't SYN
TCP Flags: RST-ACK and FIN-PUSH-ACK
Can this be ignored? I can't say I'm seeing a perf problem. Or, should/how can it be fixed? Thanks all!
Generally you can ignore FIN and RST packets that are dropped out of state unless they are conclusively linked to a specific problem. This is typically caused by the connection not being closed gracefully by one side or the other, see my post here:
Hi,
Did you find anyting related to this issue? I have also seen those packets dropped after upgrading to R81.10 TAKE30.
I haven´t seen any drops related to TCP Flags: RST-ACK and FIN-PUSH-ACK before upgrade R80.40.
My problem is that I have performance issues related to flows where I see errors in logs.
I have disabled HTTPS Inspection which seems to solve the issue.
After seeing Tim Hall's post and reading through, I chose to ignore the errors since I didn't see a performance issue. Sorry I'm not more helpful...good luck!
Are you seeing any performance impact, dropped traffic? If so, then I would be concerned...if not, then I would not worry much.
Hi,
Yes! This weekend we upgraded to lastest R81.10 GA, I´m having users reported "slow web browsning" today, I found in logs a lot of dropped packet related to tcp/443, which haven¨t been there before.
TCP packet out of state: First packet isn't SYN
TCP Flags: RST-ACK and FIN-PUSH-ACK
I quick fix, just to now whats goding on was to disable HTTPS Inspection for that VS. Logs dissapeard and users reported good web browsing performance after that. The Logs are from the FW-blade and not HTTPS Inspection.
You may need to debug wstlsd process for https inspection, when its enabled.
I am seeing a LOT of those too in my ubiquiti unifi controller where connection status/heartbeats then gets time out and throwing me an Alert of a device disconnecting even though it’s working fine. It’s so annoying.. never had that issue before checkpoint unfortunately 😞
I would open TAC case for it to have them verify, specially given the fact it causes traffic issues.
Hi!
I will do that, I just need to verify Hyperthreading (SMT/HT) enabling i BIOS for the HPE-server. I don´t know if thats setting was enabled in last update to R80.40, but support seems to be removed.
See https://community.checkpoint.com/t5/Security-Gateways/Attention-HyperThreading-SMT-support-for-Open-....
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY