- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
When I did a troubleshooting, I saw the weird response. Assume, Network device D1 is connected to CP firewall Interface eth1 and Network device D2 is connected to eth2 Interface. When Ping initiated from D1 to D2, I see packet entering eth1 and leaving eth2 and when got the response back, I see the response on eth2 but its not reached eth1. It observed via both FW monitor and TCPDUMP. Unfortunately, I am not seeing any drop by issuing command debug drop command.
Please suggest if you came across any.
Thank you in advance.
That means a routing problem. On the firewall, run 'ip route get <address>' for the destination of the reply (the client which sent the initial packet). Does it tell you traffic would go out the interface you expect?
What does the fw monitor show? i with no I? i-I with no o? i-I-o with no O? Something else?
Hi,
I see the ICMP reply back on eth2 with "i" and "I" but I did not see "o" and "O".
Thank you
Hey!
There can be an issue with IP Forwarding on the interface. Can you paste the output of this command:
sysctl -a | grep forward | grep -v "mc_forwarding" | grep "= 0"
Regards,
André Tinoco
HI Andre,
Thank you and sure.
Hi, PFO,
net.bridge.lacp_forwarding = 0
net.ipv4.ip_forward_use_pmtu = 0
That means a routing problem. On the firewall, run 'ip route get <address>' for the destination of the reply (the client which sent the initial packet). Does it tell you traffic would go out the interface you expect?
It might be routing problem, but for what Logesh8 wrote, the devices are directly connected to the interfaces. Should not have routing issue there.
@Logesh8 Can you elaborate on the topology? If there is routing involved, and the device is not directly connected, then Bob is probably right and you are missing the return route for that traffic.
@AndréTinoco , Sure I will provide you more information about topology soon.
@Bob_Zimmerman , I have scheduled a troubleshooting call on Monday. I will give you more information.
Hey just my two cents as you say both devices are directly connected and I assume firewall policy and anti-spoofing have been checked, did you check the subnet masks on both ports?
Not that the firewall isn't forwarding the traffic as it's assuming the subnet range belongs to eth2.
BR,
Markus
Hi,
Yes checked.. When we run tcpdump for physical interface of the switch and router. Output is perfect but not the same when we run tcpdump for loopback IPs of switch and router.
Hi, IP route get shows the correct Interface details.
Agree with @Bob_Zimmerman
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
12 | |
7 | |
6 | |
6 | |
6 | |
6 | |
5 | |
3 | |
3 |
Fri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY