Hello, world.
I have a ClusterXL, running R81.10.
We currently have a connection policy defined.
SRC: 10.7.52.128
DST: 192.168.216.214
The service that most consumes this source, is the SSH.
Suddenly, the "connection" was interrupted.
How can I rule out that the Firewall is responsible for this "interruption"?
I understand that it would be to check the logs. I have checked the logs, and I found a REJECT action, which leaves me with the question, is this action something normal in the Checkpoint?
Shouldn't I see "DROP"?
I get Reject, for a PING service, I have the impression that the user, as he lost the SSH connection, started to try the PING to that destination, and the Checkpoint, for some reason, started to register it with this action.
Is this normal?
Greetings. 🙂