Hi community,
has anyone ever seen SecureXL massively delaying packets ?
We currently have issues with Teams audio drop outs. Root cause analysis by Microsoft found massively delayed packets that are ignored by the client causing the dropouts.
We started troubleshooting TCP sessions from the affected subnet for better visibility and we can see massive delays even in TCP handshake SYN-ACK packet processing:
This is a screenshot from a packet analysis on the affected gateway.
bond0.32 is the internet facing interface, bond1.3939 is the internal facing interface.
Captured traffic between client 172.28.4.77 natted by firewall to a public IP 80.x.x.x communication with a Microsoft server 52.112.174.6.
The SYN-ACK is seen inbound on bond0.32 at timestamp 12:14:50,105567 and leaves the firewall on the internal interface bond1.3939 at 12:15:28,741378.
This is a significant processing time of 38 seconds !
We then exluded the target subnet 172.28.0.0 from SecureXL by https://support.checkpoint.com/results/sk/sk104468 and the issue vanished.
Case with TAC already opened. Software release R81.10 JHF109 on HP OpenServer. Running in an active/passive cluster mode.
Any input/(help appreciated.
Regards Thomas