- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
We have a current IP-A-IP communication, which travels over a dedicated link (MPLS).
Since a few weeks, we have this communication very slow and unstable.
What the source wants to consume is a service on port 80, but what I see in the logs, is that there is a traffic that at times is allowed, and at times not.
When it is allowed, the traffic matches with its firewall rule and its NO-NAT rule (since they don't want to kick the origin), but then the traffic starts to match with a rule that is not visible in the SmartConsole, and simply "throws away" the connections (the only known message is that a DROP is done).
Is there any way to detect the reason for this behavior?
I publish a reference image.
ClusterXL HA -> Version R81.10 -> Take 81
Cheers 🙂
Thats always tough bro, specially when its intermittent. MTU came to mind when I read the problem, but not so sure that might be the case here. Can you expand the drop log and send it as a screenshot, so we can see all the details? Does zdebug show anything when it fails?
Andy
Hey,
I'm sharing a notepad, with a log (Accept) and a log in (Drop), so it can be more understandable.
I'm not sure if these logs in DROPS should be ignored or not, or relate directly to the problem, since the problem is that the source has a "SLOW" problem when it wants to consume a resource from the destination.
First packet isnt syn has been an error thats been around since probably the beginning of stateful firewalls. All that says, in layman's terms, is that connection is not completing to the point of 3-way handshake (syn -> syn-ack->ack)
You should do regular fw monitor and fw monitor -F flag to see what happens.
Andy
Do you have the syntax of the command that I could apply in my scenario, in order to check the flow of this communication, please?
If you give src and dst, I can provide it.
Andy
The origin and destination, are those shown in the initial image of this publication 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 19 | |
| 16 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolFri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY