- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Post-Encrypt traffic is not visible in Fw moni...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Post-Encrypt traffic is not visible in Fw monitor. Other end FW is not receiving traffic sent by me
Below are the logs collected from the primary gateway of my firewall. In "O" the source IP is getting NATed to the NAT IP and then pre-encrypt is shown and not receiving the POST-encrpt packet.The other end firewall is not observing any traffic.
[vs_0][fw_2] eth1:i[60]: 10.140.96.6 -> 10.232.144.14 (TCP) len=60 id=42611
TCP: 40768 -> 515 .S.... seq=24587d9c ack=00000000
[vs_0][fw_2] eth1:I[60]: 10.140.96.6 -> 10.232.144.14 (TCP) len=60 id=42611
TCP: 40768 -> 515 .S.... seq=24587d9c ack=00000000
[vs_0][fw_2] eth0:o[60]: 10.140.96.6 -> 10.232.144.14 (TCP) len=60 id=42611
TCP: 40768 -> 515 .S.... seq=24587d9c ack=00000000
[vs_0][fw_2] eth0:O[60]: 10.40.112.6 -> 10.232.144.14 (TCP) len=60 id=42611
TCP: 40768 -> 515 .S.... seq=24587d9c ack=00000000
[vs_0][fw_2] eth0:e[60]: 10.40.112.6 -> 10.232.144.14 (TCP) len=60 id=42611
TCP: 40768 -> 515 .S.... seq=24587d9c ack=00000000
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You might also add -p all to your fw monitor CLI.
Some fw ctl debug: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is anything showing (is it logged?) in the logs?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
https://community.checkpoint.com/t5/CloudGuard-IaaS/The-NAT-issue-on-CP-firewall-deployed-in-the-Azu...
