- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- TCP Packet out of state, First Packet is not syn
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
TCP Packet out of state, First Packet is not syn
Hi,
Can somebody explain me, i am getting this error in tracker. not getting proper reply from tech team.
TCP Packet out of stat First Packet is not syn
TCP Flag PUSH-ACK
2 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Generally, we expect to see the full three-way handshake of a TCP connection.
If, for some reason, we don't see the full handshake, then you might see this error.
Some of the reasons you might see this are explained in this SK: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Unless there are actual connectivity or application issues observed, these can safely be ignored.
If, for some reason, we don't see the full handshake, then you might see this error.
Some of the reasons you might see this are explained in this SK: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Unless there are actual connectivity or application issues observed, these can safely be ignored.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please see my response in this thread:
https://community.checkpoint.com/t5/General-Topics/First-packet-isn-t-SYN/m-p/7021
Whether you should do anything about it depends upon what TCP flags you see reported in the dropped packet. In your case of ACK accompanied by PSH, that would generally indicate that the connection was idled out of the firewall's state table due to inactivity (60 minutes default idle timer).
Attend my Gateway Performance Optimization R81.20 course
CET (Europe) Timezone Course Scheduled for July 1-2
CET (Europe) Timezone Course Scheduled for July 1-2
