- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi @All,
I want to share an issue to see if anyone has ever encountered the same.
When I upgraded my r77.30 gateway to r80.20 (with CPUSE), server packets return do not cross my firewall.
Here is a diagram which details the issue:
Client ------ eth1-GW-eth2 ------ Server
when I do a fw monitor on my gateway GW, I see icmp request from Client that enter on eth1 and go out eth2. But no icmp reply on eth2.
When I do a tcpdump on my gateway GW I see icmp request from Client that on eth1 and eth2. AND i see icmp reply on eth2.
When i do "fw ctl zdebug drop | grep IP_Client or IP_Server I don't see any drop packet.
(Same things for tcp packets)
Thanks for your lights.
Regards
Why did you go with R80.20 and not R80.30? As far as I've heard R80.20 was "not that great" release for gateways. Plus did you install latest take as part of your upgrade?
Hi @Kaspars_Zibarts ,
We have an internal team that has a lot of memory leak problems with r80.30 installed on gateways and apparently especially on VSX.
The latest take is installed on the R80.20 gateway.
Regards.
You would have to share a bit more info then - exactly how did you run your commands and what did you see.
As for us, R80.30 on VSX has been stable, no issues at all
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY