- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Team, This is R80.20 and my packets are getting dropped with below error which I captured using fw ctl zdebug. There is a PBR configured on firewall for source IP x.x.x.x for Internet as destination.
Surprisingly web traffic works fine however only ICMP is getting dropped. Any reason why? I tried searching through lot of SKs however none of them was pinpoint to the below error neither any one has worked
@;3779257712;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=1 x.x.x.x:2048 -> 8.8.8.8:63298 dropped by fw_filter_chain Reason: [NTUP] returned Drop for reused conn;
@;3779396743;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=1 x.x.x.x:2048 -> 8.8.8.8:63297 dropped by fw_filter_chain Reason: [NTUP] returned Drop for reused conn;
@;3779497504;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=1 x.x.x.x:2048 -> 8.8.8.8:63296 dropped by fw_filter_chain Reason: [NTUP] returned Drop for reused conn;
@;3779590799;[cpu_3];[fw4_0];fw_log_drop_ex: Packet proto=1 x.x.x.x:2048 -> 8.8.8.8:63295 dropped by fw_filter_chain Reason: [NTUP] returned Drop for reused conn;
I had seen this before be caused by securexl. If you disable it and it works, then below would apply.
Permanently set the value of kernel parameter fwconn_set_esp_after_nat_links to 1 (one) - follow sk26202 (Changing the kernel global parameters for Check Point Security Gateway).
Andy
Yeah initially I thought so hence I had disabled securexl as well however it did not work. fwaccel off is the only thing that I need to do?
Thats all I found, sorry brother.
ICMP is never accelerated by SecureXL and always goes F2F, so disabling SecureXL shouldn't have any effect on this issue. I'm assuming this has something to do with Smart Connection Reuse, although it isn't employed for non-TCP connections/sessions, at least to my knowledge: sk24960: "Smart Connection Reuse" feature modifies some SYN packets
True true...I remember having to do that sk once before when customer upgraded from R80.20 to R80.30, but never related to errors in the post.
Any way I now removed the PBR and it started working fine.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY