- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
we are receiving logs with first packet isnt sync. as of now for work around we have disabled the tcp out of state in global properties. but its not an good idea to keep this disabled. so instead of disabling how can we over come this issue?
and what are steps to troubleshoot ?
Fix the application that is causing the problem.
If that's not possible, you can disable it for a specific flow by following the steps here: https://support.checkpoint.com/results/sk/sk11088
Please share the gateway version and jumbo level, in addition:
Is the gateway under memory capacity pressure - any aggressive aging logs?
Is the issue specific to a certain application?
How about the routing have you checked for asymmetrical routing?
I assume you mean first packet isnt SYN? Anyway, what really means in layman's terms is that connection is not completing to the point of 3-way handshake, syn-synack-ack
I would say run below captures. Lets assume src is 1.1.1.1 and dst is 2.2.2.2 and port is 444
tcpdump -enni any host 2.2.2.2 and port 444
fw monitor -e "accept host(2.2.2.2) and port(444);"
fw monitor -e "accept host(1.1.1.1) and host(2.2.2.2) and port(444);"
fw monitor -F '1.1.1.1,0,2.2.2.2,444,0" -F "2.2.2.2,0,1.1.1.1,444,0"
Idea is when you do -F flad you follow "srcip,srcport,dstip,dstport,protocol"
You can also refer to great site my colleague made over the years for captures/debugs on different vendors
Andy
Fix the application that is causing the problem.
If that's not possible, you can disable it for a specific flow by following the steps here: https://support.checkpoint.com/results/sk/sk11088
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY