- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: PSL Drop ADVP on DHCP Packets
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PSL Drop ADVP on DHCP Packets
R80.20 Jumbo 47 Cluster does not seem to pass DHCP request/response traffic, debug log shows:
dropped by fwpslglue_chain Reason: PSL Drop: ADVP on port 67 traffic from the DHCP servers to the clients.
Anybody have a solution? I have the DHCP server in an IPS exceptions rule.
SmartConsole logs show the traffic is all accepted, but clients not receiving an IP address.
4 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DHCP Enforcement is not done in IPS.
Best to take some packet captures and engage with the TAC.
Best to take some packet captures and engage with the TAC.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Did You resolve it with TAC? I have similar issue on R80.40 take 91.
Best regards,
Rafal
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Dan_Currens,
I had the same fwpslglue_chain issue. You only need to install the last Jumbo 188.
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In my case it was old and new dhcp services used in policy. If we removed old one all drops this kind dropped by fwmultik_process_f2p_cookie_inner Reason: PSL Drop: ADVP disapear.
