CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-01
Junior Member
 
Join Date: 2007-08-14
Posts: 14
Rep Power: 0
james.mathieson has an average reputation (10+)
Default TCP packet out of state

Hi all,

I'm having a few issues with checkpoint and was wondering if anyone has any advice.

I have a server, that keeps giving me the following message on tracker, "TCP packet out of state. First packet isn't SYN tcp_flags: PUSH-ACK"

This server I believe is initiating the connection to the destination server for authentication. After a few attempts, everything works and gets let through the firewall.

We are using NGX R60 and this is running on NOKIA boxes with IPSO, but am not sure which version as I don't have access to the boxes at the moment.

Are there any known issues for this?

Kind regards

James
Reply With Quote
  #2 (permalink)  
Old 2007-10-01
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: TCP packet out of state

RE: [fw1-gurus] TCP packet out of state: First packet isn't SYN

It references gateway clusters with a sync network that is under load, not sure if that applies but the settings may be worth checking:

Quote:
When the synchronization mechanism is under load, TCP packet out-of-state error messages may appear in the information column of SmartTracker. This section explains how to resolve each error.

TCP packet out of state - first packet isn't SYN tcp_flags: FINACK
TCP packet out of state - first packet isn't SYN tcp_flags: FINPUSH-ACK

These messages occur when a FIN packet is retransmitted after deleting the
connection from the connection table.

To solve the problem, in the SmartDashboard Global properties for Stateful
Inspection, enlarge the TCP end timeout from 20 seconds to 60 seconds. If necessary, also enlarge the connection table so it won't get full.
Reply With Quote
  #3 (permalink)  
Old 2007-10-01
Junior Member
 
Join Date: 2007-08-14
Posts: 14
Rep Power: 0
james.mathieson has an average reputation (10+)
Default Re: TCP packet out of state

Hi,

Unfortunately the timeout is at that value already as I was just looking. The server involved that is related to these problems has two network cards on different networks, so I'm wondering if the server is getting confused about which interface to use.

Just a thought.

Many thanks for your reply.

James
Reply With Quote
  #4 (permalink)  
Old 2007-10-01
Member
 
Join Date: 2006-07-10
Location: Germany
Posts: 42
Rep Power: 0
jacobsen has an average reputation (10+)
Default Re: TCP packet out of state

Hi,

I had the same issue.
I've figuered out, that disabling SecureXL lowers the amount of "tcp out of state" pretty much.

fwaccel stat
fwaccel off

give it a try.

hopefully it's better with R65.
Reply With Quote
  #5 (permalink)  
Old 2008-07-17
Junior Member
 
Join Date: 2007-05-08
Posts: 13
Rep Power: 0
synick has an average reputation (10+)
Default Re: TCP packet out of state

Can this error be related to something other than Cluster State Sync?

I have had a similar error with a server trying to access a database server, Traffic coming one way is fine, coming back it gets blocked on a different with this error.

Found out that the DB server was holding connections open for a long time, and when traffic came in it was using a held port to communicate back. That port is being block on the FW.
Reply With Quote
  #6 (permalink)  
Old 2008-07-21
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: TCP packet out of state

Quote:
Originally Posted by synick View Post
Found out that the DB server was holding connections open for a long time, and when traffic came in it was using a held port to communicate back. That port is being block on the FW.
If the reply back is being held long enough, it could be considered out of state. You might consider adjusting timeout values found under Smart Dashboard -> Policy -> Global Properties -> Stateful Inspection. Althought normally the default values are good. Ideally you'd improve the performance of your DB cluster so that the response is not delayed.
__________________
Its all in the documentation.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 21:09.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0