CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've just added two more speakers!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Services
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-16
mel4fun mel4fun is offline
Junior Member
 
Join Date: 2007-03-29
Posts: 2
mel4fun has an average reputation (10+)
Default TCP sequence validator: dropped packet with invalid ACK number

Hi,

Need some advise on the following error message :
TCP sequence validator: dropped packet with invalid ACK number

Fast facts
Gateway : Nokia IP 440 IPSO 3.7 Build 031
Checkpoint : R55

Host A : AIX box
Host B : Unix box
Host C : Destination server

FW policy

Source Destination TCP Port Action
Host A -> Host C -> TCP 3140 -> Accept (error message)
* Telnet from host A via TCP 3140. No connection

Host B -> Host C -> TCP 3140 -> Accept (no error message)
* Telnet from Host C via TCP 3140, connection is working fine.

Both Host A & Host B are sitting in the same IP segment (same switch).
With all other parameters remaining contstant (same destination, same TCP port), we cannot identify where goes wrong.

The fact is that using the same TCP port, one host is working but not the other.

Could someone assist to advise what could be the issue and any work around.
Thank you.

Last edited by mel4fun : 2007-07-16 at 20:18.
Reply With Quote
  #2 (permalink)  
Old 2007-07-17
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 805
mcnallym has an average reputation (10+)
Default Re: TCP sequence validator: dropped packet with invalid ACK number

Do you have IPSO Flows enabled on the Nokia. I see you are using IPSO 3.7 and Check Point R55, so the Nokia will be on IPSO flows to accelerate traffic rather then SecureXL.

If flows is enabled then disable the feature as not supported to have flows and sequence verifier enabled on the same box, or disable the sequence verifier.

I see that one is AIX and one is another flavour of UNIX. I have seen issues where different flavours of UNIX implement differently. I have seen issues similar to this with FTP Servers and clients as well.

Of course I presume that you realise that the hardware and the IPSO versions you are on are all out of support now for some time.
Reply With Quote
  #3 (permalink)  
Old 2007-07-17
mel4fun mel4fun is offline
Junior Member
 
Join Date: 2007-03-29
Posts: 2
mel4fun has an average reputation (10+)
Default Re: TCP sequence validator: dropped packet with invalid ACK number

Hi,

Thanks for the advice.

Problem found, and a silly mistake.

There is a static route on the Nokia for Host A, but pointing to the wrong interface. Instead of pointing inwards, it was pointing outwards to the external router.

Therefore, when we initiate the TCP 3140 from Host A, the return TCP ACK from Host C never return, thus the error.

The TCP ACK is bouncing between the firewall external and router interface.

Silly mistake but glad that we resolve it.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:55.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0