sk181525 - Cleanup rule/Stealth rule drops SIP response packets

Cleanup rule/Stealth rule drops SIP response packets

Product: Maestro HyperScale Firewall, Security Gateways, Spark Firewall
Version: R80.40 (EOS), R81 (EOS), R81.10.X, R81.20
OS: Gaia, Gaia Embedded
Last Modified: 2024-06-05

Symptoms

For example, if the internal client/server sends REGISTER to the external server, the Security Gateway drops the response for this packet (401 or 200 ok, for example).

The same occurs when an INVITE packet goes through the Security Gateway. The response to this packet is dropped.

Cause

The Security Gateway cannot find the connection in the connection table (even though the symbolic links were created), "rolls" a new early NAT port, and tries to match the "new" connection against the rulebase.

Because the rulebase was configured as one-directional, the traffic (the response) is in a different direction and does not match the same rule, possibly matching a clean-up rule.

Note: When you use hide NAT, the returning traffic sends the traffic towards the IP address of the Security Gateway. As a result, it hits a stealth rule.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, as a workaround, reconfigure the rule to be bidirectional. Make sure this rule is above the drop rule.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2023-10-06
Last Modified: 2024-06-05