sk181823 - In a Maestro Security Group, a VSX Virtual System that connects to a Virtual Switch may drop traffic as "Out of State"
In a Maestro Security Group, a VSX Virtual System that connects to a Virtual Switch may drop traffic as "Out of State"
Product: Maestro HyperScale Firewall, VSX (Traditional)
Version: R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2024-02-04
Symptoms
Traffic logs from a Virtual System that connects to a Virtual Switch show that it drops some traffic as "Out of State", or wrongly drops it on a clean up rule.
Traffic capture in the Security Group:
- shows the traffic entering the Virtual Switch
- shows the traffic exiting the the Virtual Switch
- does not show the relevant traffic entering the relevant Virtual System
- shows the traffic then exiting the relevant Virtual System
- shows the reply traffic entering the relevant Virtual System
Cause
Traffic that arrives at the Virtual Switch is not forwarded correctly to the relevant Virtual System (skips it).
Solution
This problem was fixed. The fix is included starting from:
- Check Point R81.20 starting from Take 38
- Check Point R81.10 starting from Take 113
- Check Point R81 starting from Take 89
Check Point recommends to always upgrade to the most recent version ( VSX).
Workaround Procedure
If you choose not to upgrade, follow this workaround procedure.
Configure the value of the kernel parameter sim_warp_jump_strict_mac to 0.
The kernel parameter value of "0" configures SecureXL not to drop packets if they are sent to a MAC address that does not belong to the Virtual System / Virtual Switch that received these packets.
Follow the applicable procedure.
To change the value of the SecureXL kernel parameter permanently (recommended - survives reboot):
Connect to the command line of the Maestro Security Group.
Log in to the Expert mode.
Configure the value of the kernel parameter:
g_update_conf_file $PPKDIR/conf/simkern.conf sim_warp_jump_strict_mac=0Reboot the Maestro Security Group:
reboot -b allConnect to the command line of the Maestro Security Group.
Log in to Gaia gClish or the Expert mode.
Get the value of the kernel parameter (ignore the section "
FW:"):In Gaia gClish, run:
fw ctl get int sim_warp_jump_strict_mac -aIn the Expert mode, run:
g_fw ctl get int sim_warp_jump_strict_mac -a
To change the value of the SecureXL kernel parameter temporarily (does not survive reboot):
Connect to the command line of the Maestro Security Group.
Log in to Gaia gClish or the Expert mode.
Configure the value of the kernel parameter:
In Gaia gClish, run:
fw ctl set int sim_warp_jump_strict_mac 0 -aIn the Expert mode, run:
g_fw ctl set int sim_warp_jump_strict_mac 0 -a
Get the value of the kernel parameter (ignore the section "
FW:"):In Gaia gClish, run:
fw ctl get int sim_warp_jump_strict_mac -aIn the Expert mode, run:
g_fw ctl get int sim_warp_jump_strict_mac -a
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-01-29
Last Modified: 2024-02-04