sk181874 - Dynamic Routing Manager failback causes "TCP out of state: First packet isn't SYN" drops
Dynamic Routing Manager failback causes "TCP out of state: First packet isn't SYN" drops
Product
Maestro HyperScale Firewall, Scalable Chassis
Version
R81 (EOS), R81.10 (EOS), R81.20
OS
Gaia
Last Modified
2024-07-01
Symptoms
- After dynamic routing manager failure and recovery, connections are dropped with a log message "TCP out of state: First packet isn't SYN"
- Firewall kernel debug shows these connections were declared as zombie connections:
# fw ctl zdebug -m cluster + unisync
fwha_iter_should_handle_conn: ERROR: no member will do iterator for this conn (zombie?).;
conn_entry_iterator_cb: Deleting zombie connection;
Cause
This scenario is unique when two Security Gateway Modules (SGMs) are configured in the security group along with dynamic routing protocol and there are symmetric connections on the non-SMO Security Gateway Module.
In such scenario, a connection can be considered as a zombie connection and not synchronized on SGM-1 recovery phase.
When SGM-1 is ready to be active again, the 'ROUTED' pnote is set on the SGM-2 to force its state to "Down" and moves the dynamic routing manager (DR manager) task back to SGM-1.
As the connection was not synchronized, it results in the connection drop
dropped by fw_first_packet_state_checks Reason: First packet isn't SYN;
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 70
- Jumbo Hotfix Accumulator for R81.10 starting from Take 141
- Jumbo Hotfix Accumulator for R81 starting from Take 99
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-01-09
Last Modified: 2024-07-01