sk181874 - Dynamic Routing Manager failback causes "TCP out of state: First packet isn't SYN" drops

Dynamic Routing Manager failback causes "TCP out of state: First packet isn't SYN" drops

Product

Maestro HyperScale Firewall, Scalable Chassis

Version

R81 (EOS), R81.10 (EOS), R81.20

OS

Gaia

Last Modified

2024-07-01

Symptoms

# fw ctl zdebug -m cluster + unisync
fwha_iter_should_handle_conn: ERROR: no member will do iterator for this conn (zombie?).;
conn_entry_iterator_cb: Deleting zombie connection;

Cause

This scenario is unique when two Security Gateway Modules (SGMs) are configured in the security group along with dynamic routing protocol and there are symmetric connections on the non-SMO Security Gateway Module.

In such scenario, a connection can be considered as a zombie connection and not synchronized on SGM-1 recovery phase.

When SGM-1 is ready to be active again, the 'ROUTED' pnote is set on the SGM-2 to force its state to "Down" and moves the dynamic routing manager (DR manager) task back to SGM-1.

As the connection was not synchronized, it results in the connection drop

dropped by fw_first_packet_state_checks Reason: First packet isn't SYN;

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2024-01-09
Last Modified: 2024-07-01