sk182623 - Security Gateway in the Bridge Mode, with SecureXL in the UPPAK mode, drops on IPX / Ixia monitor connections
Security Gateway in the Bridge Mode, with SecureXL in the UPPAK mode, drops on IPX / Ixia monitor connections
Product: SecureXL
Version: R81.20
OS: Gaia
Last Modified: 2025-02-26
Symptoms
- IPX / Ixia monitor connections do not pass through a Security Gateway in the Bridge Mode.
- Kernel debug on the Security Gateway (
fw ctl zdebug + drop) shows that IPX traffic (protocol 0x8137) is dropped.
Example:[ADP];adp_netfilter_brin: Ethtype 0x8137 not recognized (skb->protocol=0x8137) Bridge packet received on interface eth1-02(26) (unsupported feature) (DROP); - Following sk101371 to set the value of the
"fwaccept_unknown_protocol"parameter to 1 does not resolve the issue. - Changing the SecureXL mode on the Security Gateway from UPPAK to KPPAK and rebooting resolves the issue.
Solution
This problem was fixed. The fix is included starting from:
- Check Point Quantum R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 90
Check Point recommends to always upgrade to the most recent version
(upgrade Security Gateway / upgrade Security Management Server / upgrade Multi-Domain Security Management).
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-08-26
Last Modified: 2025-02-26