sk182667 - SIP reply packets drops on the cleanup rule

SIP reply packets drops on the cleanup rule

Product: Security Gateways
Version: R81 (EOS), R81.10 (EOS), R81.10.X, R81.20
Last Modified: 2024-10-22

Symptoms

Cause

When a SIP request arrives at the Security Gateway, it automatically allows a return traffic connection on the same Firewall instance as the request. If the reply that arrives at the dispatcher is dispatched to a different Firewall instance, it is dropped by the cleanup rule as an unknown connection.

An example of a one-direction SIP over UDP rule:

Source Destination Service Action Install on
Net_A Net_B sip Accept Gateway

Net_A and Net_B are IP phone network objects (Nodes or networks).

This rule only allows IP Phones from Net_A to start calls to IP Phones on Net_B.

Solution

This problem was fixed. The fix is included starting from:

If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:

  1. CPinfo file from the Management Server involved in the case.
  2. CPinfo file from the Security Gateway / each Cluster Member involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

The kernel global parameter sip_forward_if_needed was added. When this parameter is enabled, the Security Gateway saves the connection's instance number and forwards the response back to the correct instance when it arrives.

To enable the global parameter on the fly, run the command:

fw ctl set int sip_forward_if_needed 1

To enable the global parameter so it survives a Security Gateway reboot, add this line to the _$FWDIR/boot/modules/fwkern.conf_ file:

sip_forward_if_needed=1

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2024-10-14
Last Modified: 2024-10-22