sk182667 - SIP reply packets drops on the cleanup rule
SIP reply packets drops on the cleanup rule
Product: Security Gateways
Version: R81 (EOS), R81.10 (EOS), R81.10.X, R81.20
Last Modified: 2024-10-22
Symptoms
- SIP reply traffic drops on the cleanup rule when one-direction SIP over UDP rule is configured in the rule base, and SIP-multicore is enabled.
Cause
When a SIP request arrives at the Security Gateway, it automatically allows a return traffic connection on the same Firewall instance as the request. If the reply that arrives at the dispatcher is dispatched to a different Firewall instance, it is dropped by the cleanup rule as an unknown connection.
An example of a one-direction SIP over UDP rule:
| Source | Destination | Service | Action | Install on |
| Net_A | Net_B | sip | Accept | Gateway |
Net_A and Net_B are IP phone network objects (Nodes or networks).
This rule only allows IP Phones from Net_A to start calls to IP Phones on Net_B.
Solution
This problem was fixed. The fix is included starting from:
- Check Point R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 79
- Jumbo Hotfix Accumulator for R81.10 starting from Take 158
- Jumbo Hotfix Accumulator for R81 starting from Take 106
If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the Security Gateway / each Cluster Member involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
The kernel global parameter sip_forward_if_needed was added. When this parameter is enabled, the Security Gateway saves the connection's instance number and forwards the response back to the correct instance when it arrives.
To enable the global parameter on the fly, run the command:
fw ctl set int sip_forward_if_needed 1
To enable the global parameter so it survives a Security Gateway reboot, add this line to the _$FWDIR/boot/modules/fwkern.conf_ file:
sip_forward_if_needed=1
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-10-14
Last Modified: 2024-10-22