Hello everyone. I have noticed recently that all update sites fails on XG v17 MR6. Microsoft Updates, Google chrome, PDQ Deploy. Name it. All of them. I have already posted about a "clean up rule" that can be on all firewalls in the galaxy, except Sophos. I am posting here another behavior no one can expect coming from another suppliers' firewall. Bellow is a self explanatory log for a "temporary update server" 10.31.10.135. Rule 1 is an any-any-any rule. i.e. allow everything. "Could not associate packet to any connection." happens once in a while on any firewall. 5 to 10 % maybe ? But XG v17 MR6 brings this to a whole new level at 90%. Besides VPN that falls many times a day, this one is new (as far as I am concerned) with XG v17 MR6. By the way, Checkpoint do not behave as such: SPLAT, GAIA, or embedded GAIA. So, most likely, it is not a problem with our servers. Like they say, another day, another misery !!!
Time Log Comp Action Username Firewall Rule In Interface Out Interface Source IP Destination IP Source Port Destination Port Protocol Rule Type Message ID Live PCAP Message
2018-04-04 14:47 Firewall Rule Allowed 1 Port1 Port2 10.31.10.135 13.68.93.109 62738 443 TCP 1 1 Open PCAP
2018-04-04 14:47 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62668 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:47 Invalid Traffic Denied 0 Port1 10.31.10.135 52.84.96.66 62661 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:47 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62667 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:47 Firewall Rule Allowed admin@acme . c o m 1 Port1 Port2 10.31.10.135 208.111.183.38 62911 80 TCP 1 1 Open PCAP
2018-04-04 14:47 Firewall Rule Allowed admin@acme . c o m 1 Port1 Port2 10.31.10.135 208.111.183.38 62910 80 TCP 1 1 Open PCAP
2018-04-04 14:47 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62668 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:47 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62667 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:47 Invalid Traffic Denied 0 Port1 10.31.10.135 52.84.96.66 62661 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62668 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62667 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 52.84.96.66 62661 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62668 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 52.84.96.66 62661 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62667 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 52.84.96.66 62661 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62668 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62667 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62668 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 52.84.96.66 62661 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62667 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 52.84.96.66 62661 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62668 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62667 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:46 Firewall Rule Allowed 1 Port1 Port2 10.31.10.135 34.224.155.5 62743 443 TCP 1 1 Open PCAP
2018-04-04 14:46 Firewall Rule Allowed 1 Port1 Port2 10.31.10.135 65.55.163.222 62741 443 TCP 1 1 Open PCAP
2018-04-04 14:46 Firewall Rule Allowed 1 Port1 Port2 10.31.10.135 34.202.218.131 62739 443 TCP 1 1 Open PCAP
2018-04-04 14:45 Firewall Rule Allowed 1 Port1 Port2 10.31.10.135 65.55.163.222 62742 443 TCP 1 1 Open PCAP
2018-04-04 14:44 Firewall Rule Allowed 1 Port1 Port2 10.31.10.135 72.246.43.24 62694 80 TCP 1 1 Open PCAP
2018-04-04 14:43 Firewall Rule Allowed 1 Port1 Port2 10.31.10.135 13.78.168.230 62699 443 TCP 1 1 Open PCAP
2018-04-04 14:43 Firewall Rule Allowed 1 Port1 Port2 10.31.10.135 52.183.47.176 62697 443 TCP 1 1 Open PCAP
2018-04-04 14:43 Firewall Rule Allowed 1 Port1 Port2 10.31.10.135 40.77.232.92 62693 443 TCP 1 1 Open PCAP
2018-04-04 14:42 Firewall Rule Allowed anyuser@acme . c o m 1 Port1 Port2 10.31.10.135 40.112.152.16 62683 443 TCP 1 1 Open PCAP
2018-04-04 14:42 Firewall Rule Allowed anyuser@acme . c o m 1 Port1 Port2 10.31.10.135 40.112.152.16 62682 443 TCP 1 1 Open PCAP
2018-04-04 14:41 Firewall Rule Allowed anyuser@acme . c o m 1 Port1 Port2 10.31.10.135 52.26.219.15 62689 443 TCP 1 1 Open PCAP
2018-04-04 14:41 Firewall Rule Allowed anyuser@acme . c o m 1 Port1 Port2 10.31.10.135 72.21.91.29 62686 80 TCP 1 1 Open PCAP
2018-04-04 14:39 Firewall Rule Allowed anyuser@acme . c o m 1 Port1 Port2 10.31.10.135 52.84.96.66 62661 80 TCP 1 1 Open PCAP
2018-04-04 14:37 Firewall Rule Allowed anyuser@acme . c o m 1 Port1 Port2 10.31.10.135 52.84.95.35 62670 443 TCP 1 1 Open PCAP
2018-04-04 14:37 Firewall Rule Allowed anyuser@acme . c o m 1 Port1 Port2 10.31.10.135 208.111.183.38 62668 80 TCP 1 1 Open PCAP
2018-04-04 14:37 Firewall Rule Allowed anyuser@acme . c o m 1 Port1 Port2 10.31.10.135 208.111.183.38 62667 80 TCP 1 1 Open PCAP
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62544 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62545 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62545 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62544 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62544 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62545 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62545 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62544 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62544 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62545 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62545 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62544 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62545 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:36 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62544 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:32 Firewall Rule Allowed anyuser@acme . c o m 1 Port1 Port2 10.31.10.135 52.26.219.15 62565 443 TCP 1 1 Open PCAP
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62473 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62474 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Firewall Rule Allowed anyuser@acme . c o m 1 Port1 Port2 10.31.10.135 208.111.183.38 62545 80 TCP 1 1 Open PCAP
2018-04-04 14:26 Firewall Rule Allowed anyuser@acme . c o m 1 Port1 Port2 10.31.10.135 208.111.183.38 62544 80 TCP 1 1 Open PCAP
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62473 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62474 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62473 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62474 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62473 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62474 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62473 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62474 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62473 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62474 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62474 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:26 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62473 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:16 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 207.34.231.64 62491 80 TCP 1 1 Open PCAP
2018-04-04 14:16 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 207.34.231.64 62476 80 TCP 1 1 Open PCAP
2018-04-04 14:16 Invalid Traffic Denied 0 Port1 10.31.10.135 67.24.137.254 62451 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:16 Invalid Traffic Denied 0 Port1 10.31.10.135 69.192.18.179 62456 443 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:16 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 207.34.231.64 62475 80 TCP 1 1 Open PCAP
2018-04-04 14:16 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62409 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:16 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62408 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 208.111.183.38 62474 80 TCP 1 1 Open PCAP
2018-04-04 14:15 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 208.111.183.38 62473 80 TCP 1 1 Open PCAP
2018-04-04 14:15 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 207.34.231.64 62472 80 TCP 1 1 Open PCAP
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62409 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62408 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 69.192.18.179 62456 443 TCP 1 1 Open PCAP
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62409 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62408 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 67.24.137.254 62451 80 TCP 1 1 Open PCAP
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62409 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62408 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 207.34.231.64 62471 80 TCP 1 1 Open PCAP
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62409 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62408 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62409 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62408 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62409 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Invalid Traffic Denied 0 Port1 10.31.10.135 208.111.183.38 62408 80 TCP 0 1001 Open PCAP Could not associate packet to any connection.
2018-04-04 14:15 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 207.34.231.64 62470 80 TCP 1 1 Open PCAP
2018-04-04 14:15 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 207.34.231.64 62468 80 TCP 1 1 Open PCAP
2018-04-04 14:15 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 207.34.231.64 62467 80 TCP 1 1 Open PCAP
2018-04-04 14:15 Firewall Rule Allowed sophosmanagement@granicor.local 30 Port1 10.31.10.135 207.34.231.64 62466 80 TCP 1 1 Open PCAP
This thread was automatically locked due to age.