- reset +

Using CoreXL and SecureXL killed natted VPN traffic

As explained on sk62441 you can have serious problem in R71.30 if you have CoreXL + SecureXL + some VPN traffic being natted.
Even if the tunnel is up and running, you can ping remote hosts but TCP flows (http for instance) wont work.

You wont see any error message in the Tracker but you can catch them with "fw ctl zdebug drop" :

;[cpu_1];[fw_0];fw_log_drop: Packet proto=6 X.X.X.X:aaa -> Y.Y.Y.Y:bbb dropped by fw_conn_post_inspect Reason: fwconn_init_links (OUTBOUND) failed; 


Checkpoint released a fix for that, its name is : ilsiebel01_756_30124_0_sim_HOTFIX_FLINT_HF_HA30_076.gz

As far I know the problem is still there in R75