Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Troubleshooting Tips

From Tech-Wiki


Check Point troubleshooting checklist retained with a safety overlay.

ⓘ
Validation status
Reviewed for migration on 27 September 2026. Read-only observation should precede disabling security functions, clearing state or restarting services.
!
Some legacy steps are disruptive
Commands that disable IPS/SecureXL, remove a cluster member, stop services, reboot, unload policy or clear live connection state require explicit change control.

Original technical reference

If you are facing strange behavior, in an advanced/illogic scenario, evaluate/review the following items in this order:

  1. Policy
  2. NAT (correct NAT mode? Does it require manual proxy arp?)
  3. Routing
  4. Anti-spoofing (even from return packet, check logs in opposite direction)
  5. VPN Encryption domain (for your and remote peer)
  6. IPS (Use command: ips off)
  7. Connection Limit (fw ctl pstat)
  8. Disable SecureXL (Use command: fwaccel off)
  9. Test in the other cluster member (Use command: clusterXL_admin down –p)
  10. Issue a cpstop/cpstart or reboot
  11. Consider installing the latest Jumbo hotfix accumulator or Recommended Hotfixes (per sk106162 and sk106389)
  12. Did I forget something?!
  13. That’s probably a bug, raise a TAC

Confirm the reason of your packet being dropped using:

 fw ctl zdebug + drop | grep 'x.x.x.x\|y.y.y.y'

If log is stuck with existing old sessions (no new logs, or still showing traffic from previous policies), clear connection's table:

 fw tab -t connections -x

Official and supporting references