<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Checkpoint blocks Mobility Control Path ('Old UDP Session') in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/checkpoint-blocks-mobility-control-path-old-udp-session/m-p/2139056#M36465</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;its not WLC issue, open case with checkpoint.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 31 Mar 2013 09:35:24 GMT</pubDate>
    <dc:creator>Saravanan Lakshmanan</dc:creator>
    <dc:date>2013-03-31T09:35:24Z</dc:date>
    <item>
      <title>Checkpoint blocks Mobility Control Path ('Old UDP Session')</title>
      <link>https://community.cisco.com/t5/wireless/checkpoint-blocks-mobility-control-path-old-udp-session/m-p/2139055#M36464</link>
      <description>&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;It happens on a regular basis, that our checkpoint firewall blocks control path traffic (UDP 16666) with the reason 'old UDP session'. When this happens our guest clients lose internet access. The connection restores only after I manually send a series of mping from foreign to anchor WLC.&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Setup: Several 2404 and 5508 foreign WLC with 7.0.235.3 and 7.2.111.3 on the inside corporate network are anchoring to a 5508 with 7.2.111.3 in the DMZ. These connections are used for Guest Internet Access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;FW Details: Checkpoint: R75.46 - Build 102 / Ipso (os): 6.2-GA055b06 clish 2.1 / HW:&amp;nbsp; IP1285&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;&lt;SPAN style="font-size: 10pt;"&gt;This situation is becoming really annoying especially as our WLAN infrastructure is growing fast. I would be much obliged for any help with this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:48:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/checkpoint-blocks-mobility-control-path-old-udp-session/m-p/2139055#M36464</guid>
      <dc:creator>Christian Faessler</dc:creator>
      <dc:date>2021-07-04T06:48:19Z</dc:date>
    </item>
    <item>
      <title>Checkpoint blocks Mobility Control Path ('Old UDP Session')</title>
      <link>https://community.cisco.com/t5/wireless/checkpoint-blocks-mobility-control-path-old-udp-session/m-p/2139056#M36465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;its not WLC issue, open case with checkpoint.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Mar 2013 09:35:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/checkpoint-blocks-mobility-control-path-old-udp-session/m-p/2139056#M36465</guid>
      <dc:creator>Saravanan Lakshmanan</dc:creator>
      <dc:date>2013-03-31T09:35:24Z</dc:date>
    </item>
    <item>
      <title>Checkpoint blocks Mobility Control Path ('Old UDP Session')</title>
      <link>https://community.cisco.com/t5/wireless/checkpoint-blocks-mobility-control-path-old-udp-session/m-p/2139057#M36466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it seems to be a checkpoint issue but I was hoping to find someone here who has the same problem and could help me with this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Apr 2013 07:00:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/checkpoint-blocks-mobility-control-path-old-udp-session/m-p/2139057#M36466</guid>
      <dc:creator>Christian Faessler</dc:creator>
      <dc:date>2013-04-02T07:00:38Z</dc:date>
    </item>
    <item>
      <title>Checkpoint blocks Mobility Control Path ('Old UDP Session')</title>
      <link>https://community.cisco.com/t5/wireless/checkpoint-blocks-mobility-control-path-old-udp-session/m-p/2139058#M36467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the problem occuring with every internal WLC or only a select few?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mobility keepalives originate from the controller with the lowest mac address. &lt;/P&gt;&lt;P&gt;If your problem is only occuring with a select few controllers. perhaps it is only the controllers that your Anchor WLC has the lower mac address of the pair.&amp;nbsp; (implying your Check Point is timing out when packets are sourced from DMZ to Internal but not the other way....)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If its not a directional issue, then perhaps you could decrease the mobility keepalive interval. I believe control packets (16666) are sent at 3x the data packets.&amp;nbsp; (so 30s for control and 10s for data)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;config mobility group keepalive interval&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than that, perhaps someone knows a checkpoint setting at fault....&amp;nbsp; but to Van's point, Checkpoint should be able to provide assistance &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Apr 2013 02:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/checkpoint-blocks-mobility-control-path-old-udp-session/m-p/2139058#M36467</guid>
      <dc:creator>wesleyterry</dc:creator>
      <dc:date>2013-04-03T02:35:02Z</dc:date>
    </item>
    <item>
      <title>Checkpoint blocks Mobility Control Path ('Old UDP Session')</title>
      <link>https://community.cisco.com/t5/wireless/checkpoint-blocks-mobility-control-path-old-udp-session/m-p/2139059#M36468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It seems that it was definetly a issue with the checkpoint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After some adjustments by our FW team, the situation became a lot better lattely.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Aug 2013 13:22:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/checkpoint-blocks-mobility-control-path-old-udp-session/m-p/2139059#M36468</guid>
      <dc:creator>Christian Faessler</dc:creator>
      <dc:date>2013-08-09T13:22:22Z</dc:date>
    </item>
  </channel>
</rss>

