<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Invalid Traffic / Invalid TCP state (no routing issue)</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/148051/invalid-traffic-invalid-tcp-state-no-routing-issue</link><description>Hello, I have a problem with mainly HTTPS connections showing up in the log as Invalid Traffic / Invalid TCP state. See screenshots below. 
 example domain is https://telekom.de 
 I have 2 Internet connections with separate NAT and SD-WAN routes. Routing</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Invalid Traffic / Invalid TCP state (no routing issue)</title><link>https://community.sophos.com/thread/548984?ContentTypeID=1</link><pubDate>Sat, 23 Nov 2024 10:20:40 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b822d92b-77dc-466a-85e1-924f56830d27</guid><dc:creator>Gerhard Sauer</dc:creator><description>&lt;p&gt;MTU size is 1492&amp;nbsp; on both internet connections&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Invalid Traffic / Invalid TCP state (no routing issue)</title><link>https://community.sophos.com/thread/548982?ContentTypeID=1</link><pubDate>Sat, 23 Nov 2024 08:29:50 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1c15c710-be51-4463-800d-e2d3867584d6</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;So, could it be an issue with the MTU size of your WAN GW?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Based on your tcpdump, it looks like an issue with the packets coming back from the server. As the servers packets are not valid for the firewall.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;My firewall(s) are not causing the same issues on any gateway.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;You could dump it into a file and analyze it via wireshark:&amp;nbsp;&lt;a id="" href="https://wiki.wireshark.org/TCP_Analyze_Sequence_Numbers"&gt;https://wiki.wireshark.org/TCP_Analyze_Sequence_Numbers&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;BTW: I found an interesting post on this subject:&amp;nbsp;&lt;a id="" href="https://blog.ipspace.net/2016/02/should-firewalls-track-tcp-sequence/"&gt;https://blog.ipspace.net/2016/02/should-firewalls-track-tcp-sequence/&lt;/a&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Invalid Traffic / Invalid TCP state (no routing issue)</title><link>https://community.sophos.com/thread/548981?ContentTypeID=1</link><pubDate>Sat, 23 Nov 2024 01:55:44 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:63ce77bd-ede9-425e-81e9-fefb469d25a7</guid><dc:creator>Gerhard Sauer</dc:creator><description>&lt;p&gt;both wan gateways are active and not on standby.&lt;/p&gt;
&lt;p&gt;The same happens, when I disable the first internet connection.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;each internet connection uses an own physical ethernet cable and own IP range. SD WAN routing and NAT routing applies to the machines.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Invalid Traffic / Invalid TCP state (no routing issue)</title><link>https://community.sophos.com/thread/548980?ContentTypeID=1</link><pubDate>Sat, 23 Nov 2024 01:46:09 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:eaecad6a-c1f3-47a3-bbe8-273fa90fe281</guid><dc:creator>Gerhard Sauer</dc:creator><description>&lt;p&gt;I cannot open the telekom website at all when tcp seq checking is on (on the second line)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Invalid Traffic / Invalid TCP state (no routing issue)</title><link>https://community.sophos.com/thread/548949?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 14:00:41 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1c4bd49c-9902-49f4-84ef-2eeb6ca1c722</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Just to be sure: Do you have any kind of Issue or is it only about the &amp;quot;invalid traffic&amp;quot; Logging?&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Invalid Traffic / Invalid TCP state (no routing issue)</title><link>https://community.sophos.com/thread/548947?ContentTypeID=1</link><pubDate>Fri, 22 Nov 2024 13:13:37 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:150f028e-adea-408c-8875-a898d3d454f9</guid><dc:creator>LHerzog</dc:creator><description>&lt;p&gt;How is your WAN Gateway setup? both lines active or one standby? Does the same happen when only one line is disconnected or disabled?&lt;/p&gt;
&lt;p&gt;First thought is about a asynchronous routing issue but you&amp;#39;d need to dump the traffic on CLI for each in and out interface and see where the packets are actually going.&lt;/p&gt;
&lt;p&gt;Incoming packets seem to match no active tcp connection - thus being dropped.&lt;/p&gt;
&lt;p&gt;Also cli tool drppkt may be helpful du analyze.&lt;/p&gt;
&lt;p&gt;I suspect that the traffic is at least in parts going over different interfaces.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>