Support Center > Search Results > SecureKnowledge Details
IGMP packets generated by cluster members running on Gaia OS are dropped by the cleanup rule Technical Level
Symptoms
  • SmartView Tracker is filled with IGMP drop logs:

    Product = Security Gateway/Management
    Action = Drop
    Destination = 224.X.Y.Z
    Protocol = igmp
    Interface = Cluster_Sync_interface
    Product Family = Network


  • Kernel debug (fw ctl debug -m fw + conn drop) shows:

    [-- Stateful VM inbound: Entering (...) --];
    ;Before VM: <Source_IP_Address:0 -> 224.X.Y.Z:0 IPP 2> (len=28) (ifn=0) (first seen) ;
    ;fwconn_lookup: conn <dir 0, Source_IP_Address:0 -> 224.X.Y.Z:0 IPP 2>;
    ;not found in connections table;
    ;fw_cluster_ttl_anti_spoofing: Allowing local cluster packet by ttl, src Source_IP_Address_in_HEX, sport 0, dst Dest_IP_Address_224_in_HEX, dport 0;
    ;fwconn_lookup_other_ex: conn <dir 0, 224.X.Y.Z:0 -> Source_IP_Address:0 IPP 2>
    not found in connections table;
    ;fwconn_lookup_other_ex: conn <dir 0, 224.X.Y.Z:0 -> Source_IP_Address:0 IPP 2>
    not found in connections table;
    ;fw_handle_first_packet: Rulebase returned DROP;
    ;fw_handle_first_packet: match on rule Number_of_Clean_Up_Rule;
    ;fw_rule_count_count: counting one more connection on rule Number_of_Clean_Up_Rule
    ;fw_service_count_count: not counting service since service count is disabled;
    ;fw_log_drop: Packet proto=2 Source_IP_Address:N -> 224.X.Y.Z:M dropped by fw_handle_first_packet Reason: Rulebase drop - rule Number_of_Clean_Up_Rule;
    ;After VM: <Source_IP_Address:0 -> 224.X.Y.Z:0 IPP 2> (len=28) ;
    ;VM Final action=DROP;
    ; ----- Stateful VM inbound Completed -----
Solution
Note: To view this solution you need to Sign In .