> Source: [sk184377](https://support.checkpoint.com/results/sk/sk184377)

# sk184377 - Unauthorized ICMP Traffic on Maestro Orchestrator's Management Port During Reboot

| Property | Value |
|----------|-------|
| Solution ID | sk184377 |
| Date Created | 2025-11-27 |
| Last Modified | 2025-12-01 |
| Technical Level | Advanced |
| Products | Scalable Platforms |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- * Unauthorized Internet Control Message Protocol (ICMP) traffic destined for internal IP addresses (examples: 192.0.2.x and 203.0.113.x) is observed on the Management Port (Mgmt1) of the Maestro Orchestrator during reboot or service restart.

* The next Gateway the traffic reaches logs and accepts the traffic because of the configured implied rules (default rules that allow certain traffic).

* The routing table on the Maestro Orchestrator contains automatically generated entries for Maestro Security Group Members (SGMs) that should run over downlink ports, but are instead routed via Mgmt1.

## Cause

When a Maestro Orchestrator reboots or its services restart, the synchronization ports (local-sync and external-sync) are temporarily down.

During this period, static routes for internal destinations (such as 192.0.2.x and 203.0.113.x) become invalid during sync port downtime. The system falls back to the default route, which is configured to use the Mgmt1 port.

As a result, ICMP ping probes (ICMP echo requests used for connectivity checks) generated by the Maestro Orchestrator to check connectivity to other Maestro Orchestrators are sent out via the Mgmt1 port and reach the next Gateway in the path..

When the synchronization ports are up, the static routes become valid and traffic is correctly routed through the synchronization ports.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
