The ccm-manager backhaul process is hunting through the primary, secondary call agents, then dropping the backhaul. All started after the customer's provider upgraded their Checkpoint firewall. Initially the gateway wasn't showing as registered in Call Manager after the upgrade. But after they patched the firewall for a known MGCP bug that was black-holing traffic the gateway shows as registered. But we cannot place calls and have forced the gateways into SRST as the ccm-manager backhaul process seems to be sending packets but not receiving any. The firewall logs are seeing traffic to the CCM on TCP 2428 and returning on the random source port........as per the tcpdump on the FW interfaces........but we never see the packets received in the "sh ccm-manager backhaul". Debug of the ccm-manager backhaul packets shows them being sent. UDP port 2427 is being seen in both directions also.