Hi List,

After an upgrade of our Provider-1 from SP-4 to SP-6 we have experienced
a lot of drops on rule 0 (unknown established TCP packet). A lot of people
have complained over ssh-sessions that times out (freezes).

We suspect that a setting in base.def or some of the .def files have
"dissapeared" after the upgrade.

We have some suggestions after doing some research and the things we have found is:

* duplicate objects / services - Have checked that
*#define ALLOW_NON_SYN_RULEBASE_MATCH in objects.C
*tcp_start_timeout/tcp_end_timeout

The last thing we want to do is to uncomment the allow_non_syn_rulebase_match
but if we can't figure out something else i guess we have to.

Does anyone have any suggestions or have experienced this problem and knows a way to 
solve
this issue?

Would an increase of the tcp_start/end timeout values help? We tried to increase the
tcp session timeout from 3600->7200 without success.

Best Regards
Petra

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to