Hi List, After an upgrade of our Provider-1 from SP-4 to SP-6 we have experienced a lot of drops on rule 0 (unknown established TCP packet). A lot of people have complained over ssh-sessions that times out (freezes).
We suspect that a setting in base.def or some of the .def files have "dissapeared" after the upgrade. We have some suggestions after doing some research and the things we have found is: * duplicate objects / services - Have checked that *#define ALLOW_NON_SYN_RULEBASE_MATCH in objects.C *tcp_start_timeout/tcp_end_timeout The last thing we want to do is to uncomment the allow_non_syn_rulebase_match but if we can't figure out something else i guess we have to. Does anyone have any suggestions or have experienced this problem and knows a way to solve this issue? Would an increase of the tcp_start/end timeout values help? We tried to increase the tcp session timeout from 3600->7200 without success. Best Regards Petra ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
