The problem is that the last connection is not getting properly cleared.� Either because the RST packet was never properly received by the Firewall, or the firewall did not properly reset the connection.� Either way, the old connection is still in the connections table.� Normally, you could avoid this by lowering the session timeout for the particular service (port) you are using, however, the minimum session timeout value is 5 minutes, so this won’t be much use to you (since you’re polling every 1 minute).� The other option is to modify the firewall to turn off state inspection for the particular service you are using.� Checkpoint has a few knowledgebase articles on how to do this.� Remember though, turning off state inspection is a bad thing, and can open some security holes in your firewall, especially if this is a commonly used service, like HTTP.

 

 

 

Mike Feetham
Senior Network Administrator
Percepta
416-228-6203 (office)
416-377-1582 (pager)

-----Original Message-----
From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of nicolas figaro
Sent: Monday, March 10, 2003 4:19 AM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] FP2 : SYN packet for established tcp

 

Terje Vernholt a �crit:

 

Hi,

I am running a FP2 Nortel Alteon HA cluster, and use an application that polls a server for information.

 

For each poll, the application uses the same source and destination portnumber, sets up a connection with three way handshake, retrives a small amount of data, and ends the connection with a RST.

 

This works fine for a while (the application is polling with about 60 second intervals), then suddenly the syn packets from the clients starts to drop in the FW with the message "syn packet for established tcp".

 

Anybody have any ideas how to fix this problem ??

nope, but I've got the same problem on nokia IP 530 (ipso 3.6 fcs6) with CP FW1 NG FP3.

NF

 

regards

Terje

 

================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================

Reply via email to