|
The problem is that the last connection is not getting properly cleared.� Either because the RST packet was never properly received by the Firewall, or the firewall did not properly reset the connection.� Either way, the old connection is still in the connections table.� Normally, you could avoid this by lowering the session timeout for the particular service (port) you are using, however, the minimum session timeout value is 5 minutes, so this won’t be much use to you (since you’re polling every 1 minute).� The other option is to modify the firewall to turn off state inspection for the particular service you are using.� Checkpoint has a few knowledgebase articles on how to do this.� Remember though, turning off state inspection is a bad thing, and can open some security holes in your firewall, especially if this is a commonly used service, like HTTP.
Mike Feetham -----Original Message-----
Terje Vernholt a �crit:
Hi, I am running a FP2 Nortel Alteon HA cluster, and use an application that polls a server for information.
For each poll, the application uses the same source and destination portnumber, sets up a connection with three way handshake, retrives a small amount of data, and ends the connection with a RST.
This works fine for a while (the application is polling with about 60 second intervals), then suddenly the syn packets from the clients starts to drop in the FW with the message "syn packet for established tcp".
Anybody have any ideas how to fix this problem ?? nope, but I've got the same problem on nokia IP 530
(ipso 3.6 fcs6) with CP FW1 NG FP3.
regards Terje
|
- Re: [FW-1] FP2 : SYN packet for established tcp nicolas figaro
- Mike Feetham
