Apologies to anyone who's seen this post on the FW1-Gurus list... we're
still looking for some suggestions on this.

We're getting trouble reports from some of our Web site users following the
installation of a new CP Express NG AI R55 firewall. This box replaced a
similar one running R54.

The problem:
A small subset of our users sprinkled at universities and colleges across
the US are having difficulty viewing pages on multiple Web servers behind
our firewall. Web pages do not load entirely -- after waiting a while, a
user can hit Stop in their browser and some portion of the complete page
will display. Viewing source on the page shows that only portions of the
HTML code have been recieved by the browser.

Version:        Check Point Express NG with AI R55, HFA 01, HTTP Sec Server HF,
                        SmartDefense 540040223
OS:             R55 SecurePlatform (fresh install)
HW:             Dell PowerEdge 2500 Server, 1.4GHz P3, 512MB of RAM
                2 Intel Pro 100/S dual port NICs
Topology:       4 interfaces, 2 external ISP connections, 1 office LAN, 1 DMZ,
                Win 2000 IIS 5 Web servers in DMZ with Static NAT

Our previous firewall (CP Express NG AI R54 firewall on SecurePlatform) was
configured without NAT -- all protected servers had statically defined
public IPs. When we upgraded to R55, we moved to static NAT mappings for all
servers in order to use the new ISP Redundancy features of R55. Each server
has a private class C address, with a public address defined in the NAT
properties of each server. A second public address on our redundant network
is defined for each Web server via a static NAT rule.

Changes made to routing by our primary ISP have made it impractical to roll
back to previous topology, especially with having to reconfigure all our
servers back to public IPs.

The installation of the R55 firewall appeared to go well; all services were
available when tested from outside the firewall, both on-site and off-site
through alternate ISP connections.

Other information:

The one common denominator is that almost all users so affected reported
some patch level of Internet Explorer, mostly Windows XP Professional OS,
with a few on Mac OS.

- The problem was first reported a few days after the firewall install
- Multiple users at each site have the same problem
- Many, many more users at other sites have NO PROBLEMS
- There is no common ISP/routing path between all these users
- Users having issues see the problem whether the server is IIS or Apache
- Users having issues see the problem using either of the two Redundant
  ISP addresses/routes for multiple servers
- Users having issues see no problems accessing a similar server on our
   network placed OUTSIDE the firewall
- Packet traces with Ethereal on the Web server show full data transmission
- Packet traces with Ethereal outside the firewall look to be missing
   packets

NO CP SmartTracker LOG entries exist with the problem IPs as src or dest.
However, since the upgrade we've been getting a lot of domain-udp entries
dropped by Rule 0 - Implied Rules, but there doesn't appear to be a
correlation between those and any of our problem sites.

We have been completely unable to recreate this problem with our own
machines
-- the best we've been able to do is to get on the phone with users who are
seeing the problem halfway across the country

Okay, any suggestions on what to try next?

_____
Brian Panulla                                           HigherEdJobs.com
Programmer/Analyst                                      [EMAIL PROTECTED]

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to