are there any java applets or java applicaions involved?
We've had a similar problem and reveived the advise to move the http_proxy resource service to a new rule below the rule allowing the connection to the website. Unfortunately that didn't help us, because we didn't use and http proxy resources, but maybe it will point you in the right direction.
:-)Horst Brian Panulla wrote:
Apologies to anyone who's seen this post on the FW1-Gurus list... we're still looking for some suggestions on this.
We're getting trouble reports from some of our Web site users following the installation of a new CP Express NG AI R55 firewall. This box replaced a similar one running R54.
The problem: A small subset of our users sprinkled at universities and colleges across the US are having difficulty viewing pages on multiple Web servers behind our firewall. Web pages do not load entirely -- after waiting a while, a user can hit Stop in their browser and some portion of the complete page will display. Viewing source on the page shows that only portions of the HTML code have been recieved by the browser.
Version: Check Point Express NG with AI R55, HFA 01, HTTP Sec Server HF, SmartDefense 540040223 OS: R55 SecurePlatform (fresh install) HW: Dell PowerEdge 2500 Server, 1.4GHz P3, 512MB of RAM 2 Intel Pro 100/S dual port NICs Topology: 4 interfaces, 2 external ISP connections, 1 office LAN, 1 DMZ, Win 2000 IIS 5 Web servers in DMZ with Static NAT
Our previous firewall (CP Express NG AI R54 firewall on SecurePlatform) was configured without NAT -- all protected servers had statically defined public IPs. When we upgraded to R55, we moved to static NAT mappings for all servers in order to use the new ISP Redundancy features of R55. Each server has a private class C address, with a public address defined in the NAT properties of each server. A second public address on our redundant network is defined for each Web server via a static NAT rule.
Changes made to routing by our primary ISP have made it impractical to roll back to previous topology, especially with having to reconfigure all our servers back to public IPs.
The installation of the R55 firewall appeared to go well; all services were available when tested from outside the firewall, both on-site and off-site through alternate ISP connections.
Other information:
The one common denominator is that almost all users so affected reported some patch level of Internet Explorer, mostly Windows XP Professional OS, with a few on Mac OS.
- The problem was first reported a few days after the firewall install - Multiple users at each site have the same problem - Many, many more users at other sites have NO PROBLEMS - There is no common ISP/routing path between all these users - Users having issues see the problem whether the server is IIS or Apache - Users having issues see the problem using either of the two Redundant ISP addresses/routes for multiple servers - Users having issues see no problems accessing a similar server on our network placed OUTSIDE the firewall - Packet traces with Ethereal on the Web server show full data transmission - Packet traces with Ethereal outside the firewall look to be missing packets
NO CP SmartTracker LOG entries exist with the problem IPs as src or dest. However, since the upgrade we've been getting a lot of domain-udp entries dropped by Rule 0 - Implied Rules, but there doesn't appear to be a correlation between those and any of our problem sites.
We have been completely unable to recreate this problem with our own machines -- the best we've been able to do is to get on the phone with users who are seeing the problem halfway across the country
Okay, any suggestions on what to try next?
_____ Brian Panulla HigherEdJobs.com Programmer/Analyst [EMAIL PROTECTED]
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
-- :-)Horst Moll (Dipl.-Ing. TH) IT Sicherheitsberater ______________________________________________________
BDG GmbH & Co. KG - Make IT safe. Stollberger Str. 307 D-50933 Koeln
Tel: +49 (0)221-954231-0 direkt: +49 (0)221-954231-41 mobil: +49 (0)163-54231-41 Fax: +49 (0)221-954231-31
E-Mail: [EMAIL PROTECTED] Web: www.bdg.de PGP Fingerprint: F012 EBD9 8872 A00B E444 659C 5B64 C172 A126 B78F _____________________________________________________ ****************************************************************************************
Besuchen Sie uns auf der Cebit, 18.03.-24.03.2004 in Hannover, in der
Software Security Area, auf dem TREND MICRO Stand Halle 6, Stand G20
Sichern Sie sich gleich Ihren Besuchstermin unter
http://www.bdg.de/anmeld_cebit.html
****************************************************************************************
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
