-----Original Message-----
From: Jason Cameron 
Sent: Wednesday, April 07, 2004 7:11 AM
To: [EMAIL PROTECTED]
Subject: FW-1: fwpacket_frombuf: len smaller than IP hlen (0<20) "


Subject: FW-1: fwpacket_frombuf: len smaller than IP hlen (0<20) "



I have a Nokia Ip 330 cluster ( vrrp) with AI . I have be getting the following 
message " FW-1: fwpacket_frombuf: len smaller than IP hlen (0<20) "

Please assist me. Is this a security problem as it seems as if this packet is been 
geneated and is not valid. I am 
concerned as I have secure client connections from the internet and Have allowed  
any>fw>fw1_topo,fw1_key,IKe,Ike_tcp,fw1_pslogon_NG,tunneltest,fw1_scv_keepalive.

I also have alot of these. 


Information:    TCP packet out of state: First packet isn't SYN 
                        tcp_flags: FIN-ACK 
 
Checkpoint has a solution but isnt this a Security Risk as I have network connected to 
the internet and private leased clients ??
 
 
� SYN packets are being dropped by the firewall for a specific application server  � 
Errors on console: "[LOG_CRIT] kernel: FW-1: fwpacket_frombuf: len smaller than IP 
hlen (0<20)"  � fw monitor shows SYN packet dropped at (i) but no packet length 
problem evident        
Solution 
 
Change the default behavior of sequence verifier's "fw_trust_suspicious_estab" (even 
if sequence verifier is disabled in the SmartDefence GUI:
 
1. Stop any SmartClient connections to the SmartCenter
2. Use dbedit or GUIdbedit to change fw_trust_suspicious_estab
3. Change the properties from:
:fw_trust_suspicious_estab (false)
to
:fw_trust_suspicious_estab (true)
4. Save changes and exit GUIdbedit
5. Open the Smartdashboard GUI and verify that the 'Sequence Verifier' is disabled 
(SmartDefence --> Network security --> TCP --> 'Sequence Verifier')



=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to