hi,

I've installed the patches on R54 and R55 and it works well.

the value for fwseqvalid_exact_syn_on_rst depends on what traffic you have
through your firewall. if you have long-tcp-sessions (large and slow ftp,
bgp, etc) use a higher value, if you have short tcp-sessions (http, https,
smtp) it's not problem to have a low value.

to find out what is good for you network:

1. have tcp-sequence-number-checking avtive bevor you set this value
2. look at your logs if there are drops because of this rule and learn what
is "normal" for you
3. fwseqvalid_exact_syn_on_rst to any value you think that is good for you
4. see if your logs still look normal.

don't forget to disable flows if you have a nokia.

cheers
reinhard

At 18:12 22.04.2004, you wrote:


Good Day Ladies and Gents,



I have a query referring to the NISCC Vulnerability Advisory 236929 @
http://www.uniras.gov.uk/vuls/2004/236929/index.htm



Check Point Brought out a Solution regarding  this issue to apply hot
fixes R55 HFA - 03, R54 HFA -410 or NG FP3 HFA - 325 relevant to the
environments you are running.



Steps to be taken are to apply HFA to both enforcement modules and
management stations and set the kernel global variable
fwseqvalid_exact_ayn_on_rst to control this feature and last of all is
to verify the TCP Sequence Verifier in smart defense is set to track
anomalous out of state packets.

http://www.checkpoint.com/techsupport/alerts/tcp_dos.html





Has any done this as yet and has anyone incurred any issues due to this
solution, my main concern was the kernel global variable change



Please Advice



Regards



Jeremy Kaweesa
Network Operations
Smart Systems for Health Agency
C:  416-618-8096
BlackBerry Pin: 2003F994
[EMAIL PROTECTED]

www.ssha.on.ca

________________________________________________

This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they are
addressed.   If otherwise received, please destroy. Please Destroy.




================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================

-- Reinhard Stich ASSIST [EMAIL PROTECTED] Internet Security AG, 1150 Wien, Johnstrasse 29 Tel: +43 1 3709440 RS784-RIPE Fax: +43 1 3709440-333

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to