Nope.  It's one of the special rules, like 1999 or 99500.

CP has taken to using an insanely large number to 'pick out' with granularity both 
implied rule behavior, and (especially) Semi-smartDefense behavior.  In this case, and 
similar for 997/8/9, it's MS DCE-RPC related.  Do a traffic capture, note the GUIDs.  
Rinse, repeat.


-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] Behalf Of Davis,
Nathaniel
Sent: Wednesday, June 02, 2004 1:21 PM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Outbound port 135 dropped by rule 996??


Look at your FW-1 policy.  Rule #996 is the policy entry that is dropping
the port 135 requests.  Rule #996 could be your cleanup rule.  If this
request doesn't match any of the criteria in your rule base it may be
getting dropped.  Once again, look at your FW-1 policy, if you don't have
access to it, talk to your security team.  Hope that helps.

Nathan

-----Original Message-----
From: Kevin Peuhkurinen [mailto:[EMAIL PROTECTED]
Sent: Wednesday, June 02, 2004 12:24 PM
To: [EMAIL PROTECTED]
Subject: [FW-1] Outbound port 135 dropped by rule 996??

Hi all.   I have some users who have Secureclient NG R55 installed on
their Windows XP based laptops which they use both at the office and at
home.   If it matters, my VPN encryption topology only includes a couple
of systems that they need to access from home.

Today one of them noticed that he could not connect the logical disk
management system of any servers on the network.   He disabled the SR
policy and stopped the SR service, but no avail.

I've confirmed this on a seperate system.  With the policy disabled I
cannot connect to the logical disk management system of any server.   In
the SR diagnostics log, I see a ton of dropped packets outbound on port 135,
apparently blocked by rule 996.

Any ideas as to what is going on?   Does Secureclient block certain RPC
calls even when the policy is disabled?   How can I find out what this
mystery rule 996 is?

Mucho thanks in advance,
Kevin

=================================================
To set vacation, Out-Of-Office, or away messages, send an email to
[EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to