Nope. It's one of the special rules, like 1999 or 99500. CP has taken to using an insanely large number to 'pick out' with granularity both implied rule behavior, and (especially) Semi-smartDefense behavior. In this case, and similar for 997/8/9, it's MS DCE-RPC related. Do a traffic capture, note the GUIDs. Rinse, repeat.
-----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] Behalf Of Davis, Nathaniel Sent: Wednesday, June 02, 2004 1:21 PM To: [EMAIL PROTECTED] Subject: Re: [FW-1] Outbound port 135 dropped by rule 996?? Look at your FW-1 policy. Rule #996 is the policy entry that is dropping the port 135 requests. Rule #996 could be your cleanup rule. If this request doesn't match any of the criteria in your rule base it may be getting dropped. Once again, look at your FW-1 policy, if you don't have access to it, talk to your security team. Hope that helps. Nathan -----Original Message----- From: Kevin Peuhkurinen [mailto:[EMAIL PROTECTED] Sent: Wednesday, June 02, 2004 12:24 PM To: [EMAIL PROTECTED] Subject: [FW-1] Outbound port 135 dropped by rule 996?? Hi all. I have some users who have Secureclient NG R55 installed on their Windows XP based laptops which they use both at the office and at home. If it matters, my VPN encryption topology only includes a couple of systems that they need to access from home. Today one of them noticed that he could not connect the logical disk management system of any servers on the network. He disabled the SR policy and stopped the SR service, but no avail. I've confirmed this on a seperate system. With the policy disabled I cannot connect to the logical disk management system of any server. In the SR diagnostics log, I see a ton of dropped packets outbound on port 135, apparently blocked by rule 996. Any ideas as to what is going on? Does Secureclient block certain RPC calls even when the policy is disabled? How can I find out what this mystery rule 996 is? Mucho thanks in advance, Kevin ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
