This sounds like an authentication timeout issue.  Email me offline if you
are still having this problem.

--
Ted Serreyn              Phone:262-432-0260 Fax:262-432-0232
Serreyn Network Services, LLC        http://www.serreyn.com/


-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Mohr James
Sent: Tuesday, June 01, 2004 5:23 AM
To: [EMAIL PROTECTED]
Subject: [FW-1] Unexplainable drops, CP versions, etc

Hi All!

Please forgive my newbie questions. Our previous FW admin is no longer with
is and this was tossed into my lap. Although a training course would
definately be useful it is simply not going to happen. My boss has the
attitude that we get paid the "big bucks" for being able to figure things
out without training courses. Whether this is efficient, productive or
whatever is not the issue. I am not going to get the training.

Nevertheless, I am in desperate need of help.

We are having problems connection through the CP, typically FTP and the
Windows Terminal Server (Port 3389). This setup has been working since the
dawn of time. In fact, these are the primary methods people use to connect
through the firewall and it has worked fine until last week when "something"
happened. Unfortunately no one know what or no one is willing to say what
has changed.

The packets are getting dropped by our last rule ("drop everything else").
However, these packets should be dropped. I can see that some get through
and the user can connect. When they try aga�n they don't get through
(typically timeout errors). Or they get the timeout, then try again in a few
minutes and they ge through. It is not limited to specific target or
destination machines. With one caveat: the machines that are having problems
need to first authenticate on the firewall using an RSA token. I do not have
the problem as I am in a protected area which has access without first
having to authenticate myself on the firewall through the RSA Server. As far
as we can tell, they are able to successfully authenticate on the RSA
server.

It does not appear as if the server is overloaded. We have two machines in a
full cluster and it does not seem like it is just one specific machine that
is having the problems. Someone mention the possibility of a synchronization
problem. However, I can see that the same firewall will drop the packet and
then a minute later accept it. Both are under 10% untilization (using both
sbfc and vmstat).

Another thing is figuring out what version we have. I assume that we have
FW1 NG as we have a link in /opt: CPfw1-NG -> /opt/CPfw1-50. However,
looking through the checkpoint.com web site, I am having trouble locating
exactly where this product fits into the scheme of things. Also is there any
documentation online anywhere? PDF versions of the manual or whatever?

Any and all help is greatly appreaciated.

Regards,

Jim Mohr

ELAXY Brokerage & Trading GmbH & Co KG
_________________________________
James Mohr
Systembetrieb
Am Hofbr�uhaus 1
96450 Coburg
Germany
Fon +49 (0) 95 61.55 43.0
Fax +49 (0) 95 61.55 43.302
E-Mail: [EMAIL PROTECTED]
---------------------------------------
"Be more concerned with your character than with your
reputation. Your character is what you really are while
your reputation is merely what others think you are." --
John Wooden
---------------------------------------
Be sure to visit the Linux Tutorial:
http://www.linux-tutorial.info

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to