This sounds like an authentication timeout issue. Email me offline if you are still having this problem.
-- Ted Serreyn Phone:262-432-0260 Fax:262-432-0232 Serreyn Network Services, LLC http://www.serreyn.com/ -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Mohr James Sent: Tuesday, June 01, 2004 5:23 AM To: [EMAIL PROTECTED] Subject: [FW-1] Unexplainable drops, CP versions, etc Hi All! Please forgive my newbie questions. Our previous FW admin is no longer with is and this was tossed into my lap. Although a training course would definately be useful it is simply not going to happen. My boss has the attitude that we get paid the "big bucks" for being able to figure things out without training courses. Whether this is efficient, productive or whatever is not the issue. I am not going to get the training. Nevertheless, I am in desperate need of help. We are having problems connection through the CP, typically FTP and the Windows Terminal Server (Port 3389). This setup has been working since the dawn of time. In fact, these are the primary methods people use to connect through the firewall and it has worked fine until last week when "something" happened. Unfortunately no one know what or no one is willing to say what has changed. The packets are getting dropped by our last rule ("drop everything else"). However, these packets should be dropped. I can see that some get through and the user can connect. When they try aga�n they don't get through (typically timeout errors). Or they get the timeout, then try again in a few minutes and they ge through. It is not limited to specific target or destination machines. With one caveat: the machines that are having problems need to first authenticate on the firewall using an RSA token. I do not have the problem as I am in a protected area which has access without first having to authenticate myself on the firewall through the RSA Server. As far as we can tell, they are able to successfully authenticate on the RSA server. It does not appear as if the server is overloaded. We have two machines in a full cluster and it does not seem like it is just one specific machine that is having the problems. Someone mention the possibility of a synchronization problem. However, I can see that the same firewall will drop the packet and then a minute later accept it. Both are under 10% untilization (using both sbfc and vmstat). Another thing is figuring out what version we have. I assume that we have FW1 NG as we have a link in /opt: CPfw1-NG -> /opt/CPfw1-50. However, looking through the checkpoint.com web site, I am having trouble locating exactly where this product fits into the scheme of things. Also is there any documentation online anywhere? PDF versions of the manual or whatever? Any and all help is greatly appreaciated. Regards, Jim Mohr ELAXY Brokerage & Trading GmbH & Co KG _________________________________ James Mohr Systembetrieb Am Hofbr�uhaus 1 96450 Coburg Germany Fon +49 (0) 95 61.55 43.0 Fax +49 (0) 95 61.55 43.302 E-Mail: [EMAIL PROTECTED] --------------------------------------- "Be more concerned with your character than with your reputation. Your character is what you really are while your reputation is merely what others think you are." -- John Wooden --------------------------------------- Be sure to visit the Linux Tutorial: http://www.linux-tutorial.info ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
