The host is only the static nat without any other configuration. The log only show accept, no smartdefense drop or rejected. I check those possible before the post. There is one thing interesting. Before the HFA02, the log destination is the web server object's private ip(original ip), i.e A. After the patch, the destination become the static nat IP, i.e. B.

It display from the follow
someone   A   http   accept

to
someone   B   http   accept

I don't know if it will affect something. In my experience, the destination which is not the the host ip sometimes are NAT issue. I check everything about it, nothing conflict.

Any idea?

regards,
Thomas

Chkp Videotron wrote:
Hey Thomas, I'd like to know if you created this static nat server as a web 
server as a product installed on and then used it for protection within web 
intelligence. If so, check your logs for entries with smart defense. It may 
very well be a web intelligence protection. If it's the case, try to see what 
protection is being enforced and check to see if it's authorized traffic or if 
it's perhaps malicous.
cheers!
-----Original Message-----
From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On 
Behalf Of Thomas
Sent: Wednesday, February 01, 2006 6:56 AM
To: [email protected]
Subject: [FW-1] HTTP Download stop randomly with R60 HFA02

Hi All,
OS: SPLAT R60 HFA02
Firewall: R60 HFA02
A web server inside the firewall with static nat to the Internet. There are some files in the web server let the users download. Before the the HFA02(it means R60, and R60 HFA01) the download is without any problem. After apply the HFA02, the download will stop at any point of the files. Using the fw monitor check found that the packets during the download sent from the web server did receive by the firewall in the receiving interface, but not sent out the interface to the outgoing interface.
For example,
web server--------eth0==f/w==eth1--------user
the last capture show that ony "i eth0", no "eth0 I" , "o eth1" , "eth1 O".
If download from other interface without nat, it become correctly. Client inside the firewall with the hide nat and download from the Internet, it is fine too.
Does anyone get the problem?
--
Best Regards,
Thomas Su
Dynasafe Technologies, Inc.
=================================================
To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL 
PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options, email 
[EMAIL PROTECTED] =================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================


=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to