Mike _ a écrit :
Hello,
I had a problem with passive ftp on a NGX R65 Power (SmartDefense is disabled)

ClientX (NAT: Hide behind Gateway (Checkpoint FW)) make a connection (TCP) to a 
HTTP/FTP Server.
The ftp starts and goes into a timeout...

Security Policy:
Source (ClientX) -> Destiantion (Webserver) -> Service (Ftp, Ftp-pasv) -> 
Action(Accept)

In the SmartView Tracker:
Direction: ClientX to Webserver: Accept
Direction: Webserver to ClientX:
Product:                        VPN-1 Power/UTM
Origin:                         FW
Type:                           Log
Action:                         Drop
Protocol:                       tcp
Service:                        15825
Source:                         Webserver
Destination:                 FW
Source Port:                 tcp21
Information:                  TCP packet out of state: First packet isn't SYN
                                     tcp_flags: FIN-ACK
SmartDefense Profile:  No Protection

the gateways sees a fin-ack packet without a syn.
try to capture the traffic on the internal and external interface with tcpdump or fw monitor.

check if you don't have any assymetric routing.

Can anyone help by the problem?
greetings
Mike Deutsch

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to