Thanks Hugo,

But DNS is not the issue....because as soon as we turn Content
Inspection OFF....everything works fine....and we are still use the same
DNS servers.
So we can put that idea on the side for now.

The release notes do not say anything specific about this issue with
Content Inspection, unless I missed something and you have noticed it.

The mailing list is always my last hope before opening a case with
Checkpoint, just in case someone else ran into the same issue we have.




-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Hugo
van der Kooij
Sent: Monday, February 18, 2008 3:50 PM
To: [email protected]
Subject: Re: [FW-1] Content Inspection...Web Filtering on R65 no HFA

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Previtera, Sal wrote:
| Hello,
| Does anyone ran into issues with Content Inspection, Web Filtering
| In Monitor mode only or actually filtering...
|
| SPLAT CLUSTERXL in new mode....R65 no HFA...
|
| We had experience the following issue;
|
| Web Pages will not display correctly and had to Click on refresh to
get
| web pages to display correctly..
|
| Or get PAGE NOT FOUND....then try again and Web page display
correctly.
|
| The problem is intermittent, not any Web site specific; the gateways
| load is never more then 30 percent.
|
| The problem exists to users that go thru the firewall directly or use
a
| proxy-server, no difference there.
|
|
| Anyone else encountered this issue ?  does HFA fix this issue?

First off. If you look at the release notes there are plenty of relevant
issues. Always read the release notes.

Then there is the issue with DNS. If your DNS servers are not 250%
reliable you will get a lot of problems. In my experience a lot of DNS
servers can not handle the load a busy firewall will put them under and
it will have a direct negative impact on your webtraffic. (Note that you
will not see a big CPU load or such but the DNS server will simply be
too slow.)

Hugo.

- --
[EMAIL PROTECTED]               http://hugo.vanderkooij.org/
PGP/GPG? Use: http://hugo.vanderkooij.org/0x58F19981.asc

        A: Yes.
        >Q: Are you sure?
        >>A: Because it reverses the logical flow of conversation.
        >>>Q: Why is top posting frowned upon?

Bored? Click on http://spamornot.org/ and rate those images.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iD8DBQFHuf2IBvzDRVjxmYERAn47AJ91CB5bYjRiITY6NxplcKlK2JItdQCdE+hQ
YoZ5G22eNNuKKqeYUWfCFlw=
=FJA8
-----END PGP SIGNATURE-----

Scanned by Check Point Total Security Gateway.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to