Users of our network complained that they couldn't surf anymore. When
checking this out, I noticed drops on the firewall:
service: 4789
source: our proxy server
dest: our firewall
This happened on each http-request. Nothing changed with rebooting the proxy
server. When I restarted the firewall, all surfing went fine. No more drops
on this unknown port, just plain and simple http traffic coming from the
proxy server (and not destined for the firewall).
Can someone explain to me what happened, and how I can avoid this from
happening again?
NT firewall, Check Point FireWall-1 v.2000, VirusWall,...
Thanks in advance,
--------------------------------------------------------------------------
Kurt Haegeman, Network Security Engineer, CCSA
Dolmen Computer Applications
<www.dolmen.be>
winmail.dat