Larry
The problem only appears when I use an "HTTP-with resource" type rule to block (e.g. mp3) stuff in addition to the general http rule. If I disable the http-wtih resource rule everything works but as per the previous email - I don't want to do that so I have chosen to diable http 1.1 in the browsers until I have tested other workarounds.
Tim Higgins
| "Larry Pingree" <[EMAIL PROTECTED]>
23/02/01 18:08
|
To: <[EMAIL PROTECTED]> cc: <[EMAIL PROTECTED]>, <[EMAIL PROTECTED]> Subject: Re: [FW1] asp pages slow |
Well, certainly if you are running proxied connections across Firewall-1's security servers then ASP may be effected, but the question posed by this person did not contain data about running Security servers.
The question would be is he? If so, then this needs to be looked at by check point, but if they only have an http accept rule, then check point should have no effect on HTTP traffic, correct?
-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-
Larry Pingree
Sr. Security Consultant
Email: [EMAIL PROTECTED]
SiegeWorks
Company WebSite: http://www.siegeworks.com/
Security Installation, Training and Consulting
-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-
----- Original Message -----
From: [EMAIL PROTECTED]
To: Larry Pingree
Cc: [EMAIL PROTECTED] ; [EMAIL PROTECTED]
Sent: Thursday, February 22, 2001 1:10 AM
Subject: Re: [FW1] asp pages slow
Larry
I thought so too but I saw a posting from Bradley Wendelboe giving details of known problems.
I tried:-
1. Turn off transparent/proxy rule - this worked but is not practical for us to leave this way - I just wanted to prove whether this made a difference.
2. Turn off HTTP 1.1 support in IE5 (Advanced settings) - worked. (We are going to leave this as the temporary fix).
Bradley also gave another fix which he couldn't get working on 4.1 but we may have some success (!?) on 4.0
Checkpoint are allegedly work on it ;-)
Cheers
Tim Higgins
| "Larry Pingree" <[EMAIL PROTECTED]> Sent by: [EMAIL PROTECTED] 21/02/01 22:38 | To: <[EMAIL PROTECTED]>, <[EMAIL PROTECTED]> cc: Subject: Re: [FW1] asp pages slow |
Check Point should have no effect on this as ASP is processed on your webserver and not on the Firewall.
-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-
Larry Pingree
Sr. Security Consultant
Email: [EMAIL PROTECTED]
SiegeWorks
Company WebSite: http://www.siegeworks.com/
Security Installation, Training and Consulting
-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-
----- Original Message -----
From: [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Tuesday, February 20, 2001 8:27 AM
Subject: [FW1] asp pages slow
Hi
We have had several reports over the past few months of asp pages on Web sites being extremely slow.
The first few reports we put down to problems at the sites themselves but we still see frequent problems at a range of sites.
Does anyone know of any FW-1 issues (or anything else) that may affect this ?
Our setup:-
Pentium II-500
512Mb RAM
NT 4.0 SP4
FW-1 4.0 SP4
IE5
TIA
Tim Higgins
#**********************************************************************
This message is intended solely for the use of the individual
or organisation to whom it is addressed. It may contain
privileged or confidential information. If you have received
this message in error, please notify the originator immediately.
If you are not the intended recipient, you should not use,
copy, alter, or disclose the contents of this message. All
information or opinions expressed in this message and/or
any attachments are those of the author and are not
necessarily those of Hughes Network Systems Limited,
including its European subsidiaries and affiliates. Hughes
Network Systems Limited, including its European
subsidiaries and affiliates accepts no responsibility for loss
or damage arising from its use, including damage from virus.
#**********************************************************************
#**********************************************************************
This message is intended solely for the use of the individual
or organisation to whom it is addressed. It may contain
privileged or confidential information. If you have received
this message in error, please notify the originator immediately.
If you are not the intended recipient, you should not use,
copy, alter, or disclose the contents of this message. All
information or opinions expressed in this message and/or
any attachments are those of the author and are not
necessarily those of Hughes Network Systems Limited,
including its European subsidiaries and affiliates. Hughes
Network Systems Limited, including its European
subsidiaries and affiliates accepts no responsibility for loss
or damage arising from its use, including damage from virus.
#**********************************************************************
#**********************************************************************
This message is intended solely for the use of the individual
or organisation to whom it is addressed. It may contain
privileged or confidential information. If you have received
this message in error, please notify the originator immediately.
If you are not the intended recipient, you should not use,
copy, alter, or disclose the contents of this message. All
information or opinions expressed in this message and/or
any attachments are those of the author and are not
necessarily those of Hughes Network Systems Limited,
including its European subsidiaries and affiliates. Hughes
Network Systems Limited, including its European
subsidiaries and affiliates accepts no responsibility for loss
or damage arising from its use, including damage from virus.
#**********************************************************************
