NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] SAP Disconnect Problem



I have something very similar.  I have 2 firewalls, one here in Canada and
one in York, PA.  If I use FWZ encryption between the networks everything
works perfectly.  If I put the encryption as IKE or if I turn off encryption
altogether, I get massive lag.

I tested this by just having a telnet session from one firewall to the
other.  I do an 'ls \bin' on the remote firewall and notice that with IKE or
no encryption, there is a major delay every 50 or so lines.  The delay is
typically a second or so.  If I turn FWZ on, the lag is gone completely.

My problem was not primarily with SAP, but with NFS mounted machines.  This
lag completely messes up NFS.  Although we did have issues with SAP users
getting booted from time to time. (there were not that many remote SAP
users).

If you manage to find a solution to this problem, please let me know.  I
have posted this question many times and have yet to get an answer...

Joe

======================================================================
Joseph Voisin, Systems and Network Administrator, Engel Canada Inc.
www.engelmachinery.com | [email protected] |======================================================================


-----Original Message-----
From: William Butler [mailto:[email protected]]
Sent: Monday, October 15, 2001 1:00 PM
To: [email protected]
Subject: [FW-1] SAP Disconnect Problem

We are having disconnect problems with SAP and checkpoint 4.1 SP3 firewalls.
Our platform is Nokia IP 330's and 440's with a 4.1 Provider-1 box pushing
the policies. After we upgraded from 4.0 to 4.1 sp3 our SAP system began to
disconnect right in the middle of using it. This happens at random and does
not happen to all users at once. We form site to site vpn's using IKE
tunnels. There was a mention in the newsgroups of a simliar problem. The
message below is a message from a user who posted something similiar, but I
did not see any resolution. The note below mentions FWZ worked where IKE did
not.
Any help is greatly appreciated,
------------
*       To: "'[email protected]'"
<[email protected]>
*       Subject: [FW1] IKE and SAP
*       From: Greg Thiesen <[email protected]>
*       Date: Thu, 12 Jul 2001 09:22:34 -0700
*       Sender: [email protected]

Title: Message
I'm currently using FWZ and have added IKE for encryption. My Firewall is
4.1 SP1. When we connect to SAP GUI using IKE we are getting timeouts. When
I use FWZ to connect to SAP it works just fine. SAP uses port 3200. Has
anyone seen this behavior before??

Regards,

William Butler

===============================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
===============================================

===============================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
===============================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.