[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [FW-1] SAP Disconnect Problem
I have something very similar. I have 2 firewalls, one here in Canada and one in York, PA. If I use FWZ encryption between the networks everything works perfectly. If I put the encryption as IKE or if I turn off encryption altogether, I get massive lag. I tested this by just having a telnet session from one firewall to the other. I do an 'ls \bin' on the remote firewall and notice that with IKE or no encryption, there is a major delay every 50 or so lines. The delay is typically a second or so. If I turn FWZ on, the lag is gone completely. My problem was not primarily with SAP, but with NFS mounted machines. This lag completely messes up NFS. Although we did have issues with SAP users getting booted from time to time. (there were not that many remote SAP users). If you manage to find a solution to this problem, please let me know. I have posted this question many times and have yet to get an answer... Joe ====================================================================== Joseph Voisin, Systems and Network Administrator, Engel Canada Inc. www.engelmachinery.com | [email protected] |====================================================================== -----Original Message----- From: William Butler [mailto:[email protected]] Sent: Monday, October 15, 2001 1:00 PM To: [email protected] Subject: [FW-1] SAP Disconnect Problem We are having disconnect problems with SAP and checkpoint 4.1 SP3 firewalls. Our platform is Nokia IP 330's and 440's with a 4.1 Provider-1 box pushing the policies. After we upgraded from 4.0 to 4.1 sp3 our SAP system began to disconnect right in the middle of using it. This happens at random and does not happen to all users at once. We form site to site vpn's using IKE tunnels. There was a mention in the newsgroups of a simliar problem. The message below is a message from a user who posted something similiar, but I did not see any resolution. The note below mentions FWZ worked where IKE did not. Any help is greatly appreciated, ------------ * To: "'[email protected]'" <[email protected]> * Subject: [FW1] IKE and SAP * From: Greg Thiesen <[email protected]> * Date: Thu, 12 Jul 2001 09:22:34 -0700 * Sender: [email protected] Title: Message I'm currently using FWZ and have added IKE for encryption. My Firewall is 4.1 SP1. When we connect to SAP GUI using IKE we are getting timeouts. When I use FWZ to connect to SAP it works just fine. SAP uses port 3200. Has anyone seen this behavior before?? Regards, William Butler =============================================== To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html =============================================== =============================================== To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ===============================================
|