NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] NBT wincopy failures



You could be having an MSS (maximum segment size) issue.  While configuring
a LAN-to-LAN NetScreen VPN a couple of years back I ran into exactly this
problem.  Basically, I had to tell at least one of the firewalls to
negotiate the MSS size to take into account the additional bytes added to
each packet to handle IPSEC.

You may find the following URLs of interest, even though I have to leave it
to others to explain how this does/doesn't fit in terms of the FW1 product:

http://www.cisco.com/warp/public/105/38.shtml
http://www.sandelman.ottawa.on.ca/ipsec/1996/07/msg00094.html

Particularly from my read of the first document, I have a feeling that these
kinds of file copies are *always* and issue, and VPN overhead may well just
be the straw that breaks the camel's back.  I say this because I've noticed
that NBT file copying over the Internet, even unencrypted, has notably
slower throughput than every other data transfer I do.

-Russ

-----Original Message-----
From: Jonathan Higgins [mailto:[email protected]]
Sent: Tuesday, February 12, 2002 12:11 PM
To: [email protected]
Subject: [FW-1] NBT wincopy failures


Netbios over TCP .. yuck..

but, people at my institution seem to enjoy mounting their directorys at
home and copy files and such.

Since the install of my firewall(FW-1 on Nokia 650) I have received several
complaints about problems with NBT or SMB connections.  The complaints are
generally specific to "the file never finishes copying".. or "the paper just
keeps flipping from one folder to the other" .. and so on.. A thorough check
of my log files gives no specific indication of the problem, and SynDefender
was reporting some half-closed sessions.. but I turned it off thinking
SynDefender may be the culprit... but that didn't fix it either..

After combing through most of the support docs and phoneboy.. I have found
nothing.. Anyone have any ideas?

Jonathan Higgins
Network Service Specialist IV
[email protected]

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.