NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] Smtp dropped on rule 0



Title: Message
Alexey,
That error is generally (at least I have never seen it to be) an issue with the firewall.  The explanation on phoneboy.com is excellent, and you can get a better understanding of the state table from Lance Spitzer at http://www.enteract.com/~lspitz/fwtable.html.  I would venture a guess that some of the connections you had were not properly closed when you rebooted and perhaps they are still trying to continue communication, though there is no entry in the state table for them. 
 
Check what's happening with the 3way handshake.  I think the time out is 180seconds.  This will also occur with async routing (something that's bad anyway).
 
HTH,
Alex
 
-----Original Message-----
From: Alexey Vitashkevich [mailto:[email protected]]
Sent: Thursday, May 23, 2002 9:50 AM
To: [email protected]
Subject: [FW-1] Smtp dropped on rule 0

Hi. I updated 8 firewalls on NOKIAs IP 330 to IPSO 3.5.1 and CP 4.1 SP5a.

Since then on two of those firewalls I have very strange problem with SMTP packets dropped on RULE 0 with error:

Unknown established TCP packet.

The phoneboy solution didn't help and I really don't know what to do next.

Any ideas ?

 

Alexey Vitashkevich

Senior Security Consultant - MCSE, CCSE, CNE

Phone :ext. 107

Fax     :  

Mobile : (917) 476-8313

www.nextgeninter.net

 



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.