[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [FW-1] Syn for established connection
Title: RE: [FW-1] Syn for established connection Checkpoint is working on a hotfix that will sit on top of NG FP2 to solve this problem and behave like 4.1. They are testing now. I, too, encountered this problem several months back ago and opened a trouble ticket with Checkpoint to figure out what was going on. David Grabowski had the same problem and I told him what Checkpoint said about our application and the problem seemed similiar. Turns out they were the exact same problem as yours is as well. Our application was also hardcoded with a specific source port and had back-to-back connections that would get dropped. Our application worked fine with 4.1, but bombed on NG due to their "security enhancements" as they call it. They are working on a fix but I would encourage everyone who has this problem to make sure they open up a trouble ticket so that Checkpoint knows all the folks who are encountering this problem. -----Original Message-----
Hi everyone ! Just want to know does anyone encounter a "SYN packet for established connection" error in NG fp2? actually i read an article by David Grabowski- about what he learned in FW-1 state table..that an established TCP session will by default have a lifetime of 3600 sec. and every packet traverse will reset the timer..After the session will closed (via FIN or RSt packet) it enters a "half-closed" state..the lifetime is 50 sec. the problem is the Device im using uses a statically coded source port for its communication and there is no way we can reconfigure this. if a new syn connection is attemted and matches the established connection it is dropped by the FW-1. In version FW-1 4.1 this syn packet will be match against the rulebase..does anyone knows how to revert the behavior of NG to 4.1 on how it handles a syn connection or a workaround. _____________________________________________________________
_____________________________________________________________
=================================================
|