CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-04
pnetcr pnetcr is offline
Junior Member
 
Join Date: 2005-12-30
Posts: 14
Rep Power: 0
pnetcr has an average reputation (10+)
Default TCP Packet out of state

Have trawled through this forum and there's lots on the above but I still cant see a solution to my issue

NGX R60 / IP390 / NOKIA IPSO Clustering (Forwarding mode)

3rd party using FW1_clntauth_http (900) to Cluster object with SECURID. Cluster then passsing authentication request to internal ACE server which authenticates correctly. 3rd party is authorized to pass through firewall as appropriate client authentication rule dictates.

The problem appears to be totally randomly (all could be OK for 13 hours, 45mins, 3hours, etc) the individual firewall objects send back TCP out of state messages (First packet isnt SYN SYN-ACK & First packet isnt SYN RST-ACK) on source port 900 to the clients. This effectively de-authorizes them to use the appropriate rules they require. This affects all clients from the 3rd party at the same time and the problem seems to last a random period (25mins, 56mins, etc) before they can successfully authenticate and all is well again. What I cant understand is why the FW's does this as the 'Client Authentication Authorization Timeout' setting is set to 12 hours.

For reference there are loads of similar out of state messages on the logs for HTTP browsing. I understand the reasons for the messages (especially with clustering) but they are non problematic to the business, whereas the SECURID issue is!

I dont want to uncheck 'Drop out of state TCP packets' as this defeats the purpose of a FW.

I am not sure if this is just a 'feature' which I have to live with cause Im using clustering and some solutions like mine just aint cut out for it, however has anyone experienced something similiar before I have to start removing one of the FW's from the cluster, etc to get to the bottom of the issue.

Since migrating to NGX R60 / IP390 / NOKIA IPSO Clustering (Forwarding mode), all has been well for about the 20 services routing through the FW's apart from the above!!
Reply With Quote
  #2 (permalink)  
Old 2007-06-05
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 72
Rep Power: 3
gfont96 has an average reputation (10+)
Default Re: TCP Packet out of state

Hi pnetcr,

I don't know if this is of any use but you could take a look at the following Solution ID: #sk11088 and disable the out-of-state checking for that particular port.

Cheers,

George
Reply With Quote
  #3 (permalink)  
Old 2007-06-11
pnetcr pnetcr is offline
Junior Member
 
Join Date: 2005-12-30
Posts: 14
Rep Power: 0
pnetcr has an average reputation (10+)
Default Re: TCP Packet out of state

Worked a treat...Thanks
Reply With Quote
  #4 (permalink)  
Old 2007-08-06
tech123 tech123 is offline
Member
 
Join Date: 2007-08-05
Posts: 40
Rep Power: 0
tech123 has an average reputation (10+)
Default Re: TCP Packet out of state

Hi Pnetcr,

Does the solution hold good for provider-1 environment,Iam facing this problem(TCP out of state;first packet isn't SYNC) on my firewall which is not in cluster,IPSO 3.8.Could you please help on this.

Thank you
tech123
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:18.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0