CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-08
Junior Member
 
Join Date: 2007-01-17
Location: Chennai
Posts: 8
Rep Power: 0
prasanthkdas@aim.com has an average reputation (10+)
Send a message via AIM to prasanthkdas@aim.com
Default Drop out of state TCP packets

Hello Team,

When we uncheck the option " Drop out of state TCP packets " in the global properties in smartdashboard, would it have any negative security impacts.

Best Regards,
Prasanth K Das
Reply With Quote
  #2 (permalink)  
Old 2007-06-10
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Drop out of state TCP packets

Yes the firewall stops being stateful and just a bunch of access lists
Reply With Quote
  #3 (permalink)  
Old 2007-06-10
Junior Member
 
Join Date: 2007-06-09
Posts: 1
Rep Power: 0
sowderjc has an average reputation (10+)
Default Re: Drop out of state TCP packets

I guess a good question would be what are you looking to gain by turning off the firewall's ability to detect packets that are out of sequence and don't follow the proper TCP negotiation tactics? Is this causing problems? Chilljim is right - if you turn this functionality off you take away the firewalls ability to perform much "smart" analysis of the packets and are just running the traffic through the rules you have created.

I ran into an issue where there was a lot of bad programs running on our corporate network (didn't follow any standards for using network communication) and would get these kinds of messages from the firewall. The users would restart their applications and everything would work fine.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:11.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0