CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-13
Junior Member
 
Join Date: 2008-05-12
Posts: 3
Rep Power: 0
jjprieto has an average reputation (10+)
Default connection dropped due stateful inspection

Hi all,

We have a diskless SPLAT distro with root mounted over NFS. If I activate Stateful inspection via TCP, then the NFS connection is dropped and system hangs because it is 'out of state'. How could I activate stateful inspection with this exception? Is it possible to view states (in netfilter is /proc/net/ip_conntrack?

thanx
Reply With Quote
  #2 (permalink)  
Old 2008-05-13
Senior Member
 
Join Date: 2005-10-12
Posts: 322
Rep Power: 4
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: connection dropped due stateful inspection

hi mate i am not very clear with ur question though. but as far i could guess is that u want stateful inspection to be enabled but not for NFS service right .

since cp is a stateful firewall by default and it will allow packets only on the base of stateful inspection there is no way u can disable stateful inspection for a service.

i guess no firewall allows to disable stateful inspection.

regards

sebastan
Reply With Quote
  #3 (permalink)  
Old 2008-05-14
Junior Member
 
Join Date: 2008-05-12
Posts: 3
Rep Power: 0
jjprieto has an average reputation (10+)
Default Re: connection dropped due stateful inspection

hi, thanks for your post. In Linux you can play with iptables, applying state rules when you want.

The problem with my SPLAT is that it is a diskless system booting from PXE and mounting root via NFS, hence first it makes a NFS connection and later it inserts fwmod module, so NFS connection results in an 'out of state'. I have seen that it is possible to include exceptions (but only gateways from a cluster, not a host like the NFS server).

Is there another way to bypass the problem? Maybe inserting fwmod at bootstraping process, before mounting root via NFS?

Regards
Reply With Quote
  #4 (permalink)  
Old 2008-05-16
Senior Member
 
Join Date: 2005-10-12
Posts: 322
Rep Power: 4
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: connection dropped due stateful inspection

hi i guess there is no way u have the fwd on bootstrapping process. i guess if u are do it learning purpose then might as well install a hard disk and get the splat working smoothly it will save a lot of time and effort.

regards

sebastan
Reply With Quote
  #5 (permalink)  
Old 2008-05-18
Junior Member
 
Join Date: 2008-05-12
Posts: 3
Rep Power: 0
jjprieto has an average reputation (10+)
Default Re: connection dropped due stateful inspection

Hi sebastian

Thanks a lot for your reply. I have discover that the problem fix using UDP instead of TCP.

Using TCP works too, but the boot process seems to hang up at /etc/init.d/cpboot service, applying basic policies. But the system continue boot process after 6 or 7 minutes, maybe because the NFS restore the TCP connection and then it become a 'legal' connection. I will investigate NFS tunning to get down thi time.

Thanks.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:19.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0