CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Content Security/Security Servers/CVP/UFP
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2009-09-21
Senior Member
 
Join Date: 2007-07-27
Posts: 124
Rep Power: 4
desperado618 has an average reputation (10+)
Default Websense not working after upgrade to R65

I recently upgraded from IPSO 4.1/R60 to IPSO 4.2b096/R65..After doing so, the firewall is no longer sending traffic to the Websense.
Tracker does not show traffic hitting that rule (it is set to log) yet a tcpdump shows Resets.

I have created a new rule and new UFP object. neither worked.
Reply With Quote
  #2 (permalink)  
Old 2009-09-21
Member
 
Join Date: 2008-04-07
Location: Munich, Germany
Posts: 42
Rep Power: 0
tomama has an average reputation (10+)
Default Re: Websense not working after upgrade to R65

Have you checked that there maybe is a rule which is above the one you need above your rule which does not log and the traffic hits this rule as well?

Have you checked using fw monitor to see this traffic passing the firewall?
Reply With Quote
  #3 (permalink)  
Old 2009-09-21
Senior Member
 
Join Date: 2007-07-27
Posts: 124
Rep Power: 4
desperado618 has an average reputation (10+)
Default Re: Websense not working after upgrade to R65

when I add a rule right above the websense rule that bypasses it, it works fine.

Fw monitor shows that the traffic does not even reach the inspection engine. It reaches the ingress interface and thats it.
Basically I just get eth2c0i (I do not even get ethc2coI, which would indicate that it leaves the ingress).
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:36.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1