CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Interoperability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-15
imslickrick2k imslickrick2k is offline
Junior Member
 
Join Date: 2007-06-19
Posts: 19
Rep Power: 0
imslickrick2k has an average reputation (10+)
Default NGX R61 is changing DF bit on packets from 1 to 0 - HELp

Hello,

Our firewall is changing the DF bit from 1 to 0 and this is causing issues with a few of our applications. There are threads that refer to Keep_DF_Flag being changed in dbedit but i've been informed this does not work in clustered environments (which we are running)

does anyone have any ideas that can help?

We're on R61 NGX
Reply With Quote
  #2 (permalink)  
Old 2007-10-17
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 836
Rep Power: 3
melipla has an average reputation (10+)
Default Re: NGX R61 is changing DF bit on packets from 1 to 0 - HELp

Out of curiosity, which applications are being affected? I haven't seen any threads about Keep_DF_Flag so I'm curious as to what you're seeing.
Reply With Quote
  #3 (permalink)  
Old 2007-10-17
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 745
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: NGX R61 is changing DF bit on packets from 1 to 0 - HELp

I ran into this issue six months ago in my previous employment.
Basically Checkpoint has a solution for this in checkpoint sk17280.
However, this article does not address if you have cluster
environment.

I opened a TAC case with Checkpoint and after three months
of going back and forth, the solution is to manually modified
the $FWDIR/conf/objects_5_0.C file as follows:

0) cd /tmp
1 ) mdsenv customer_CMA (if you have a P-1 environment),
cd $FWDIR/conf if you have SmartCenter environment

2) mdsstop_customer customer_CMA
cpstop (if you have SmartCenter)

3) cd $FWDIR/conf

4) cp objects_5_0.C objects_5_0.C.orginal
5) cp object_5_0.C.backup object_5_0.C.backup.original
6) vi objects_5_0.C file and add "keep_DF_flag" and set it to "true"
to the cluster object name, above the property "log_consolidtor (false)"
For example, if your gateway cluster name is "gw-cluster" then
place the following line:
gw_cluster=(true)
7) save the file,
8) cd /tmp
9) perform "mdsstart_customer customer_CMA
cpstop;cpstart if you have SmartCenter,
10) push the policy,

I did this 3 months ago and it seemed to fix the problem.

Let me know if it works for you.

BTW, dbedit is another way of using vi to modify the objects_5_0.C file.
Reply With Quote
  #4 (permalink)  
Old 2007-10-19
imslickrick2k imslickrick2k is offline
Junior Member
 
Join Date: 2007-06-19
Posts: 19
Rep Power: 0
imslickrick2k has an average reputation (10+)
Default Re: NGX R61 is changing DF bit on packets from 1 to 0 - HELp

Quote:
Originally Posted by cciesec2006 View Post
vi objects_5_0.C file and add "keep_DF_flag" and set it to "true"
to the cluster object name, above the property "log_consolidtor (false)"
For example, if your gateway cluster name is "gw-cluster" then
place the following line:
gw_cluster=(true)

I did this 3 months ago and it seemed to fix the problem.

Let me know if it works for you.

BTW, dbedit is another way of using vi to modify the objects_5_0.C file.
Hi and thanks for your reply, we were actually considering adding this line in there until our TAC told us it wouldn't work. i then came across your reply so we're thinking of giving this a shot. I'm a little confused however in your example you put gw_cluster=(true) did you mean under the gw_cluster add Keep_DF_Flag=(true)??

thanks for your help
Reply With Quote
  #5 (permalink)  
Old 2007-10-19
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 745
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: NGX R61 is changing DF bit on packets from 1 to 0 - HELp

Yes, that's exactly what I mean. Under the gw_cluster add
Keep_DF_Flag=(true)
Reply With Quote
  #6 (permalink)  
Old 2007-10-23
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 836
Rep Power: 3
melipla has an average reputation (10+)
Default Re: NGX R61 is changing DF bit on packets from 1 to 0 - HELp

Have you seen any improvement in performance after changing this setting?
Reply With Quote
  #7 (permalink)  
Old 2007-11-02
imslickrick2k imslickrick2k is offline
Junior Member
 
Join Date: 2007-06-19
Posts: 19
Rep Power: 0
imslickrick2k has an average reputation (10+)
Default Re: NGX R61 is changing DF bit on packets from 1 to 0 - HELp

changed the param in both the objects_5_0.C and objects_5_0.C.backup, verified it was there after cpstop/cpstart and a policy push

Only thing is, when i goto GUIDBEDIT i still don't see it anywhere using the search feature. I haven't actually tested it to see whether its working, but just a little curious - should i not see it in there if i've added it to the objects_5_0.c files?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:26.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0