CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've already had our first sign-ups!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Interoperability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-08
imslickrick2k imslickrick2k is offline
Junior Member
 
Join Date: 2007-06-19
Posts: 13
imslickrick2k has an average reputation (10+)
Default Server side packet of an old UDP connection -> Dropped Packets

Hi everyone,

We've recently encountered an issue of OUT-OF-STATE UDP Packets on a number of our firewalls. Initially we didn't see anything in the logs, but after unchecking 'Drop OOS UDP Packets" and enabling LOG for that option in the global options, we can still see packets being dropped. We have tried increasing/decreasing the UDP Virtual Timeout settings with no affect.

We were also advised by our vendor to change the fw_one_reply_from_any_port(false) to true in GUIDBEDIT, this made no affect either. I would really appreciate if anyone can help with this, we've been working on it for days.


Origin: FW-1
Type: Log
Action: Drop
Protocol: udp
Service: 28005
Source: xxxxxx
Destination: xxxxxx
Source Port: UDP_12080 (12080)
Information: message_info: Server side packet of an old UDP connection

The packets are from our BIGIP load balancer to our AAA boxes. Out of a range of 28000-28007, ports 28003 and 28005 are being dropped because of this. The rule in dashboard is source / dest / service ANY

Any help is appreciated.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 05:46.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0