CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-13
mayur mayur is offline
Junior Member
 
Join Date: 2006-04-13
Posts: 1
Rep Power: 0
mayur has an average reputation (10+)
Default th_flags: 2 message_info: SYN packet for established connection

Hi,

I'm having a problem on a Nokia IP330 running NG FP2. Basically I have a webservers behind the firewall, which are being connected to via a proxy server on the other side of the internet.

About 10 times a day I get dropped packets in the logs (HTTP) with the message 'th_flags 2 message_info SYN packet for established connection'

The proxy is Microsoft proxy server, and isn't caching this particular website, and has pretty much default options set for everything (I think it defaults to 15 minutes for http sessions)

The firewall also has the default timeout options set (10 minutes for http)

Can anyone shed any light as to why these packets are being dropped?

will decreacing the http timeout on the firewall help?

Thanks in advance
Reply With Quote
  #2 (permalink)  
Old 2006-08-02
nooon nooon is offline
Junior Member
 
Join Date: 2005-11-29
Posts: 19
Rep Power: 0
nooon has an average reputation (10+)
Default Re: th_flags: 2 message_info: SYN packet for established connection

Up please !

We have the same issue (R55)

- we enabled sequence number checking onto smart defense as proposed by ckpt KB
- we reduced the tcp-end timer from 50 to 10 sec

still getting these SYN packet for established connection !@#$
Reply With Quote
  #3 (permalink)  
Old 2006-08-02
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: th_flags: 2 message_info: SYN packet for established connection

Have you guys searched CHKP's SecureKnowledge database? There should be a technote that explains this is coming from SmartDefense and that you have to use dbedit to change the definition.

If memory serves, what's happening is MS Proxy is behaving in a way that doesn't jive with the connections table held for three way handshakes on the firewall. You can either do a packet capture and try to file a bug report with MS or you can use the SK article to disable the SmartDefense check. My preference is both. Disable SmartDefense and replace with a real IDS solution AND use proxy products(like BlueCoat) that don't mess up transmissions like MS does.

That's my two cents on this.
Reply With Quote
  #4 (permalink)  
Old 2006-08-03
nooon nooon is offline
Junior Member
 
Join Date: 2005-11-29
Posts: 19
Rep Power: 0
nooon has an average reputation (10+)
Default Re: th_flags: 2 message_info: SYN packet for established connection

smartfdefense disabled, no ids, no ms proxy, and tcp-end timer decreased to 10s and still no luck !@#
Reply With Quote
  #5 (permalink)  
Old 2007-03-01
dr-spoof dr-spoof is offline
Junior Member
 
Join Date: 2006-03-10
Location: Detroit Michigan USA
Posts: 15
Rep Power: 0
dr-spoof has an average reputation (10+)
Default Re: th_flags: 2 message_info: SYN packet for established connection

Your lucky with only 10, I see 1000's aday all revolvoing around NCP. No help from Check Point yet.


Quote:
Originally Posted by mayur View Post
Hi,

I'm having a problem on a Nokia IP330 running NG FP2. Basically I have a webservers behind the firewall, which are being connected to via a proxy server on the other side of the internet.

About 10 times a day I get dropped packets in the logs (HTTP) with the message 'th_flags 2 message_info SYN packet for established connection'

The proxy is Microsoft proxy server, and isn't caching this particular website, and has pretty much default options set for everything (I think it defaults to 15 minutes for http sessions)

The firewall also has the default timeout options set (10 minutes for http)

Can anyone shed any light as to why these packets are being dropped?

will decreacing the http timeout on the firewall help?

Thanks in advance
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:02.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0