CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-08-11
Member
 
Join Date: 2005-08-24
Posts: 74
Rep Power: 4
gfont96 has an average reputation (10+)
Default TCP packet out of state

Hello All,

We have a sun java application server version 8.1 using a JDBC connection to and oracle daabase. The application server is in one DMZ the database in an other.

I keep seeing in the logs the following error ' TCP connection out of state, First Packet isn't a SYN : TCP Flags' then it gives me random tcp flags, sometimes ACK, sometimes PUSH, ACK etc

This keeps breaking the application and we have to restart the application server.

I have unchecked 'drop out of state tcp packets' and we'll see what happens.

What sort of issue is it having it unchecked (performance ? / Security ?)

Can anyone tell me what might be happening with the communication and how I might troubleshoot it ?

Manager is NGXR60 HFA03 Windows 2K, modules are NGXR60 HFA03 running on SPLAT in HA mode (active, passive)

Cheers all, have a good weekend

George
Reply With Quote
  #2 (permalink)  
Old 2006-08-11
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 857
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: TCP packet out of state

Most likely the problem is related to the database opening connections, then not using them for over an hour (the default TCP service timeout). You can increase the timeout for certain services - check the advanced button on the service definition. You could try putting it up to 2 hours.

Another thing to try is changing the tcp_keepalive_interval on the hosts, using ndd. (This assumes HP-UX or Solaris, there will be some similar way of changing it on other OSes). Default keepalive_interval is 2 hours, but Check Point's default timeout is 1 hour. If an OS has a session with no traffic up for two hours, it sends a tcp keepalive packet. If it gets no response, it closes the session. If you set the keep alive interval to under an hour, then Check Point should register the session as still open, and reset the timer.

Thirdly, I have heard of some issues with the sqlnet service defined in Check Point. You might want to do some research into that, I think there are some things you can do with that. Have a look in SecureKnowledge.
Reply With Quote
  #3 (permalink)  
Old 2006-08-13
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 857
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: TCP packet out of state

Oh, and I meant to add, that allowing out of state TCP packets is a massive security risk. If you're going to do that, why bother with using Check Point at all? Just install a Cisco router with basic access lists, and save yourself the license fee.

Think carefully through the implications of allowing out of state traffic - you've now disabled Check Point's vaunted "Stateful Inspection" What would happen if I was to send 25,000 acks through your firewall? It would allow them, and add them to your connection tables, filling it up.

I could also use it for port scanning pretty trivially.
Reply With Quote
  #4 (permalink)  
Old 2006-08-14
Member
 
Join Date: 2005-08-24
Posts: 74
Rep Power: 4
gfont96 has an average reputation (10+)
Default Re: TCP packet out of state

Thanks Northlandboy,

I have since looked on the Sun website and found a document for the 'developers' showing them how to configure their boxes to allow them to function correctly via a firewall !.

Cheers,

George
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 14:25.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0