CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-15
Junior Member
 
Join Date: 2006-03-29
Posts: 6
Rep Power: 0
Dazar has an average reputation (10+)
Default Browsing delay and jamming

Hello, (...i hope i'm in the right forum)
I've NGX R61 that working in load sharing, unicast mode.
i getting a lot of complains about surfing an the net. i search the logs and find this:

Type: Log
Action: Drop
Protocol: tcp
Service: 59382
Source: 209.191.106.109
Destination: *.*.*.*
Source Port: http (80)

----------------

this is just one of many logs that shows blocking a legitimate web site (in this example it's block YAHOO).
anyone have a idea, why i have thousands of requests from web site back to my FW in source port http ?

there is no problem that i can see on the policy, and the anti spoofing is ok.

Thanks,
David
Reply With Quote
  #2 (permalink)  
Old 2007-05-15
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Browsing delay and jamming

Quote:
Originally Posted by Dazar View Post
this is just one of many logs that shows blocking a legitimate web site (in this example it's block YAHOO).
anyone have a idea, why i have thousands of requests from web site back to my FW in source port http ?
Sounds like a stateful problem--going to a webpage can create hundreds of connections because of the different types of data. There may be something wrong with your routing. IE The firewall sends it out one port but the connection comes back in another.
Reply With Quote
  #3 (permalink)  
Old 2007-05-16
Junior Member
 
Join Date: 2006-03-29
Posts: 6
Rep Power: 0
Dazar has an average reputation (10+)
Default Re: Browsing delay and jamming

the routing table in all of the machines and routers are fine,
there is no dynamic routing protocol, only static.
btw, the information field in the tracker logs, is empty.

Thanks,
David
Reply With Quote
  #4 (permalink)  
Old 2007-05-16
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Browsing delay and jamming

Just as a test you might consider removing the "Drop out of state TCP packets". Check if web access works well after that, if it does, that means you are somehow getting problems with keeping connection state, which would indicate possible routing problems, as stated before. If it doesn't then at least you know what it isn't ;)
Reply With Quote
  #5 (permalink)  
Old 2007-05-20
Junior Member
 
Join Date: 2006-03-29
Posts: 6
Rep Power: 0
Dazar has an average reputation (10+)
Default Re: Browsing delay and jamming

Thanks, but the "Out of state" check box is unmarked.

David
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 21:23.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0