CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-27
paprichaat paprichaat is offline
Junior Member
 
Join Date: 2006-10-18
Posts: 14
Rep Power: 0
paprichaat has an average reputation (10+)
Default https web page hangs with NGX and NAT

I am at my wits end.

Am using the follwowing setup:

tomcat web server--> Cisco CSS (SLBs) --> NGX R65 --> Internet

Static NAT on the CP gateway (Nokia) for HTTPs from any client to the SLB VIP. On the client browser you get a certificate challenge and then the connection is eventually reset by the server (as seen on TCPDUMP) with no further page updates (just blank page).

This works inside the firewall, just fine. Is it NAT causing the issue? or does the fw dislike a mismatched certificate ...nothing in the logs but green, no smartdefence or rule 0 issues. NAt working ok on both sides according to tcpdump.

Has anyone any suggestions?

Thanks.
Reply With Quote
  #2 (permalink)  
Old 2007-10-19
gavvys gavvys is offline
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 136
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: https web page hangs with NGX and NAT

Hi
Well the same problem of resetting the connection was faced by one of my friends.This issue is not with the NATting.
In that case there was also HTTPS communication and he was facing the issue with stateful inspection.

"Drop out of state TCP Packets" refers to instances where the Firewall doesn't recognize a proper three way hand shake of the TCP connection. When this function is on, the firewall expects to see the full TCP connection establishment process of SYN, SYN ACK, etc. While examining the TCP connection establishment, the firewall will check the first SYN packet for authorization against the Firewall-1 Rule Base.
If the firewall receives a SYN-ACK packet, it goes to the state table to look for the connection (the SYN should already be there), if the firewall fails the find the connection reference, the packet will be dropped with the "Drop out of state TCP Packets" message.
When this option is unchecked in Global properties menu (under "Stateful Inspection -> Out of state packets"), it simply allows TCP packets, that the firewall cannot find in the state table to be tested against the Rule Base as a secondary option.

Kindly check the issue.
Let me know if this resolves your issue or not.

Regards
Ranjit
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:48.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0