CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-05
renato_rj renato_rj is offline
Member
 
Join Date: 2006-05-02
Posts: 36
Rep Power: 0
renato_rj has an average reputation (10+)
Default Violated unidirectional connection with FTP

Hello, could someone explain me what this log is for ?
My firewall is NGX R 65 and I see this in my log events.

Number: 1061270
Date: 5Nov2007
Time: 15:22:11
Product: VPN-1 Power/UTM
Interface: eth4
Origin: xxxxxxxx
Type: Log
Action: Drop
Protocol: tcp
Service: ftp-data (20)
Source: xxxxxxxxxxxxxxxxxxx
Destination: xxxxxxxxxxxxxxxxxxx
Source Port: 40902
Information: message_info: Violated unidirectional connection
SmartDefense Profile: Monitor_Only
Policy Info: xxxxxxxxxxxxxxxxxxx
Created at: Tue Oct 30 19:19:46 2007
xxxxxxxxxxxxxxxxxxx

Thanks in advance.

Regards,

Renato_rj.
Reply With Quote
  #2 (permalink)  
Old 2007-11-06
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 724
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Violated unidirectional connection with FTP

Its a smart defense monitor log entry, there should be additional columns called "Attack" and "Attack Information" which should give you more detail [at least my R65 does].

As a fun side note, I did a search on your error and look what I found from Ray!

Quote:
Date: Mon, 29 Mar 2004 18:58:51 -0500 using NG AI R55 HFA02.

Fixed. In Policy/Global Properties/Stateful Inspection, we had to check
"Accept stateful UDP replies for unknown services."

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-11-07
renato_rj renato_rj is offline
Member
 
Join Date: 2006-05-02
Posts: 36
Rep Power: 0
renato_rj has an average reputation (10+)
Default Re: Violated unidirectional connection with FTP

Quote:
Originally Posted by melipla View Post
Its a smart defense monitor log entry, there should be additional columns called "Attack" and "Attack Information" which should give you more detail [at least my R65 does].

As a fun side note, I did a search on your error and look what I found from Ray!
Melipa, thanks for your help... But, FTP isnīt UDP packet, I donīt belive this solution is for me... The field "Attack" and "Attack information" return nothing...
My SmartDefense is disable, I donīt install SmartDefense in my gateway, but the problem continue...

Thanks for your help....

Regards,

Renato....
Reply With Quote
  #4 (permalink)  
Old 2007-11-07
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 724
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Violated unidirectional connection with FTP

Quote:
Originally Posted by renato_rj View Post
Melipa, thanks for your help... But, FTP isnīt UDP packet, I donīt belive this solution is for me...
Some of the traffic which Ray saw the error for was TCP based. Why changing that UDP option affected it, I cannot say. Do you have this option selected? If so then we already know its not a solution for you.

This snippet explains it better then I would, and gives you instructions to work around it, for NG at least:

Quote:
6.22: SmartView Tracker Log Error: Rule 0: Reason:
Violated Unidirectional Connection
FireWall-1 can mark a connection in the connections table to allow traffic to pass in one direction only. This can either be a connection that started from the inside, in which case FireWall-1 would mark the table to read that only outbound packets are allowed, or it can be a connection that originated from the outside, in which case FireWall-1 would mark the table to read that only inbound packets are allowed. This means that data can pass in only one direction (ACK packets as part of normal TCP are acceptable). When a packet violates a unidirectional connection, Check Point logs an entry into SmartView Tracker/ Log Viewer.

UDP services have an option to set a service to accept replies. In a sense, that is unidirectional. Unidirectional TCP connections occur with FTP. Some programs that use FTP do so in a nonstandard way that requires all the connections used by the FTP connection to be bidirectional. To allow for bidirectional FTP connections in FireWall-1 NG, perform the following steps.
You can read the rest at:
http://searchsecurity.techtarget.com...Point-Ch06.pdf
Reply With Quote
  #5 (permalink)  
Old 2007-11-09
renato_rj renato_rj is offline
Member
 
Join Date: 2006-05-02
Posts: 36
Rep Power: 0
renato_rj has an average reputation (10+)
Default Re: Violated unidirectional connection with FTP

Melipa, thanks again !!!

Iīll read this pdf and some result Iīll post here....


Regards,

Renato_rj.
Reply With Quote
  #6 (permalink)  
Old 2007-11-14
renato_rj renato_rj is offline
Member
 
Join Date: 2006-05-02
Posts: 36
Rep Power: 0
renato_rj has an average reputation (10+)
Default Re: Violated unidirectional connection with FTP

Melipla, it seems that decided the problem...

I create a protocol called ftp_basic and apply in the rule... Works fine !!

Regards,

Renato_rj.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 00:57.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0