CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-21
nothing nothing is offline
Junior Member
 
Join Date: 2007-02-16
Posts: 3
Rep Power: 0
nothing has an average reputation (10+)
Default Now and then our clients can't access our websites

Hello,

We have CP R55 on our company, and we host numerous websites to our clients.
Now and then we receive a call from our clients because suddenly they can't access our websites. From the inside we don't have any problems using internet (http, messenger, anything).
For some reason the firewall stops accepting traffic from outside to our websites.

We already checked the logs and there aren't any dropped packets.

We only solve this by rebooting the Firewall which isn't a solution that we like too much because the clients need to access those sites.

Has anyone had this problem?
Since i'm not too acquainted with Checkpoint is there any troubleshooting you recommend the next time this happens (and it will)?

Thanks in advance,
Nuno Santos
Reply With Quote
  #2 (permalink)  
Old 2008-02-21
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 895
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Now and then our clients can't access our websites

What operating system is the firewall running on? Are the web sites on different IP addresses than the firewall external interface? If so, it sounds like you're losing ARP. Will a policy push make it work again?

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-02-22
nothing nothing is offline
Junior Member
 
Join Date: 2007-02-16
Posts: 3
Rep Power: 0
nothing has an average reputation (10+)
Default Re: Now and then our clients can't access our websites

The Checkpoint is Checkpoint SecurePlatform NG with Application Intelligence (R55) Build 110

The websites are on different machines on our DMZ with different IP Addresses from the CP interface (NAT used).

I think we've tried the policy push without success. The only thing that works is to reboot the firewall (i didn't know about the cpstop;cpstart -> i will try the next time the problem happens since it probably is faster than rebooting).

(Basically we have our internet connection connected to one nic of the checkpoint and have two more nic's on the CP, one for the intranet and other for the DMZ which then are connected to switches)

ISP ------> NIC1
NIC2------>Switch (intranet)----> machines
NIC3------>Switch (DMZ)-------> machines for web acces
Reply With Quote
  #4 (permalink)  
Old 2008-02-22
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 895
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Now and then our clients can't access our websites

When the failure occurs, does SmartView Tracker show the connection attempts at all or are there zero log entries? If not, it's quite probably an ARP issue. It could be that the router on the outside of the firewall is the problem and that rebooting the firewall causes the router to reset something.

I don't know what build 10 is. What HFA does the command

cpshared_ver <Enter>

Are these set up with manual NAT rules or automatic NAT rules?

show?
Reply With Quote
  #5 (permalink)  
Old 2008-02-25
nothing nothing is offline
Junior Member
 
Join Date: 2007-02-16
Posts: 3
Rep Power: 0
nothing has an average reputation (10+)
Default Re: Now and then our clients can't access our websites

Hello and thanks for the replies.

The HFA is HFA_04 Hotfix 093.

The NAT entries are manual.

(The router we have is a Cisco. The next time the problem occur i will check it to see if is there any problem)
Reply With Quote
  #6 (permalink)  
Old 2008-02-25
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 895
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Now and then our clients can't access our websites

HFA04 is ancient. You really need to get to the current HFA, 20.

Do you have proxy ARPs set up in local.arp for each of those IP addresses?

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:58.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0