CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-12
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 582
Rep Power: 10
BarryStiefel has disabled reputation
Default Dropped Packets from the Internet

Dropped Packets from the Internet



When I ran "fw log -c drop", I got tons of dropped packets from Internet destined to the inside. Here's a sample of the log. 23:50:18 drop eagle.foo.com >hme1 proto tcp src 209.51.11.7 dst 198.216.82.250 service 43425 s_port http len 40 rule 11 23:50:19 drop eagle.foo.com >hme1 proto tcp src 203.137.129.4 dst 198.216.82.250 service 63752 s_port http len 40 rule 11 23:50:42 drop eagle.foo.com >hme1 proto tcp src 206.28.103.5 dst 138.241.79.238 service 4140 s_port http len 40 rule 11

My security policy is basically allow all outgoing, and drop all incoming, which is rule 11.

Answer If you look at these entries, you'll notice that they are "reverse" of what they should be (i.e. the source port is http). These entries will sometimes appear because some packets were received after the connection was closed. These are "normal" and should be of no concern.



Unchecking the checkbox "Log Established TCP Connections" in the rulebase properties and re-installing your security policy should prevent these errors from being logged.

In NG AI, go to Policy|Global Properties|Stateful Inspection in the out of state packets.

-- RobertGraham - 16 Mar 2004

FAQForm FAQs.Class: LoggingAndAlertingFAQs, TroubleshootingFAQs FAQs.OS: FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:22.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0