CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Nortel ASF/NSF
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-06-04
Junior Member
 
Join Date: 2008-04-28
Posts: 2
Rep Power: 0
timor5000 has an average reputation (10+)
Default These NSFs are bizarre

I would love to know how these things work. Trying to get Nortel to tell me or find doco on the inner workings of these switches is nigh on impossible

Troubleshooting a connection through these things is tough. Is tcpdump totally broken on these things?

For example if i run tcpdump -n -i <internal interface> host <my IP> and do the same on the external interface i'll see the SYN on the internal and nothing else. Alot of the time I just see nothing at all.

For my packet arriving on the internal interface I will not see the SYN ACK on any interface. Can anyone explain exactly how these accelerators handle connections? It's driving me crazy. btw this is being tested on a non production firewall so there's absolutely no load on it. buffer space should not come into play

tcpdump is tcpdump. it's linux. I would expect it to behave properly

anyone have any clues on how to get this to operate as expected? is it because of the switch architecture it behaves this way?

bizarre...
Reply With Quote
  #2 (permalink)  
Old 2008-06-05
Junior Member
 
Join Date: 2008-05-26
Location: Osnabrück
Posts: 16
Rep Power: 0
Carsten has an average reputation (10+)
Default Re: These NSFs are bizarre

I have almost no experience with tcpdump on a firewall, I prefer fw monitor, you should give it a try as well, because it is meant especially for firewall packet filtering and it is superior to tcpdump for this purpose.

http://www.cpug.org/check_point_reso...or_rev1_01.pdf
Reply With Quote
  #3 (permalink)  
Old 2008-06-05
Junior Member
 
Join Date: 2008-04-28
Posts: 2
Rep Power: 0
timor5000 has an average reputation (10+)
Default Re: These NSFs are bizarre

Quote:
Originally Posted by Carsten View Post
I have almost no experience with tcpdump on a firewall, I prefer fw monitor, you should give it a try as well, because it is meant especially for firewall packet filtering and it is superior to tcpdump for this purpose.

http://www.cpug.org/check_point_reso...or_rev1_01.pdf
I use fw mon and it's a great tool for understanding how packets traverse the firewall and troubleshooting. The trouble is i like to have the all the info on one line so i can apply filters to it like grep and awk

fw monitor splits this line into 2 so you see src dst IP on the first line and ports on the second. fine i guess for dumping the output into a reader like wireshark but its crap for Real time troubleshooting

havent figured out how to get it into one line if it can even be done?

will have to play with INSPECT
Reply With Quote
  #4 (permalink)  
Old 2008-06-23
Junior Member
 
Join Date: 2007-04-08
Posts: 8
Rep Power: 0
Sidney has an average reputation (10+)
Default Re: These NSFs are bizarre

Quote:
Originally Posted by timor5000 View Post
I would love to know how these things work. Trying to get Nortel to tell me or find doco on the inner workings of these switches is nigh on impossible

Troubleshooting a connection through these things is tough. Is tcpdump totally broken on these things?

For example if i run tcpdump -n -i <internal interface> host <my IP> and do the same on the external interface i'll see the SYN on the internal and nothing else. Alot of the time I just see nothing at all.

For my packet arriving on the internal interface I will not see the SYN ACK on any interface. Can anyone explain exactly how these accelerators handle connections? It's driving me crazy. btw this is being tested on a non production firewall so there's absolutely no load on it. buffer space should not come into play

tcpdump is tcpdump. it's linux. I would expect it to behave properly

anyone have any clues on how to get this to operate as expected? is it because of the switch architecture it behaves this way?

bizarre...
Hi,

Well the reason why I think tcpdump don't and actually can't work is that the accelerator part (the switch) is not running linux contrary to the director piece, it's based on asics. On the other hand fw monitor is "glued" to the Checkpoint kernel so it gathers its information from the director (bear in mind fw monitor limitations with SXL, the hardware based acceleration from the switch on ASF/NSF or ADP on Nokia and Xbeam X series).

My 2cents.

Sidney
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 16:03.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0