CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've just added two more speakers!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Services
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-11
mnutriaji mnutriaji is offline
Junior Member
 
Join Date: 2007-02-12
Posts: 12
mnutriaji has an average reputation (10+)
Default Disconnect after Policy Install

Hi All

I have 1 firewall and 1 smartcenter, distributed installation. using R55 HFA07 for the firewall and R65 for Smartcenter.

The strange thing happen when i push the policy into the firewall, internet (external) connection got disconnected for 3-5 minutes.

There were no dropped traffic in Smartviewtracker, interface was fine.

What i was thinking is somehow when policy got installed, firewall just cleared all the connection table and make the new one.
is it like that?

anyone ever experience this similar problem before?

Thank you in advance

regards

Nutriaji
Reply With Quote
  #2 (permalink)  
Old 2008-01-11
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 835
RayPesek has an average reputation (10+)
Default Re: Disconnect after Policy Install

Check in SmartView Dashboard:

Open the firewall object
Advanced
Connection Persistency

Rematch is usually the best choice. What operating system is the firewall using?

R55 HFA07 is ancient. The current HFA is 20 and there were a ton of fixes in between. You can apply HFA20 over HFA07 and it will add all of the patches. I believe R55 goes end of life in mid-2008 also.

HTH,

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-01-11
mnutriaji mnutriaji is offline
Junior Member
 
Join Date: 2007-02-12
Posts: 12
mnutriaji has an average reputation (10+)
Default Re: Disconnect after Policy Install

Hi Ray,

Thank you for your reply, yes i have put the setting as Rematch Connections previously. But the problem still there. i still have other frewall with HFA_02 never act like these.

thanks

Nutriaji
Reply With Quote
  #4 (permalink)  
Old 2008-01-12
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 835
RayPesek has an average reputation (10+)
Default Re: Disconnect after Policy Install

What operating system are you using? I've seen Nokia's occasionally lose automatic ARP during a policy push, so I added a manual proxy ARP and it was OK after that.

This could only be the cause if the browsing was NOT being done via the real IP of the firewall's external interface.

Ray
Reply With Quote
  #5 (permalink)  
Old 2008-01-13
mnutriaji mnutriaji is offline
Junior Member
 
Join Date: 2007-02-12
Posts: 12
mnutriaji has an average reputation (10+)
Default Re: Disconnect after Policy Install

Quote:
Originally Posted by RayPesek View Post

This could only be the cause if the browsing was NOT being done via the real IP of the firewall's external interface.

Ray
Your statement above, does it using NAT?

In my case, not only one or two connection getting diconnected, but it's like the external interface cannot go any further. loose connection about 3-5 mins.

I'm using Nokia IPSO < 4.0, 3.8 i guess. Do you know what really happen (the detail) when we push the policy into the firewall? All i know is:
- Saving the policy into Saved/Saved As Policy Packages
- Update the Policy Filter and the NAT
- That's it.

Does Checkpoint do like interfering the interface, make IPSO do something in O/S level?

Advise Please...

Thanks you in advance

Regards

Nutriaji
Reply With Quote
  #6 (permalink)  
Old 2008-01-13
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 835
RayPesek has an average reputation (10+)
Default Re: Disconnect after Policy Install

Installing the security policy does reset all of the automatic ARPs. Try this:

SSH to the firewall and continuously ping the next hop router, the one between the firewall external interface and your ISP.

Set up a security rule to allow this if needed. Also set up a security rule to allow you to ping the same router from your desktop.

Once both the firewall and your desktop are pinging the next-hop router continuously, push a policy and see if the pinging stops for awhile.

Normally the firewall external interface is caused by Hide NAT. If this is a proxy ARP issue the pinging should not stop.

Ray
Reply With Quote
  #7 (permalink)  
Old 2008-01-27
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 106
Routerkid1 has an average reputation (10+)
Default Re: Disconnect after Policy Install

and get your firewalls up to HFA_20
Reply With Quote
  #8 (permalink)  
Old 2008-01-28
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 328
MarioL has an average reputation (10+)
Default Re: Disconnect after Policy Install

From what you describe, this may be cause by NAT. Check your NAT rules... I usually prevent all NAT between firewalls and management, to prevent disconnects, etc.
Reply With Quote
  #9 (permalink)  
Old 2008-02-08
dwmaas dwmaas is offline
Junior Member
 
Join Date: 2006-05-16
Posts: 5
dwmaas has an average reputation (10+)
Default Re: Disconnect after Policy Install

Hi,
I am adding to this post since this is similar to a problem I am seeing with my secureplatorm R55 HFA-17 active/active cluster. We use automatic nats and have a manual NAT rule that does not nat between management and firewalls.

Upon completion of policy push, we loose connectivity to the next hop router. I ping the router from the firewall during the push, the ping stops upon completion of the push. I try to re-push with no change. I have to perform a reboot of both firewalls to re-establish connectivity again.

This just started a few days ago, and we have not seen this before.
Any ideas of what the issue maybe or what I can do?
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:56.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0