CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-01
matthewjones@comcast.net matthewjones@comcast.net is offline
Junior Member
 
Join Date: 2006-05-01
Location: New Jersey
Posts: 2
Rep Power: 0
matthewjones@comcast.net has an average reputation (10+)
Default Installing Policy-Does it drop existing connections?

If I push a new policy to my Nokia IP380 - Do all active connections get dropped? My boss seems to think they do - I do not believe they do.
I can't seem to find a simple answer on this.

Thanks in advance for the assist.

MAJ
Reply With Quote
  #2 (permalink)  
Old 2006-05-01
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Installing Policy-Does it drop existing connections?

In most cases by default the connections should not drop unless a new rule says to drop that connection.
Reply With Quote
  #3 (permalink)  
Old 2006-05-10
phlegm phlegm is offline
Junior Member
 
Join Date: 2005-11-18
Posts: 18
Rep Power: 0
phlegm has an average reputation (10+)
Default Re: Installing Policy-Does it drop existing connections?

Why not try a test. Dial up and get a VPN in from the outside and start up an FTP or something from the inside. Push out a policy and see if they stay connected. I know at our site they maintain their connections even if we fail over to the backup firewall.
Reply With Quote
  #4 (permalink)  
Old 2006-05-10
andrew andrew is offline
Member
 
Join Date: 2006-03-25
Posts: 41
Rep Power: 0
andrew has an average reputation (10+)
Default Re: Installing Policy-Does it drop existing connections?

In my experience --- yes and no.

When pushing policy there is always a 'lull' in the traffic. Connections that can survive the lull stay up, those that cannot, don't.

For example, we have a telecommuter with VoIP and Instant Messaging over VPN. I can push policy while on the phone with this person, and the line goes quiet for a couple of seconds, and then we're back on, however the IM session is dumped and he must reconnect.

FTP over VPN dumps during a policy push, too. PCAnywhere over VPN, no.

Go through and test connections in your environment during policy push, determine what survives and what doesn't, and then you'll know what to expect when you make changes during the middle of the day.
Reply With Quote
  #5 (permalink)  
Old 2007-06-11
angelo angelo is offline
Junior Member
 
Join Date: 2007-06-09
Posts: 2
Rep Power: 0
angelo has an average reputation (10+)
Default Re: Installing Policy-Does it drop existing connections?

Look under:

Gateway Properties --> Advanced --> Connection Persistence.
Reply With Quote
  #6 (permalink)  
Old 2007-06-11
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: Installing Policy-Does it drop existing connections?

Andrew is right, the push affects different applications in various ways depending upon a couple variables:
  • Traffic load
  • Sensitivity of the service (VoIP vs. HTTP)
  • Luck

I include luck because you'll push the policy 50 times and everything will be ok, and on the 51st time you'll completely trash the state table and people will be disconnected. They can reconnect immediately, but for the poor folks in customer service entering in line 50 on a complicated order in the ERP system it can be a maddening experience.
Reply With Quote
  #7 (permalink)  
Old 2007-06-12
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,027
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Installing Policy-Does it drop existing connections?

Within each service there is a tick box

Keep Connections open after policy has been installed.

By default this is not ticked

What it does is actually empty the state table causing the connections to rebuild the state table as they go through. It doesn't drop the connection as such, however as other people have said not all applications will handle the lull increating a new entry.

You could tick this for services that you need to survive the policy install as it would not empty that service from the connection table.
Reply With Quote
  #8 (permalink)  
Old 2007-06-12
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Installing Policy-Does it drop existing connections?

From the help file

Keep connections open after policy has been installed even if they are not allowed under the new policy. This overrides the settings in the Connection Persistence page. If you change this property, the change will not affect open connections, but only future connections.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:52.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0