CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-19
Junior Member
 
Join Date: 2005-08-26
Location: Muenster, Germany
Posts: 1
Rep Power: 0
moelljoe has an average reputation (10+)
Default DCE-RPC Enforcement Violation

Hello,

last week, we upgrade from CheckPoint NG R55 to CheckPoint NG-X R60 HFA03. Now we have problems with the microsoft domain controler communication.

If the server A in our dmz to try to connect server B (domain controler) we got often this alert:

Number: 192944
Date: 19Jun2006
Time: 16:35:13
Product: SmartDefense
Interface: eth-s1p2c0
Origin: fw (192.168.1.1)
Type: Alert
Action: Reject
Protocol: tcp
Service: epmap-135 (135)
Source: serverA (192.168.10.10)
Destination: serverB (172.16.20.20)
Source Port: 4740
Attack Name: DCE-RPC Enforcement Violation
Attack Information: Source IP in port command is different than the Server IP


Is there anybody who get this error message too??
Is there anybody who know, how we can disable this check in smart defense?

moelljoe
Reply With Quote
  #2 (permalink)  
Old 2006-06-27
Member
 
Join Date: 2006-06-27
Location: United Kingdom
Posts: 73
Rep Power: 3
munrog has an average reputation (10+)
Send a message via MSN to munrog Send a message via Skype™ to munrog
Default Re: DCE-RPC Enforcement Violation

Hi there,

This is a known problem in NGX (R60). You need to contact your CSSP and get hold of an update to the DCERPC.def file. (it may also be included in HFA03)

According to Solution ID: #sk31245
In DCE-RPC communication, the End Point Mapper response may contain a redirection to other servers. Redirection can be used by a malicious server to attack hosts on the network. By default, the server response is dropped, and the following log message displays:

"DCE-RPC Enforcement Violation... Source IP in port command is different than the Server IP"

Cheers
Greg
Reply With Quote
  #3 (permalink)  
Old 2006-08-07
Junior Member
 
Join Date: 2006-04-05
Location: VAN
Posts: 24
Rep Power: 0
_d3nx has an average reputation (10+)
Default Re: DCE-RPC Enforcement Violation

Hi,

I have faced same errors in NGX HFA04. Did you have resolved this problem?
Reply With Quote
  #4 (permalink)  
Old 2006-08-07
Senior Member
 
Join Date: 2006-06-14
Location: The Netherlands
Posts: 153
Rep Power: 3
dbedit has an average reputation (10+)
Default Re: DCE-RPC Enforcement Violation

Replace dcerpc.def with dcerpc_HFA.def that came with your HFA03. That's in your fw1\lib directory. First do a cpstop, replace , cpstart.
If this does not work add new service tcp-135 to rule.
Reply With Quote
  #5 (permalink)  
Old 2006-08-07
Senior Member
 
Join Date: 2006-06-14
Location: The Netherlands
Posts: 153
Rep Power: 3
dbedit has an average reputation (10+)
Default Re: DCE-RPC Enforcement Violation

Srry, forgot to mention RENAME and replace :-)
Reply With Quote
  #6 (permalink)  
Old 2006-09-20
Junior Member
 
Join Date: 2006-09-19
Posts: 5
Rep Power: 0
cgill27 has an average reputation (10+)
Default Re: DCE-RPC Enforcement Violation

This works, also don't forget to push policy to affected gw's.

Craig
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:03.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0