CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-27
Junior Member
 
Join Date: 2006-09-29
Posts: 10
Rep Power: 0
mfavinsk has an average reputation (10+)
Default Trouble avoiding CIFS errors

I've been having a lot of trouble getting rid of the "CIFS message too long" error generated by my firewall. In researching this issue, I found many people achieved good results by increasing their asm_cifs_max_buffer. I increased this value to its maximum size and I still had the CIFS message too long issue.

The next thing I did was create a new service called "nbsession_none", where I set the protocol type to "None" and unchecked "Match for Any." I then created a rule above the previous netbios rule allowing nbsession_none connections to the specific server in question. I was still getting the CIFS message too long error, but now with the service of nbsession_none!

Finally, I changed the regular nbsession service Protocol type to "None." Now everything worked! It seems that even though my traffic was matching the nbsession_none service, somehow the Protocol type of the nbsession service was still being used for SD / AI processing.

My questions:

Since Tracker shows that the rule matched was for the nbsession_none service, why is there still CIFS SD / AI processing happening on the data?

Why did I have to change the Protocol Type of the nbsession service to finally make this work? Since the nbsession_none service is the one that got matched, why is the nbsession service getting involved at all?

Am I doing something wrong here? Is there some other way I should be doing this?

Thanks for your help everyone.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:13.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0