CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-08
Senior Member
 
Join Date: 2006-02-18
Posts: 103
Rep Power: 3
ChrisA has an average reputation (10+)
Default Use SmartDefense SYN Gateway for TCP packet out of state

We're seeing thousands of "TCP packet out of state" errors in the firewalls (Nokia IP710, ipso 3.9 b45, ChkPt R60 HFA02). This is nothing new, but within the last month we've installed new proxy servers which are crashing left and right, running out of buffers. The "TCP packet out of state" errors might be totally unrelated, but because the vast majority of these errors are occurring for proxy traffic, someone asked if perhaps the firewall is having problems keeping up with the traffic to/from this new proxy, resulting in the 'out of state' errors and subsequently, the buffer overloads on the proxy. Or, alternatively, the 'out of state' errors always occurred, but the new proxy server can't handle this traffic like the old proxy. In either case, I've been asked if SYNdefender can be used to deal with the 'out of state' errors so that the traffic to/from the proxy is handled more cleanly.

We currently have "Override modules' SYNDefender configuration" checked, but nothing else.

Would SYN Gateway or Passive SYN Gateway help us, and if so, which one is the better choice?

I'd really appreciate feedback on this thread. The more, the better. I tried turning flows off on the Nokia, and it made no difference. I'll be trying the "cphaconf set_ccp broadcast" next Sunday to see if that helps. I'm also researching the effect of "Synchronize connections on cluster" option in various services. I would be extremely grateful for any info. Thank you!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:12.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0