CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-17
Member
 
Join Date: 2007-01-30
Location: Abudhabi
Posts: 48
Rep Power: 0
sridharraj80 has an average reputation (10+)
Default Particular IP has been blocked

Hi Guys ,

Yesterday I have faced a peculiar issue.

I have allowed a http and https request for a range of IP address(This was working since a month ). From yesterday one IP from this range is droped in the firewall for http and https request. I have tried swapping the IP with some other machine and still it is not working. This is again matching the cleanup rule and droping.

Anyone faced with similar situtation. What will be the root cause of this problem. Can one please help to solve this problem

Sridhar
Reply With Quote
  #2 (permalink)  
Old 2007-03-17
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Particular IP has been blocked

Can you detail how the rule and objects are set up, and which version & HFA level you're on?

If these are public IP addresses, fell free to block out the first part if needed for confidentiality.

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-03-19
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Particular IP has been blocked

Could it be that you somehow blocked that IP on SAM? I think if that was the case it should drop as rule 0, but hey, no harm done in checking I guess.

When you are viewing active connections on the "SmartView Tracker", there is an option that allows you to block intruders, "Tools->Block Intruder". This doesn't show on rules, but would cause the traffic to drop.
The option below that one "Clear Blocking" should remove the blocking.

If this isn't the problem, this is what I would do:
1 - Create a specific rule for that IP alone, just like the "normal" rule and place it above, with log
2 - Try the access again and check results
3 - Check logs
Reply With Quote
  #4 (permalink)  
Old 2007-03-19
Member
 
Join Date: 2007-01-30
Location: Abudhabi
Posts: 48
Rep Power: 0
sridharraj80 has an average reputation (10+)
Default Re: Particular IP has been blocked

Hi ,

The rule is like this..

<172.x.x.x-172.x.x.x><ANY><ANYTraffice><http,https><Accept><L og>.

Version NG with R55 Build 127.

Thanks
Sridhar
Reply With Quote
  #5 (permalink)  
Old 2007-03-20
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Particular IP has been blocked

Have you tried to reinstall policy?

Is anything showing up in the logs?
Reply With Quote
  #6 (permalink)  
Old 2007-03-21
Member
 
Join Date: 2007-01-30
Location: Abudhabi
Posts: 48
Rep Power: 0
sridharraj80 has an average reputation (10+)
Default Re: Particular IP has been blocked

Hi ,

I have explicitily allowed the particular IP also . Even then it is not working .

sridhar
Reply With Quote
  #7 (permalink)  
Old 2007-03-21
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Particular IP has been blocked

What rule is dropping the traffic? Don't want to doubt you, but check the number, it may not be the clean up.

You might want to check my previous post too. Everything you say makes me think SAM, but...
Reply With Quote
  #8 (permalink)  
Old 2007-03-21
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Particular IP has been blocked

check sam table on the module(s)

fw tab -t sam_blocked_ips -f
Reply With Quote
  #9 (permalink)  
Old 2 Weeks Ago
Junior Member
 
Join Date: 2006-08-09
Posts: 3
Rep Power: 0
lnx32 has an average reputation (10+)
Default Re: Particular IP has been blocked

I had a similar issue this week where the firewall was rejecting traffic outbound from one of my mail servers. It only effected one of them. The other one was working just fine. I checked the active log and saw that the sam rule was in effect for this particular reject. I checked the active connections and selected the reject. I then cleared the block intruder section in Tools and it cleared up the problem!

I still don't know how this was marked as block intruder in the first place though but the clearing in the active log did in fact work!!!!

Last edited by lnx32; 2 Weeks Ago at 22:24.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:18.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0