CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-04-03
Junior Member
 
Join Date: 2007-03-11
Posts: 10
Rep Power: 0
K2Technologies has an average reputation (10+)
Default SD killing HTTPS connection

People within my network are attempting to get to a website from Wells Fargo. The connections are getting blocked by SD but I do not fully understand why. From that, I cannot create a work around to this issue.

Can anyone help me decipher the following log entry:

Number: 567715
Date: 3Apr2007
Time: 8:52:50
Product: SmartDefense
Interface: eth2
Origin: Cheyenne (172.24.1.15)
Type: Log
Action: Drop
Protocol: tcp
Service: https (443)
Source: 172.16.1.13
Destination: wellsfargo.com (209.84.206.42)
Source Port: 1629
Attack Name: Invalid SSL Packet
Attack Information: Too many open connections


Thank you.
Reply With Quote
  #2 (permalink)  
Old 2007-04-04
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: SD killing HTTPS connection

Quote:
Originally Posted by K2Technologies View Post
Attack Name: Invalid SSL Packet
Attack Information: Too many open connections
Sounds like you have multiple people accessing this website at once...does it work when only one person does it?

Wish there was a reference as to which smart defense alert triggered the log entry...
Reply With Quote
  #3 (permalink)  
Old 2007-04-04
Junior Member
 
Join Date: 2007-03-11
Posts: 10
Rep Power: 0
K2Technologies has an average reputation (10+)
Default Re: SD killing HTTPS connection

The "too many open connections" has to be a misnomer; the site worked before we upgraded to R60 (from R55) and still works from any location not going through our FW1 gateway....
Reply With Quote
  #4 (permalink)  
Old 2007-04-04
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: SD killing HTTPS connection

You updated SD after you upgraded? Otherwise disable all your Smart Defense and see which one [if any] is causing the problem..? I don't bank there so I can't try it.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:13.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0