CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-10-06
Ezrae Ezrae is offline
Junior Member
 
Join Date: 2005-08-24
Posts: 2
Rep Power: 0
Ezrae has an average reputation (10+)
Default NGX SmartDefense PNG protection false positives

Hi,

I was wondering if anyone else out there is having this problem:

We upgraded to NGX, and since then we're having trouble with the PNG protection in Smart Defense.

When making a Webdav connection and attempting to upload a powerpoint (.ppt) or dynamically created PNG files from an ArcIMS mapping server the files are blocked with the PNG protection message in the logs.

Disabling PNG protection does not fix the problem.

We're running NGX on Nokia IPSO 3.9 Build 35.

Rolling back to R55W solves the problem, but rolling back permanently isn't really an option.

Thanks!
Jen
Reply With Quote
  #2 (permalink)  
Old 2005-10-12
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: NGX SmartDefense PNG protection false positives

We have a customer here with the same issue. Case has been escalated to Check Point and they are working on it. Sounds like an NGX bug.
Reply With Quote
  #3 (permalink)  
Old 2005-10-13
intehnet intehnet is offline
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: NGX SmartDefense PNG protection false positives

is this limited to the nokia build of NGX or all versions?
Reply With Quote
  #4 (permalink)  
Old 2006-10-26
dramirez dramirez is offline
Junior Member
 
Join Date: 2006-10-16
Posts: 5
Rep Power: 0
dramirez has an average reputation (10+)
Default Re: NGX SmartDefense PNG protection false positives

CMA is running R61, the firewall is running R55 HFA17.

Some users were complaining of not being able to download stuff, in the logs: SD Microsoft Internet Explorer PNG Rendering

If I disable the PNG protection, they are able to get their stuff...

SD is creating me more problems with too many false positives, I'm starting to hate it.
Reply With Quote
  #5 (permalink)  
Old 2006-10-27
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: NGX SmartDefense PNG protection false positives

Quote:
Originally Posted by dramirez View Post
SD is creating me more problems with too many false positives, I'm starting to hate it.
SmartDefense may be blocking stuff you don't want it to, but it is very rare that it is a false positive. SmartDefense is very strict about how it intrupets the RFC/standards.

When you encounter something that you think is a false positive, please open a ticket. The more information the SmartDefense developers get the better, but don't be surprised if they come back and tell you SD is right and the file/site/whatever is broken. There is a lot of very poorly written websites and the like out there.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:42.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0