CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-08-21
Junior Member
 
Join Date: 2006-06-02
Posts: 24
Rep Power: 0
rugby1725 has an average reputation (10+)
Default Scanning and system crashing

I'm having some issues with scanning across my clusters. While I realize that we need to dial back the scanning it definitely concerns me should we get a true SYN attack or DoS. I'm really not sure what I'm missing so I'm looking for some help.

Setup: I'm running NG AI R55 in a load sharing cluster with 2 machines. The servers are Sun V240's with dual CPU and 4 Gb RAM. Mgmt is a Sun V210 w/ NGX 65.

Scenario: If we scan with NMAP across the firewall it will cause a kernel panic and the firewall will crash. It doesn't happen every time and not always the same box. I've upped the connection limit table to 100000 and that helps somewhat, I've also increased the log buffer limit in the /etc/system based on a sk article I saw that said if it fills the machine could panic.

Any help would be greatly appreciated.

Kris
Reply With Quote
  #2 (permalink)  
Old 2007-08-21
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Scanning and system crashing

What HFA level are you on for R55? I've never heard of this happening and the firewall should be able to protect itself. What do you allow for connections o the firewall itself?

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-08-22
Junior Member
 
Join Date: 2006-06-02
Posts: 24
Rep Power: 0
rugby1725 has an average reputation (10+)
Default Re: Scanning and system crashing

We're currently on HFA_18. I should have been a little clearer on the problem description. This happens when we are scanning through the firewalls, ie scanning boxes sitting out on a DMZ. The machines doing the scanning essentially have an any, any rule for them. Obviously this could cause connection table limit issues, hence the reason we upped that to 100000. However, the scan that caused the last crash was only ports 1-1023 on 15 hosts which shouldn't have caused an issue even at the default setting.

Kris
Reply With Quote
  #4 (permalink)  
Old 2007-08-23
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Scanning and system crashing

I'd open a support case with CP. You're right, this should bot be happening. Did you do anything like turn off SmartDefense's "packet sanity" checks?

Ray
Reply With Quote
  #5 (permalink)  
Old 2007-08-24
Junior Member
 
Join Date: 2006-06-02
Posts: 24
Rep Power: 0
rugby1725 has an average reputation (10+)
Default Re: Scanning and system crashing

Nope I pretty much left that all default
Reply With Quote
  #6 (permalink)  
Old 2007-08-25
Senior Member
 
Join Date: 2006-09-26
Posts: 822
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Scanning and system crashing

I have several pairs of Checkpoint NG AI R55 running HFA_17
with ClusterXL Active/Active.

I would like to know if you or Checkpoint have a solution
to fix this. Thanks.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:21.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0