CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-12
Junior Member
 
Join Date: 2006-11-27
Posts: 10
Rep Power: 0
the-k33n has an average reputation (10+)
Default DCE-RPC Problem

Hi, i have a strange problem withe smartdefence.
Maybe somebody can point me into the right direction.

Smartview tracker logs the following.

Number: 1247628
Date: 12Sep2007
Time: 16:35:08
Product: SmartDefense
Attack Name: DCE-RPC Enforcement Violation
Attack Information: UUID is not allowed through the Rule Base
Interface: eth0
Origin: gatede
Type: Log
Action: Monitor Only
Service: rpc (135)
Source: 192.168.0.32
Destination: exchangeserver(10.150.150.74)
Protocol: tcp
Source Port: 1954
Information: DCE-RPC Interface UID: 1544f5e0-613c-11d1-93df-00c04fd7bd09


I have a rule that allows exactly that DCE-Service.
Nevertheless that service is blocked?
Can you tell me why?


Thanks in advance Mario.
Reply With Quote
  #2 (permalink)  
Old 2007-09-17
Junior Member
 
Join Date: 2007-08-21
Posts: 5
Rep Power: 0
Henrik has an average reputation (10+)
Default Re: DCE-RPC Problem

Hi,

Sometimes smartdefence don't log all the dce-rpc as it should so try to use the "all dce-rpc" insted, this will give you all the dce-rpc protocols that are getting used for this session and when you goth them all you could put this in to the rule base insted.

This is at leased how I usually how I go around this
Reply With Quote
  #3 (permalink)  
Old 2007-09-17
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: DCE-RPC Problem

This is a 50-50 call as to wether is Microsoft or Check Point. There are some knowledgebase articles on Check Point and Microsoft about this. Microsoft have messed about with the DCE-RPC for Exchange on Windows 2003 SP1.

What version of Check Point are you on.

From my understanding either upgrade the Windows to 2003SP2 or upgrade your Check Point to NGX and the latest HFA's to resolve this along with getting a SMARTDefense update.
Reply With Quote
  #4 (permalink)  
Old 2007-09-18
Junior Member
 
Join Date: 2006-11-27
Posts: 10
Rep Power: 0
the-k33n has an average reputation (10+)
Default Re: DCE-RPC Problem

Hi,
i have also tried #sk25562 but it didn`t help neither.
I think i will do an upgrade at the weekend and see what will happen.

Thanks for your help.

Mario
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:11.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0