CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartView Tracker/Logging And Alerting
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-07-11
Junior Member
 
Join Date: 2008-05-24
Posts: 6
Rep Power: 0
rockysam39 has an average reputation (10+)
Default FTP download issues

Hi



We are facing this issue since last few months. When we try to download any drivers from the Dell or HP websites , the download is getting re-directed to one of their FTP sites and then the download fails with either 'Page cannot be displayed' error or continues to try opening the page for eternity...
When I check the logs on the firewall ( SmartView Tracker ) I see all the FTP traffic from the source machine is passing the Firewall, and not dropped/rejected (not even by the Smartdefense). However , veryfew packets are getting dropped. One such log detail is as follows:-



Number: 177797
Date: 5Jul2008
Time: 5:40:36
Product: VPN-1 Power/UTM
Interface: eth1
Origin: INITC_FW_01
Type: Log
Action: Drop
Protocol: tcp
Service: ftp (21)
Source: 10.108.8.32
Destination: pla-ftp.nai.com (216.143.70.11)
Source Port: 1697
Information: TCP packet out of state: First packet isn't SYN
tcp_flags: ACK
Policy Info: Policy Name: INITC_FW_01-20071108-DH
Created at: Fri Jul 04 13:44:14 2008
Installed from: SmartCenter-1
The Firewall rule for Internet is set to allow FTP traffic.
I have tried to check for logs of traffic coming from these FTP sites (i.e., inbound ftp traffic ) but I dont see any traffic at all.

I'm trying to figure out if there is any blockage on the Firewall or not, though I believe there is none.

Can anyone help me with any ideas to research this from the Firewall end or a better way to analyze these traffic?
Is there anything else I may check to see if the FTP download is getting blocked by the Firewall or Smartdefense?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:55.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0