CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > SSL Network Extender
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-27
Junior Member
 
Join Date: 2007-10-19
Posts: 14
Rep Power: 0
kevindri has an average reputation (10+)
Default R60-R65 upgrade ssl drop

I moved server boxes and also upgraded from R60 to R65.

Once a user would connect it could stay connected for anywhere between 5 minutes to 2 hours. All sessions would drop at same time.

Logs didn't show anything.

Old server had 10/100 NIC cards the new one Gigabit network cards.

We made a change to set the Public NIC to 100 MB full duplex to match the router.
We still had the same problem.

SecureClient was able to work.

The new R65 firewall also to had a Connectra CM license - but where going to connect the original way of connecting to gw.ip.address

Has anyone else seen this issue?
Reply With Quote
  #2 (permalink)  
Old 2007-12-28
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: R60-R65 upgrade ssl drop

Haven't seen this one but there there are some changes to SNX in HFA01 (HFA02 is current), it might be worth a quick try if you haven't installed it yet.
Reply With Quote
  #3 (permalink)  
Old 2008-01-10
Junior Member
 
Join Date: 2007-10-19
Posts: 14
Rep Power: 0
kevindri has an average reputation (10+)
Default Re: R60-R65 upgrade ssl drop

turned out to be bad on-board NIC
Reply With Quote
  #4 (permalink)  
Old 2008-02-04
Junior Member
 
Join Date: 2007-10-19
Posts: 14
Rep Power: 0
kevindri has an average reputation (10+)
Default Re: R60-R65 upgrade ssl drop

Update:
We tried again after motherboard replace and we had worse issues.

It appeared to be fine in Parallel testing mode, but when thrown into live environment with heavy load and traffic, lots of things did not work and connectivity to servers or the firewall web admin were slow.


We did here from a consultant who helped troubleshoot say that the Broadcom NIC cards have issues and Intell should be used.

Has anyone else experienced this issue?
Dell 1950 Poweredge server or problem with Broadcom NIC's

ready to buy a 4port Intel nic card and hopefully that will be it.


Link to new thrhead in Interoperablity.
R65 + Dell 1950 + Broadcom NIC

Last edited by kevindri; 2008-02-04 at 10:02.
Reply With Quote
  #5 (permalink)  
Old 2008-02-04
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: R60-R65 upgrade ssl drop

I've had good success with Intel Pro 1000s (duals and quads). I've definitely have had issues in the past with cards that are not on the Hardware Compatibility list (NICs), so I highly recommend you use something from that list. I don't see your broadcomm on there so I would not recommend using it.

HTH
__________________
Its all in the documentation.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:26.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0