Hi All,
Our product communicate over the FW-1 using tcp (See below).
HostA ---- FW-1 ---- HostB
(destination port 20XX) (source port 10XX)
It is correct to set the FW-1's rule base with regards to this communication.
But we got the following the FW-1's log.
---------------------------------------------------------------------
"1111111" "16Jul2004" "9:04:17" "VPN-1 & FireWall-1" "eri0" "FW-1"
"Log" "Drop" "20XX" "Host B" "Host A" "tcp" "" "10XX" "" "th_flags:2;
message_info: SYN packet for established connection; "
---------------------------------------------------------------------
We found out http://www.firewall-1.org/2002-04/msg00180.html,
so we believe reducing the tcpendtimeout setting might prevent another
extended disconnection between HostA and HostB.
However, this communication was initially interrupted by the FW-1.
Our product was automatically recoverd.
Why ?
Any ideas ?
Best Regards,
Sekigawa Ai
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================