13.07.2015 Views

Firewall - Check Point

Firewall - Check Point

Firewall - Check Point

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

• To disable ISP redundancy, in SmartDashboard edit the gateway object >Topology > ISP Redundancy, and remove the check mark from Support ISPRedundancy.ClusterXL• To disable VPN link selection - Reply from the same interface, in SmartDashboardedit the gateway object > VPN > Link Selection > Outgoing Route Selection, anddo the following:A. Under When initiating a tunnel, enable Operating system routing table,B. and under When responding to remotely initiated tunnel, select Setup, andenable Use outgoing traffic configuration.21. When configuring a VTI cluster interface, it should be assigned a name identical tothe name of the member interface.High Availability22. In legacy High Availability mode for ClusterXL, MAC address synchronization is notsupported for VLAN tagged interfaces. Use new High Availability mode, or manuallyconfigure the MAC addresses of the interfaces using the ifconfig CLI or WebUI.23. Issuing a Stop Member command in SmartView Monitor performs the cphastopcommand on this member. Among other things, this disables the StateSynchronization mechanism. Any connections opened while the member is stoppedwill not survive a failover event, even if the member is restarted using cphastart.However, connections opened after the member is restarted are synchronized asnormal.Load Sharing24. Under load, tcp packet out of state error messages may appear. For each case thereis a specific way to resolve it. Refer to the “<strong>Firewall</strong> and SmartDefense” guide for afull explanation and security implications.• message_info: TCP packet out of state - first packet isn't SYN tcp_flags: FIN-ACKmessage_info: TCP packet out of state - first packet isn't SYN tcp_flags:FIN-PUSH-ACKIn SmartDashboard > Global Properties > Stateful Inspection, enlarge tcp endtimeout. The recommended value is 60 seconds. If there are many connectionsconsider enlarging the connection table size in the same ratio as the tcp endtimeout.• message_info: SYN packet for established connectionrun the command: fw ctl set int fw_trust_rst_on_port When a single port is not enough, you can set the port number to -1, meaningthat you trust a reset from every port.Enterprise Suite NGX R61 Known Limitations Supplement Last Update — February 7, 2007 38

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!