Firewall - Check Point

Firewall - Check Point Firewall - Check Point

downloads.checkpoint.com
from downloads.checkpoint.com More from this publisher
13.07.2015 Views

SecureXL69. When configuring Server Availability for ConnectControl (SmartDashboard > Policymenu > Global Properties > ConnectControl), the value for the Server availabilitycheck interval must be a multiple of 5 and no less than 15.SecureXLUnsupported Features1. ISP redundancy, when working in conjunction with SecureXL, has the followinglimitations:• Some connections passing through interfaces configured with ISP redundancyare not accelerated, while other connections (for example, an internalconnection to a DMZ) are accelerated and are not affected by this limitation.• ISP redundancy over PPTP and PPPoE interfaces is not supported.2. When SecureClient is connected to a VPN-1 gateway with two external interfacesand the connected interface goes down, SecureClient will lose connectivity. In orderto resume connectivity, the user needs to disconnect and reconnect.3. When configuring Remote Access > Office Mode on a VPN gateway that has multipleexternal interfaces with SecureXL enabled, make sure that Support connectivityenhancement for gateways with multiple external interfaces is checked.4. QoS is not supported with SecureXL.Accelerated Features5. The SmartDefense feature PPTP Enforcement does not allow acceleration of the GREprotocol over PPTP when enabled. In order to accelerate the GRE protocol overPPTP, disable this feature (on the SmartDefense tab, select Application Intelligence> VPN Protocols > PPTP Enforcement).6. Overlapping NAT is not supported with Performance Pack.Platform Specific - Nokia7. When the SmartDefense TCP Sequence Verifier feature is enabled and SecureXL ison or Flows acceleration is enabled, a message appears when you install a policyfrom SmartDashboard and the Sequence Verifier feature is not enforced.• For SecureXL, the message displayed is: “Warning: This Gateway supportsSecureXL traffic acceleration. TCP Sequence Verifier (SmartDefense) will not beenforced on accelerated connections. To allow Sequence Verification, turn offacceleration on the Gateway by running cpconfig.”Enterprise Suite NGX R61 Known Limitations Supplement Last Update — February 7, 2007 46

• For Flows acceleration, the message is: “Flows: TCP Sequence Verifieracceleration is not supported on the Gateway.”Performance PackTo configure the TCP Sequence Verifier, select the SmartDefense tab > Network Security> TCP and deselect Sequence Verifier.Platform Specific — Solaris8. On Solaris platforms, Performance Pack does not support the following types ofinterfaces• VLAN and virtual interfaces• bge, dmfe and skge interfacesPerformance PackUnsupported Features1. Performance Pack does not support dynamic interface changes on Solaris. Beforeperforming ifconfig up/down/plumb or unplumb, turn off acceleration by issuing thefwaccel off command. Then enable acceleration by issuing the fwaccel oncommand.2. Performance Pack does not support source based routing.Unsupported Products3. Performance Pack is not supported when using ClusterXL Load Sharing with StickyDecision Function (SDF). When SDF is enabled, acceleration is automaticallyturned off. To re-enable acceleration, first make sure acceleration is enabled byrunning the cpconfig configuration tool. Then disable SDF (in SmartDashboard, editthe Gateway Cluster object, select the ClusterXL page, and click Advanced), andinstall the new Security Policy twice.4. PPTP and PPPoE interfaces are not supported by Performance Pack inconfigurations where NAT and/or VPN-1 are used.5. Virtual interfaces and VLAN interfaces are not supported by Performance Pack onSolaris.Accelerated Features6. The SmartDefense feature PPTP Enforcement does not allow acceleration of the GREprotocol over PPTP when enabled. In order to accelerate the GRE protocol overPPTP, disable this feature (on the SmartDefense tab, select Application Intelligence> VPN Protocols > PPTP Enforcement).Enterprise Suite NGX R61 Known Limitations Supplement Last Update — February 7, 2007 47

SecureXL69. When configuring Server Availability for ConnectControl (SmartDashboard > Policymenu > Global Properties > ConnectControl), the value for the Server availabilitycheck interval must be a multiple of 5 and no less than 15.SecureXLUnsupported Features1. ISP redundancy, when working in conjunction with SecureXL, has the followinglimitations:• Some connections passing through interfaces configured with ISP redundancyare not accelerated, while other connections (for example, an internalconnection to a DMZ) are accelerated and are not affected by this limitation.• ISP redundancy over PPTP and PPPoE interfaces is not supported.2. When SecureClient is connected to a VPN-1 gateway with two external interfacesand the connected interface goes down, SecureClient will lose connectivity. In orderto resume connectivity, the user needs to disconnect and reconnect.3. When configuring Remote Access > Office Mode on a VPN gateway that has multipleexternal interfaces with SecureXL enabled, make sure that Support connectivityenhancement for gateways with multiple external interfaces is checked.4. QoS is not supported with SecureXL.Accelerated Features5. The SmartDefense feature PPTP Enforcement does not allow acceleration of the GREprotocol over PPTP when enabled. In order to accelerate the GRE protocol overPPTP, disable this feature (on the SmartDefense tab, select Application Intelligence> VPN Protocols > PPTP Enforcement).6. Overlapping NAT is not supported with Performance Pack.Platform Specific - Nokia7. When the SmartDefense TCP Sequence Verifier feature is enabled and SecureXL ison or Flows acceleration is enabled, a message appears when you install a policyfrom SmartDashboard and the Sequence Verifier feature is not enforced.• For SecureXL, the message displayed is: “Warning: This Gateway supportsSecureXL traffic acceleration. TCP Sequence Verifier (SmartDefense) will not beenforced on accelerated connections. To allow Sequence Verification, turn offacceleration on the Gateway by running cpconfig.”Enterprise Suite NGX R61 Known Limitations Supplement Last Update — February 7, 2007 46

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!