Thank you for the reply.

On Tue, 13 Jun 2000, Scheidel, Greg wrote:

> - TCP Timeout default setting is 3600 secs.  Try setting to that and retest;
> see if it makes a difference.  If it does, then it points to TCP Timeout
> setting.

I've set it to 3600 and then to 7200. No change.

> - Make sure you've turned on "Display Warning Messages" on the SYN Defender

It's on.

> options, and that you're using Long logging on your clean-up rule.  Look at

It's there.

> the log and see if you're getting SYN Defender drops or clean-up rule drops.

It's SYN Defender drops.

>   - Check to see if the log lines do in fact say "message SYN -> SYN-ACK ->
> timeout", "message SYN -> SYN-ACK -> RST" or something similar.  If so, it
> points back to SYN Defender.

Yes, this is what it's logging.

> - Test with SYN Defender (passive or active) completely turned off.  That'll
> tell you if it's related to SYN Defender at all.

Done this. Works only when set to None.

> SYN Defender cannot be set per interface; its all or nothing.

Oh well. We'll need to leave it off.

Frank





================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to