Thank you for the reply.
On Tue, 13 Jun 2000, Scheidel, Greg wrote:
> - TCP Timeout default setting is 3600 secs. Try setting to that and retest;
> see if it makes a difference. If it does, then it points to TCP Timeout
> setting.
I've set it to 3600 and then to 7200. No change.
> - Make sure you've turned on "Display Warning Messages" on the SYN Defender
It's on.
> options, and that you're using Long logging on your clean-up rule. Look at
It's there.
> the log and see if you're getting SYN Defender drops or clean-up rule drops.
It's SYN Defender drops.
> - Check to see if the log lines do in fact say "message SYN -> SYN-ACK ->
> timeout", "message SYN -> SYN-ACK -> RST" or something similar. If so, it
> points back to SYN Defender.
Yes, this is what it's logging.
> - Test with SYN Defender (passive or active) completely turned off. That'll
> tell you if it's related to SYN Defender at all.
Done this. Works only when set to None.
> SYN Defender cannot be set per interface; its all or nothing.
Oh well. We'll need to leave it off.
Frank
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================