Firewall-1

[FW-1] TCP packet out of state and LDAP

Subject: [FW-1] TCP packet out of state and LDAP
From: Thomas Mårtensson <thomas.martensson AT NUTEK DOT SE>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Wed, 30 Mar 2005 10:30:57 +0200
I should tell you that I'm tunning R55 HFA 13 on SPLAT

Hi all,

we currently have a problem with ldap authentication and TCP packet out
of state. I have done the usual stuff* but I still get a lot of "out of
state" packets, and when those packets appear in the log someone can't
login resulting in a lot of people bugging me. It worked fine before
when all servers were on the same LAN (for obvious reasons), but I don't
want that.

Have anyone else had this kind of problems and what did you do to solve
them?

Regards,
//Thomas

* with usual stuff, I mean:
tcp_keepalive_interval is set to 3500 sec on both sides (solaris)
I have set the ldap service 'session timeout' to 7200 sec. and checked
"keep connections after policy..."

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>