Firewall-1

[FW-1] HFA17: DCE-RPC still logging rule 995

Subject: [FW-1] HFA17: DCE-RPC still logging rule 995
From: Dave Row <Dave.Row AT RETAILVENTURESINC DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Fri, 3 Mar 2006 07:14:40 -0500
I applied the HFA17 hotfix to my SPlat NG w/ AI R55 nodes.  Afterward, I
replaced the dcerpc.def files with the dcerpc_HFA.def.  Although the
release notes specifically say that HFA16 fixed this exact issue, I
still have 995s in my logs.

OK, the release notes also say, (paraphrased) "if you still have the
problems after replacing/modifying the dcerpc.def file, then disable
checking altogether by setting NO_ENFORCE_CNTX_NUM 1."  No love.

How can this possibly be?!  Either the HFA is made to fix the issue or
not.  Certainly after disabling context count checking, the errors would
stop, right?

Bottom line:  my Windows 2003 DCs are still not replicating, and I'm
still taking 995 hits in my logs.

Is anyone else out there wrestling with this?  I'm getting very tired of
these night-time maintenance windows that don't pan out.  Any help would
be appreciated.


- Dave

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>