Firewall Issue

Firewall Issue

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Firewall Issue Ankur 06-13-2008
`--> Re: Firewall Issue Ansgar -59cobal...06-13-2008
Posted by Ankur on June 13, 2008, 2:09 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi Folks,

I'm new to the group, so kindly forgive it my question is not
appropirate in any way.

We have a situation where we have a Server application that is
listening on a port on which client applications connect.
Server and clients are on seperate networks.
Server application network is using a firewall device as an interface
for client connections.

The firewall device is configured in such a way that it periodically
performs a poll operation on the ports where the Server is listening
for client connections, just to check the the Server application is
alive and well.
The Server application is written in such a way that it treats all the
connections on this port as connect requests and proceeds to handle
them accordingly.
This leads to some errors of the application logs since while handling
such requests i.e. poll operation for the firewall since the
application doen't distinguish client connect requests from the
firewall poll operation thereby generating following error messages:-

GetCompletionStatus failed - "The specified
network name is no longer available.

My question is-

Is there a workaround on the firewall side to fix this kind of
behaviour by changing some kind of configuration. The poll request is
a valid requirement and cann't be done away with.
Or is it that I need to handle this situation in the Server
application itself i.e. to distinguish between normal client connect
requests and the firewall poll operation.

I'll highly appreciate your insights.

Thanks.
Ankur.

Posted by Ansgar -59cobalt- Wiechers on June 13, 2008, 7:43 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> We have a situation where we have a Server application that is
> listening on a port on which client applications connect.
> Server and clients are on seperate networks.
> Server application network is using a firewall device as an interface
> for client connections.
>
> The firewall device is configured in such a way that it periodically
> performs a poll operation on the ports where the Server is listening
> for client connections, just to check the the Server application is
> alive and well.
> The Server application is written in such a way that it treats all the
> connections on this port as connect requests and proceeds to handle
> them accordingly.
> This leads to some errors of the application logs since while handling
> such requests i.e. poll operation for the firewall since the
> application doen't distinguish client connect requests from the
> firewall poll operation thereby generating following error messages:-
>
> GetCompletionStatus failed - "The specified
> network name is no longer available.
>
> My question is-
>
> Is there a workaround on the firewall side to fix this kind of
> behaviour by changing some kind of configuration. The poll request is
> a valid requirement and cann't be done away with.
> Or is it that I need to handle this situation in the Server
> application itself i.e. to distinguish between normal client connect
> requests and the firewall poll operation.

Well, if you have a way to perform some kind of "nop" (no operation)
request on the server application and also are able to update the check
on your firewall appliance accordingly, then you can get around this
error. Otherwise it can only be fixed in the server application AFAICS.

cu
59cobalt
--
"If a software developer ever believes a rootkit is a necessary part of
their architecture they should go back and re-architect their solution."
--Mark Russinovich

Similar ThreadsPosted
Pix Firewall Issue November 20, 2005, 9:31 pm
NLB Firewall Issue? June 1, 2007, 11:56 am
Issue with Checkpoint Firewall December 29, 2005, 3:01 am
How do you safely debug a firewall issue? December 8, 2007, 12:11 am
SSH remote login problem - firewall issue? June 10, 2006, 1:03 pm
Pix 501 to Pix 501 VPN Issue December 28, 2005, 1:06 pm
PIX 501 issue July 24, 2006, 5:53 pm
Sonicwall VPN Issue August 1, 2004, 11:46 pm
Network issue March 11, 2005, 7:18 am
Connection Issue September 15, 2005, 10:11 am

The site map in XML format XML site map

Contact Us | Privacy Policy