recreatable: Checkpoint VPN-1 Edge X fails at passive ftp with 5-series firmware

recreatable: Checkpoint VPN-1 Edge X fails at passive ftp with 5-series firmware

Secure Home | Search | About

Networking Firewalls - Software and hardware firewalls discussions 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
recreatable: Checkpoint VPN-1 Edge X fails at passive ftp with 5-series firmware jorain 03-21-2005
Posted by jorain on March 21, 2005, 11:52 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Last week we experienced a problem which we found to be caused by an
automatic update of our Checkpoint VPN-1 Edge X's firmware.


It was factory-loaded as:
Firmware Version 4.5.39x
Hardware Type SBox-200
Hardware Version 1.0
Installed Product VPN-1 Edge X (Unlimited nodes)



One morning we received the news that all our remote employees were no
longer able to connect to a propriatary 3rd party Voxco-server at the
office.

After some packet sniffing in a recreated environment we found that
this software simply failed at transferring data by passive FTP to the
Voxco-server.

The firewall-rules seemed correct and unaltered.


When we tried to connect from an identical 'remote' client-laptop to
our own ftp-servers (IIS and FreeBSD) both passive and active
connections worked without a problem. Only connecting (passv) to that
specific server failed.


Now the tricky bit : using the same Voxco-client software from within
the LAN posed no problem. So it was not just a problem with that
service !


After quite a bit of systematic troubleshooting, we noticed that the
firmware of our Checkpoint VPN-1 Edge X had been automatically
upgraded to a 5-series firmware.

We did a factory-reset, recreated the exact same firewall rules: and
the problem was gone.


Just to be sure we recreated the problem by upgrading it once more.
And the problem re-appeared.


Conclusion: as soon as we upgrade our device to the latest firmware,
it blocks some (not all) passive FTP-connections, eventhough we set up
correct forwarding rules.




-- jorain


Similar ThreadsPosted
Checkpoint VPN-1 Edge X questions / firmware / traffic August 31, 2005, 11:51 am
Checkpoint FW1/VPN1 training October 19, 2005, 1:01 pm
CheckPoint VPN Edge? January 5, 2005, 8:40 pm
Checkpoint Safe@Office vs. VPN-1 Edge X June 21, 2006, 3:47 pm
HotBrick vs. Passive FTP September 20, 2005, 3:09 pm
Netscreen Passive FTP question September 16, 2005, 9:39 pm
Inbound Passive FTP using IPNAT February 18, 2008, 8:51 am
A L2 Switch between a Active and passive Firewall November 8, 2006, 2:22 am
NGX to VPN-1 Edge layer 2 VPN April 5, 2006, 3:50 pm
Firebox X5 Edge questions November 28, 2004, 6:05 pm

The site map in XML format XML site map

Contact Us | Privacy Policy