<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rdp slow access between vlans in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10632#M13140</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;for the moment, i've created a policy letting me access windows update at the application level, and it looks fine. i'll keep track of it&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:39:50 GMT</pubDate>
    <dc:creator>lior_me1</dc:creator>
    <dc:date>2019-03-11T11:39:50Z</dc:date>
    <item>
      <title>rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10621#M13129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;problem with rdp access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79841_Capture.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hangs on this window for a minute or two and then connects&lt;/P&gt;&lt;P&gt;any ideas what to look for?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;happens from every computer on a given vlan to another vlan on the checkpoint gaia appliance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 14:55:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10621#M13129</guid>
      <dc:creator>lior_me1</dc:creator>
      <dc:date>2019-03-06T14:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10622#M13130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you see on a tcpdump between the relevant hosts?&lt;/P&gt;&lt;P&gt;Anything in the logs that might suggest what's going on?&lt;/P&gt;&lt;P&gt;This sounds like a DNS issue of some sort that is unrelated to the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Mar 2019 17:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10622#M13130</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-09T17:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10623#M13131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This Sounds like a&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS issue or&lt;/P&gt;&lt;P&gt;RDP encryption issue or&lt;/P&gt;&lt;P&gt;RDP authentication (ntlm vs. kerberos) issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anything in in the Windows event logs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:36:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10623#M13131</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-10T09:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10624#M13132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Or old RDP client and new Windows 2012/2016/2019 Server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:39:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10624#M13132</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-10T09:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10625#M13133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Microsoft Troubleshooting RDP Client connection problems:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://support.microsoft.com/en-us/help/186645/troubleshooting-rdp-client-connection-problems" title="https://support.microsoft.com/en-us/help/186645/troubleshooting-rdp-client-connection-problems"&gt;https://support.microsoft.com/en-us/help/186645/troubleshooting-rdp-client-connection-problems&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:41:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10625#M13133</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-10T09:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10626#M13134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i've narrowed down the issue :&lt;/P&gt;&lt;P&gt;when you try to connect using mstsc, the application tries to contact microsoft's servers. the hang is caused by the firewall trying to process it (i think)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79938_Capture.PNG" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:57:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10626#M13134</guid>
      <dc:creator>lior_me1</dc:creator>
      <dc:date>2019-03-10T10:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10627#M13135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like it is hitting a UserCheck rule of some sort (e.g. the redirect log entries).&lt;/P&gt;&lt;P&gt;You might want to explicitly allow that traffic or create a REJECT (as opposed to drop) rule for it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:34:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10627#M13135</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-10T11:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10628#M13136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;1. the problem is that this ip is a part of a very large pool. cp recognizes it as windows update in the application layer.&lt;/P&gt;&lt;P&gt;2. why reject vs drop? what's the advantage ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:44:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10628#M13136</guid>
      <dc:creator>lior_me1</dc:creator>
      <dc:date>2019-03-10T11:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10629#M13137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With a drop, the application will receive no response and may wait for the attempted TCP connection to timeout.&lt;/P&gt;&lt;P&gt;With a reject, the firewall sends a TCP Reset, which will hopefully cause the application to quit trying to reconnect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2019 15:44:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10629#M13137</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-10T15:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10630#M13138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so, in general (very interesting information), in what cases should i use drop and what cases should i use reject?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2019 15:48:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10630#M13138</guid>
      <dc:creator>lior_me1</dc:creator>
      <dc:date>2019-03-10T15:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10631#M13139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the vast majority of cases, I would use Drop.&lt;/P&gt;&lt;P&gt;Reject is useful in situations similar to what you describe.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2019 16:48:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10631#M13139</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-10T16:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10632#M13140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;for the moment, i've created a policy letting me access windows update at the application level, and it looks fine. i'll keep track of it&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:39:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/10632#M13140</guid>
      <dc:creator>lior_me1</dc:creator>
      <dc:date>2019-03-11T11:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: rdp slow access between vlans</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/47262#M13141</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;the problem seems to be persistent. every few days, some new address pops up&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i've came across addresses like : map2.hwcdn.net, and like 3.a.download.windowsupdate.com and so on and so forth&lt;/P&gt;&lt;P&gt;how can i make the proper exclution for all those url's in a wildcard form? i don't mind handling each domain, but dealing with each ip is crazy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2019 14:38:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/rdp-slow-access-between-vlans/m-p/47262#M13141</guid>
      <dc:creator>lior_me1</dc:creator>
      <dc:date>2019-03-17T14:38:52Z</dc:date>
    </item>
  </channel>
</rss>

