<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabling Smart Connection Reuse in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-Smart-Connection-Reuse/m-p/151006#M24586</link>
    <description>&lt;P&gt;It really depends on the environment.&lt;BR /&gt;Which is why you test it with the temporary "fix" as mentioned in the SK, only putting it to fwkern.conf after you've verified it doesn't cause undesirable side effects.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jun 2022 21:09:26 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-06-15T21:09:26Z</dc:date>
    <item>
      <title>Disabling Smart Connection Reuse</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-Smart-Connection-Reuse/m-p/151002#M24585</link>
      <description>&lt;P&gt;Good evening,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd like to know what the impact would be if I was to disable the Smart Connection Reuse mechanism on our corporate gateways. I am investigating an issue with our NFS mounts "hanging" when there is an interruption to the connection and the following&amp;nbsp;&lt;A href="https://www.suse.com/support/kb/doc/?id=000019722" target="_blank" rel="noopener"&gt;article&lt;/A&gt;&amp;nbsp;explains the exact issue we're experiencing and seems to point the finger at Smart Connection Reuse functionality as the culprit (as does this old&amp;nbsp;&lt;A href="https://www.cpug.org/forums/showthread.php/19664-smart-connection-reuse-NFS-%28maybe-AIX-flavored-NFS%29" target="_self"&gt;CPUG&lt;/A&gt;&amp;nbsp;article).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my troubleshooting efforts, I'd like to disable this mechanism and see if it "resolves" the issue. I'm reluctant to do so without knowing what the potential impact might.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've search the Support Portal and found SK24960. It mentions that disabling feature will treat&amp;nbsp;&lt;SPAN&gt;TCP [SYN] packets on established connections as out of state. How much of an issue/impact is this likely to be in a production environment?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Aaron.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 20:34:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-Smart-Connection-Reuse/m-p/151002#M24585</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-06-15T20:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Smart Connection Reuse</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-Smart-Connection-Reuse/m-p/151006#M24586</link>
      <description>&lt;P&gt;It really depends on the environment.&lt;BR /&gt;Which is why you test it with the temporary "fix" as mentioned in the SK, only putting it to fwkern.conf after you've verified it doesn't cause undesirable side effects.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 21:09:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-Smart-Connection-Reuse/m-p/151006#M24586</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-15T21:09:26Z</dc:date>
    </item>
  </channel>
</rss>

