<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about sk171375 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155446#M26487</link>
    <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;, what he says makes sense. Just out of curiosity, was there a good reason in the past as to WHY you were using all those other services? Because, at the end of the day, it would use port 21 regardless. Yes, it is true that data connection would start with port 20 initiated by the server, but then whatever is initiated by the client would come on port 21, so sk seems pretty logical.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Aug 2022 16:46:45 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-08-22T16:46:45Z</dc:date>
    <item>
      <title>Question about sk171375</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155007#M26445</link>
      <description>&lt;P&gt;Recently, I'm facing an issue like sk171375 symptom. I'm just curious that the sk explains the cause "This causes an issue where the Security Gateway chooses an incorrect protocol handler to deal with the Passive mode FTP connection:".&lt;/P&gt;&lt;P&gt;What is the order of it? How to select priority when the CP rule configures multiple services on the same port? Or is it dynamic allocation? What is it according to?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 17:00:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155007#M26445</guid>
      <dc:creator>Herschel_Liang</dc:creator>
      <dc:date>2022-08-15T17:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Question about sk171375</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155008#M26446</link>
      <description>&lt;P&gt;I know in the old days of CP (pre R80), this was ALWAYS fixed by one simple trick...change protocol type to "none" in service properties. In R80 and above, that does not exist, its bene replaced with "no item selected". Does it do same thing, I really cant say, as I never had a need to use it, but worth a try. You can create custom service with same port number and try.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 17:24:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155008#M26446</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-15T17:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: Question about sk171375</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155022#M26447</link>
      <description>&lt;P&gt;Maybe something misunderstands. In my case, we configure it as sk171375 previously.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="微信截图_20220816074813.png" style="width: 694px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17433iDE44DD26F15BEAB1/image-size/large?v=v2&amp;amp;px=999" role="button" title="微信截图_20220816074813.png" alt="微信截图_20220816074813.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My question is "how to select which service will be hit when traffic goes through?". Because we configure it as a screenshot for a long time and it works fine. But we face rejecting alerts from last morning. After changing to the sk171375 solution, it works again. But it is a question left, why did it work previously, no change on that rule. How to select which service will be hit when traffic goes through? I'm just curious and &lt;SPAN&gt;just trying to figure out how it works&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 23:57:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155022#M26447</guid>
      <dc:creator>Herschel_Liang</dc:creator>
      <dc:date>2022-08-15T23:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: Question about sk171375</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155024#M26448</link>
      <description>&lt;P&gt;Do you have screenshots of the drops/alerts? If I were you, I would open TAC case to get an official response, but my educated guess is they would most likely tell you to follow the sk and since you said that worked, then there would probably nothing else to try.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 00:53:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155024#M26448</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-16T00:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Question about sk171375</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155033#M26449</link>
      <description>&lt;P&gt;Yes, I have open a TAC case, but it seems that no too depth responce about my question.&lt;/P&gt;&lt;P&gt;===================================================================================================&lt;/P&gt;&lt;P&gt;"Multiple configured FTP services in the same rule allow the connections to the FTP server. This causes an issue where the Security Gateway chooses an incorrect protocol handler to deal with the Passive mode FTP connection". It might work before if the ftp or ftp-pasv service handler was chosen, but you can't control that which service will be chosen by the firewall if you have multiple services with the same tcp port defined.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2022 06:32:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155033#M26449</guid>
      <dc:creator>Herschel_Liang</dc:creator>
      <dc:date>2022-08-16T06:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Question about sk171375</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155438#M26486</link>
      <description>&lt;P&gt;Why would not you use just one FTP service in the rule? The answer from TAC is suggesting just that.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 14:40:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155438#M26486</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-08-22T14:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: Question about sk171375</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155446#M26487</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;, what he says makes sense. Just out of curiosity, was there a good reason in the past as to WHY you were using all those other services? Because, at the end of the day, it would use port 21 regardless. Yes, it is true that data connection would start with port 20 initiated by the server, but then whatever is initiated by the client would come on port 21, so sk seems pretty logical.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 16:46:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-sk171375/m-p/155446#M26487</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-22T16:46:45Z</dc:date>
    </item>
  </channel>
</rss>

