<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Uploading a big file gets interrupted only when connected via Remote Access in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/228041#M43870</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/102202"&gt;@kamilazat&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I agree with what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;indicated. Most likely best to do vpn debugs when issue is happening if turning off TP blades does not help. Though, to me, logically, not sure that will help, if all works fine with those blades enabled otherwise.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 26 Sep 2024 12:33:04 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-09-26T12:33:04Z</dc:date>
    <item>
      <title>Uploading a big file gets interrupted only when connected via Remote Access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/227982#M43857</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;I wasn't sure whether to post this on Remote Access or Threat Prevention, so I'm posting on Security Gateways.&lt;/P&gt;&lt;P&gt;When a remote computer tries to upload a big file (400MB+) to an internal resource without RA VPN, the upload goes perfectly fine. But only when connected via VPN the upload goes until 7-10% and then it gets interrupted.&lt;/P&gt;&lt;P&gt;The traffic goes through a single gateway (no cluster) with version R81.20 JHF T41, and with enabled blades&amp;nbsp;fw vpn cvpn urlf av appi ips identityServer SSL_INSPECT anti_bot.&lt;/P&gt;&lt;P&gt;We already tried looking at logs on SmartConsole and zdebug drop, but neither of them gave us anything. Also checked if Aggressive Aging was at play, but the CPU usage never gets higher than 30%, and everything is set to default 80%.&lt;/P&gt;&lt;P&gt;Currently we're waiting for a maintenance window for testing while turning TP off by fw amw unload command.&lt;/P&gt;&lt;P&gt;Where else can I look if that doesn't help? And why wouldn't I see any logs?&lt;/P&gt;&lt;P&gt;Any ideas would be appreciated.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 06:42:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/227982#M43857</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-09-26T06:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Uploading a big file gets interrupted only when connected via Remote Access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/227994#M43860</link>
      <description>&lt;P&gt;I would debug the vpn tunnel during the upload if excluding this traffic from TP (AV IPS) does not help.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 07:58:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/227994#M43860</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-09-26T07:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: Uploading a big file gets interrupted only when connected via Remote Access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/228034#M43869</link>
      <description>&lt;P&gt;While diagnosis is ongoing worth checking that 3DES / DES isn't enabled and used for Remote Access VPN for both security &amp;amp; performance reasons!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 12:23:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/228034#M43869</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-26T12:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Uploading a big file gets interrupted only when connected via Remote Access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/228041#M43870</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/102202"&gt;@kamilazat&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I agree with what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;indicated. Most likely best to do vpn debugs when issue is happening if turning off TP blades does not help. Though, to me, logically, not sure that will help, if all works fine with those blades enabled otherwise.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 12:33:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/228041#M43870</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-26T12:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: Uploading a big file gets interrupted only when connected via Remote Access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/228059#M43875</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;Thank you for the suggestions!&lt;/P&gt;&lt;P&gt;Update: We have narrowed the problem down to ICAP. The GW is set as ICAP client. When ICAP is turned off, then everything works fine.&lt;/P&gt;&lt;P&gt;Now the question is how does the it handle the differences between normal IPs and Office Mode IPs. There are no such settings in $FWDIR/conf/icap_client_blade_configuration.C file. Or do we also need to all IP ranges including the Office Mode address ranges?&lt;/P&gt;&lt;P&gt;And even if the answer is yes, it's still mysterious how it allows the upload until some percentage, and then drops the traffic.&lt;BR /&gt;&lt;BR /&gt;Additional edit: I think this post would look better in Threat Prevention &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 13:12:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/228059#M43875</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-09-26T13:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Uploading a big file gets interrupted only when connected via Remote Access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/228061#M43876</link>
      <description>&lt;P&gt;How is &lt;CODE&gt;:icap_servers () - :failmode ()&lt;/CODE&gt; set in $FWDIR/conf/icap_client_blade_configuration.C file?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 13:14:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/228061#M43876</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-09-26T13:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: Uploading a big file gets interrupted only when connected via Remote Access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/228065#M43878</link>
      <description>&lt;P&gt;It is open. I'm attaching the file with redacted IPs.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 13:33:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uploading-a-big-file-gets-interrupted-only-when-connected-via/m-p/228065#M43878</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-09-26T13:33:44Z</dc:date>
    </item>
  </channel>
</rss>

