<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint Connect drops due to Malware in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Connect-drops-due-to-Malware/m-p/26622#M602</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Support gave us a R80.10 hotfix for the issue in&amp;nbsp;sk123075 -&amp;nbsp;Anti-Bot is dropping traffic although it is disabled.&lt;/P&gt;&lt;P&gt;We installed this fix today and now we wait to see if it resolves our issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Martijn.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Feb 2019 19:35:17 GMT</pubDate>
    <dc:creator>Martijn</dc:creator>
    <dc:date>2019-02-14T19:35:17Z</dc:date>
    <item>
      <title>Endpoint Connect drops due to Malware</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Connect-drops-due-to-Malware/m-p/26619#M599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our customer is reporting problems with Endpoint Connect. Sometimes users cannot connect to the gateway and&amp;nbsp; sometimes the connection is lost.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is very random because some users can stay connected for more than 5 hours while other users cannot connect at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We ran a 'fw&amp;nbsp; ctl zdebug' and noticed the connection is drop due to Malware. See below, where x.x.x.x is the client and y.y.y.y is the gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw ctl zdebug + drop | grep x.x.x.x&lt;BR /&gt;;[vs_2];[tid_3];[fw4_3];fw_log_drop_ex: Packet proto=6 x.x.x.x:51120 -&amp;gt; y.y.y.y:443 dropped by fw_handle_first_packet Reason: Anti Malware;&lt;BR /&gt;;[vs_2];[tid_3];[fw4_3];fw_log_drop_ex: Packet proto=6 x.x.x.x:51122 -&amp;gt; y.y.y.y.:443 dropped by fw_handle_first_packet Reason: Anti Malware;&lt;BR /&gt;;[vs_2];[tid_3];[fw4_3];fw_log_drop_ex: Packet proto=6 x.x.x.x:51124 -&amp;gt; y.y.y.y:443 dropped by fw_handle_first_packet Reason: Anti Malware;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a case with Check Point and they would like to run a kernel debug. Problem with this is, it causes outage on the network (heavy load on the firewall) and we do not know when the probem occurs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen this before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer is at VSX R80.10 Take 169.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Martijn.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2019 11:37:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Connect-drops-due-to-Malware/m-p/26619#M599</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2019-01-23T11:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Connect drops due to Malware</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Connect-drops-due-to-Malware/m-p/26620#M600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ultimately a debug would be required to see why it is dropping in more detail.&lt;/P&gt;&lt;P&gt;Did you, by chance, try configuring (temporarily maybe) an exception in the relevant Threat Prevention policy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jan 2019 04:36:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Connect-drops-due-to-Malware/m-p/26620#M600</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-26T04:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Connect drops due to Malware</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Connect-drops-due-to-Malware/m-p/26621#M601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, we created an exception in the Threat Prevention policy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the top of the policy we created a rule with a Threat Prevention profile without AV, AB and IPS enabled and as destination the gateway.&lt;/P&gt;&lt;P&gt;This did not solve the problem. In the end, we had to disable AB completely.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe I can replicate the issue in my lab so we do not need to run a debug at the customer. &amp;nbsp;But we have many customers with Endpoint Connect and AB enabled and we do not see any issues there. So the chances are, I cannot replicate it at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And that means a debug at the customer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Martijn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2019 11:26:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Connect-drops-due-to-Malware/m-p/26621#M601</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2019-01-27T11:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Connect drops due to Malware</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Connect-drops-due-to-Malware/m-p/26622#M602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Support gave us a R80.10 hotfix for the issue in&amp;nbsp;sk123075 -&amp;nbsp;Anti-Bot is dropping traffic although it is disabled.&lt;/P&gt;&lt;P&gt;We installed this fix today and now we wait to see if it resolves our issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Martijn.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2019 19:35:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Connect-drops-due-to-Malware/m-p/26622#M602</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2019-02-14T19:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Connect drops due to Malware</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Connect-drops-due-to-Malware/m-p/26623#M603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just an update for this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We installed the hotfix, but I am sorry to say it did not solve our problem.&lt;/P&gt;&lt;P&gt;Sometimes VPN traffic (Endpoint Connect) is still dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer has enabled AB again because it is more important to enable this security feature than people sometimes cannot connect or get disconnected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check Point support is now investigating again. Maybe the fix was not installed correctly (we did not see errors when installing the fix).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep you posted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Martijn.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2019 15:10:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Connect-drops-due-to-Malware/m-p/26623#M603</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2019-03-05T15:10:31Z</dc:date>
    </item>
  </channel>
</rss>

