<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.10 Gateway: SecureXL + DCE RPC in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Gateway-SecureXL-DCE-RPC/m-p/12891#M2145</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When SecureXL is enabled some connection/inspection timers are handled a bit differently, not sure if that is related to your problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the meantime, instead of disabling SecureXL completely I'd recommend disabling acceleration for just for the specific IP addresses that are having the DCE/RPC issues.&amp;nbsp; See the following SK for the instructions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" style="max-width: 840px;"&gt;sk104468: How to &lt;STRONG&gt;disable&lt;/STRONG&gt; &lt;STRONG&gt;SecureXL&lt;/STRONG&gt; for specific IP addresses&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While completely disabling SecureXL on a 4-core box like a 5800 won't have a dramatic effect, doing so can be downright disastrous on boxes with more than 8 cores due to the automatic interface affinity function getting disabled along with SecureXL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Apr 2018 22:57:18 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2018-04-04T22:57:18Z</dc:date>
    <item>
      <title>R80.10 Gateway: SecureXL + DCE RPC</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Gateway-SecureXL-DCE-RPC/m-p/12889#M2143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One of my clients recently migrated to R80.10 on brand new 5800s running in high availability.&amp;nbsp; These units replaced some older 12200 units running R77.30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the migration, strange issues with DCE RPC communication began to crop up.&amp;nbsp; The most visible was Outlook fat client running across Endpoint VPN trying to communicate with the Exchange servers.&amp;nbsp; &amp;nbsp;After careful examination, I determined that sometimes the endpoint mapper attempt on port 135 would be permitted (via the special ALL_DCE_RPC service), but the response would be corrupted or possibly dropped (no log evidence other than the 135 connection allowed).&amp;nbsp; About 30% of the attempts would work just fine, the remainder would mysteriously fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I immediately started chasing IPS as a possible culprit, but could not find any logging evidence to blame it and exceptions had absolutely no effect on things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After many hours of troubleshooting, I finally started looking at the acceleration layer.&amp;nbsp; Sure enough, disabling SecureXL caused the this DCE RPC issue to disappear.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOW, I am fully aware that SecureXL combined with DCE RPC communication will defeat acceleration templating, that has been discussed elsewhere and documented.&amp;nbsp; HOWEVER, even with that caveat, it should not disrupt, drop or interfere with the DCE RPC communication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone come across this?&amp;nbsp; Is it a known bug?&amp;nbsp; Are there configuration items I need to visit in the acceleration layer or elsewhere that need to be dealt with?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These gateways are operating on R80.10 Take 70.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2018 21:35:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Gateway-SecureXL-DCE-RPC/m-p/12889#M2143</guid>
      <dc:creator>Egenity</dc:creator>
      <dc:date>2018-04-04T21:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Gateway: SecureXL + DCE RPC</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Gateway-SecureXL-DCE-RPC/m-p/12890#M2144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Disabling SecureXL should never be the solution to a problem.&lt;/P&gt;&lt;P&gt;You should open a TAC case.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://www.checkpoint.com/support-services/contact-support/index.html" title="http://www.checkpoint.com/support-services/contact-support/index.html"&gt;Contact Support | Check Point Software&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2018 22:42:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Gateway-SecureXL-DCE-RPC/m-p/12890#M2144</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-04-04T22:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Gateway: SecureXL + DCE RPC</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Gateway-SecureXL-DCE-RPC/m-p/12891#M2145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When SecureXL is enabled some connection/inspection timers are handled a bit differently, not sure if that is related to your problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the meantime, instead of disabling SecureXL completely I'd recommend disabling acceleration for just for the specific IP addresses that are having the DCE/RPC issues.&amp;nbsp; See the following SK for the instructions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" style="max-width: 840px;"&gt;sk104468: How to &lt;STRONG&gt;disable&lt;/STRONG&gt; &lt;STRONG&gt;SecureXL&lt;/STRONG&gt; for specific IP addresses&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While completely disabling SecureXL on a 4-core box like a 5800 won't have a dramatic effect, doing so can be downright disastrous on boxes with more than 8 cores due to the automatic interface affinity function getting disabled along with SecureXL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Apr 2018 22:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Gateway-SecureXL-DCE-RPC/m-p/12891#M2145</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-04-04T22:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Gateway: SecureXL + DCE RPC</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Gateway-SecureXL-DCE-RPC/m-p/12892#M2146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very good points Tim, thank you!&amp;nbsp; &amp;nbsp;I am not sure how feasible it will be to disable SecureXL for specific IP addresses/ranges, as it is unclear how widespread the problem is.&amp;nbsp; The specific instance of Outlook vs. Exchange was the most reported and visible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch Abernathy&lt;/A&gt;:&amp;nbsp; I will be pursuing a SR on this once I can definitely confirm the issues are truly resolved by turning off SecureXL.&amp;nbsp; &amp;nbsp;I was just soliciting any additional information and/or advice anyone had.&amp;nbsp; Nice to encounter you again, it has been many years!&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2018 19:49:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Gateway-SecureXL-DCE-RPC/m-p/12892#M2146</guid>
      <dc:creator>Egenity</dc:creator>
      <dc:date>2018-04-05T19:49:34Z</dc:date>
    </item>
  </channel>
</rss>

