<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobile access blade with segfault. in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/126822#M8954</link>
    <description>&lt;P&gt;I agree! Fortunately, we upgraded to kernel 3.10 (R80.30), that is compatible with SMBv2/3. Since &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8012"&gt;@Jenni_Guerrica&lt;/a&gt; is running with 80.40, probably it´s standard for it. IMO, since the user is connected in Portal, the Gaia should keep those connections running up, until the user disconnects (Sign Out) or the reach the interval for reconnection/reauth.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Aug 2021 14:54:52 GMT</pubDate>
    <dc:creator>Dreyfuss</dc:creator>
    <dc:date>2021-08-12T14:54:52Z</dc:date>
    <item>
      <title>Mobile access blade with segfault.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/114354#M8949</link>
      <description>&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;Hi!&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;It seems that I discovered the problem about File Sharing describe in &lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/Mobile-Access-Blade-with-CIFS-segfault/m-p/81873#M3122" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/Mobile-Access-Blade-with-CIFS-segfault/m-p/81873#M3122&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;It turns out that Checkpoint itself is dubious in understanding about compatibility in smbv2 / 3 with version 80.30 (even in kernel 3.10).&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;In one sk CP says it is not compatible, in another CP says it is compatible.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;In my studies, I saw that it was compatible, yes.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;And I started without migrating to version 80.40.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;The heart of the matter is the fact that, for Mobile Access, the default is for the feature to make the connection in SMBv1, according to &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112202" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112202&lt;/A&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;This should not be default, or at least, that this information should be clearer.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;There is also clear confusion regarding the compatibility of version 80.30 and smbv2 / 3.&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;DEFAULT is still SMBv1!!!&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;After applying these settings, I listed the dialect between server and Windows Server:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;XXX.XXX.XXX.XXX/xxx /opt/CPcvpn-R80.30/mnt/cvpn_mnt/ml14 cifs rw,relatime,&lt;EM&gt;&lt;STRONG&gt;vers=3.0&lt;/STRONG&gt;&lt;/EM&gt;,sec=ntlmssp,cache=strict,username=john.doe,domain=XXXXXX,uid=0,noforceuid,gid=0,noforcegid,addr=XXX.XXX.XXX.XXX,file_mode=0755,dir_mode=0755,nounix,mapposix,noperm,rsize=1048576,wsize=1048576,echo_interval=60,actimeo=1 0 0&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="VIiyi"&gt;&lt;SPAN class="JLqJ4b ChMk0b"&gt;&lt;SPAN&gt;In spite of this call to be with the support of Checkpoint of the United States for 365 days (1 YEAR!), no one in CP knows to fix it.&lt;BR /&gt;SR: 6-0001974972&lt;BR /&gt;&lt;BR /&gt;Now I got one more problem: after 2 hours, the mounting simply vanishes from mount location and the user of Mobile Access loses the connection to the share. So, after a re authentication, everything works again. Here we go again.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 11:53:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/114354#M8949</guid>
      <dc:creator>Dreyfuss</dc:creator>
      <dc:date>2021-03-23T11:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile access blade with segfault.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/114679#M8950</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5692"&gt;@AndreiR&lt;/a&gt;&amp;nbsp;any way we can make SMBv3 the default in a future JHF or version?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 01:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/114679#M8950</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-26T01:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile access blade with segfault.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/126588#M8951</link>
      <description>&lt;P&gt;Did you ever get a solution?&amp;nbsp; We are having a similar issue now on R80.40 jumbo 94&lt;/P&gt;&lt;P&gt;[11 Aug 15:47:31] T_event_fdclr_epoll: failed to clear socket: 54 from epoll set: Bad file descriptor&lt;BR /&gt;[11 Aug 15:47:31] T_event_fdclr_epoll: failed to clear socket: 55 from epoll set: Bad file descriptor&lt;BR /&gt;[11 Aug 15:47:31] T_event_fdclr_epoll: failed to clear socket: 56 from epoll set: Bad file descriptor&lt;BR /&gt;[11 Aug 15:47:31] T_event_fdclr_epoll: failed to clear socket: 57 from epoll set: Bad file descriptor&lt;BR /&gt;[11 Aug 15:47:31] T_event_fdclr_epoll: failed to clear socket: 58 from epoll set: Bad file descriptor&lt;BR /&gt;[11 Aug 15:47:31] T_event_fdclr_epoll: failed to clear socket: 59 from epoll set: Bad file descriptor&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 16:06:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/126588#M8951</guid>
      <dc:creator>Jenni_Guerrica</dc:creator>
      <dc:date>2021-08-11T16:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile access blade with segfault.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/126717#M8952</link>
      <description>&lt;P&gt;Hi there!&lt;/P&gt;&lt;P&gt;There are two problems: the first one is solved simply changing the default version on SMB (DEFAULT is v1!) as follows: &lt;EM&gt;cvpnd_settings $CVPNDIR/conf/cvpnd.C set FileShareDefaultSmbVersion "&amp;lt;version&amp;gt;"&lt;BR /&gt;&lt;BR /&gt;The second problem is: after two hours (aprox) the users loses the connection. There´s no answer from TAC, so I made a "gambiarra" (&lt;A href="https://www.urbandictionary.com/define.php?term=Gambiarra" target="_blank"&gt;https://www.urbandictionary.com/define.php?term=Gambiarra&lt;/A&gt;)&lt;BR /&gt;I scheduled a job by crontab (using jobuser) to make a ls (1 minute each) in the /opt/mnt/etc,etc,etc where the mountings are located. So, the Gaia´ OS do not loses the connection with the file server.&lt;BR /&gt;&lt;/EM&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 11:39:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/126717#M8952</guid>
      <dc:creator>Dreyfuss</dc:creator>
      <dc:date>2021-08-12T11:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile access blade with segfault.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/126755#M8953</link>
      <description>&lt;P&gt;Just to be clear, SMBv2/v3 does not work on the Linux 2.6.18 kernel, which was standard prior to R80.40.&lt;BR /&gt;And the fact the connection times out after 2 hours does make some sense since that's the default connection timeout if there is no activity on that connection.&lt;BR /&gt;That "gambiarra" is one way to keep those connections active. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 14:34:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/126755#M8953</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-12T14:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile access blade with segfault.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/126822#M8954</link>
      <description>&lt;P&gt;I agree! Fortunately, we upgraded to kernel 3.10 (R80.30), that is compatible with SMBv2/3. Since &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8012"&gt;@Jenni_Guerrica&lt;/a&gt; is running with 80.40, probably it´s standard for it. IMO, since the user is connected in Portal, the Gaia should keep those connections running up, until the user disconnects (Sign Out) or the reach the interval for reconnection/reauth.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 14:54:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-access-blade-with-segfault/m-p/126822#M8954</guid>
      <dc:creator>Dreyfuss</dc:creator>
      <dc:date>2021-08-12T14:54:52Z</dc:date>
    </item>
  </channel>
</rss>

