Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Luis_Miguel_Mig
Advisor

connection persistence

Is there a consensus recommendation about connection persistence?  Keep all connections or rematch connections?
Even though the default value is rematch connections it seems like the recommendation is keep all connections.

Any thought?

https://support.checkpoint.com/results/sk/sk103598

0 Kudos
4 Replies
the_rock
Legend
Legend

I ALWAYS do keep connections. Believe it or not, I had few instances before where VPN tunnel had intermittent issues and that setting was what fixed it. Ironically enough, once with TAC on the phone, I suggested that, everyone was super sceptical, but once it worked, TAC person was also somewhat surprised.

I actually discovered it ages ago totally by coincidence after being on the phone for 8 hours lol

Andy

0 Kudos
Henrik_Noerr1
Advisor

We have 'keep connections' on +400 Virtual Systems - We found that scheduled IPS updates broke various connections, with no easy possibility to troubleshoot..

0 Kudos
Alex-
Advisor
Advisor

We mostly enable it now with all cloud-based services and whatnot which can break when recomputed at policy installation.

 

Some services, like VOIP through the gateways, especially mandate to activate this mode: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_VoIP_AdminGuide/Topics-VOIPG...

0 Kudos
Lesley
Advisor
Advisor

I think there is no good or wrong on this setting.

Maybe one option is more friendly for connections and connectivity and the other option you could consider more 'secure'.

I am a 'Keep all connections' kinda guy. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events