Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Daniel_Kavan
Advisor

keepalive on Endpoint Security

The user upgraded to E88.50 and we are still seeing the issue.  ICMP pings from his PC or router to the gateway.   Is there some kind of keepalive ping check on Endpoint Security I can have him uncheck?   We are trying to figure out what's sending pings back to the remote access gateway (which are dropped) dest-unreach (ICMP).  We don't allow ping.

0 Kudos
1 Reply
the_rock
Legend
Legend

Yes, there is and it actually has absolutely zero to do with endpoint version. Its in global properties and its refered to below.

Hope that helps.

Best,

Andy

 

http://downloads.checkpoint.com/dc/download.htm?ID=60345

 

To configure tunnel idleness:

1. Connect to the Security Management Server with GuiDBedit.

2. Open the Global Properties > properties > firewall_properties object.

3. Find disconnect_on_idle and these parameters:

  • do_not_check_idleness_on_icmp_packets

  • do_not_check_idleness_on_these_services - Enter the port numbers for the services that you want to ignore when idleness is checked.

  • enable_disconnect_on_idle - to enable the feature

  • idle_timeout_in_minutes

4. Save and install the policy.

 

Btw, there is ping option there you can change, so if user is somewhat savvy, they can always keep pinging say google dns in cmd and tunnel will NEVER time out, though its supposed to say after 60 mins (just as an example)

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events