Great Circle Associates Firewalls
(June 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Re[2]: Checkpoint FTP Problem
From: Darren Reed <avalon @ coombs . anu . edu . au>
Date: Wed, 26 Jun 1996 20:07:47 +1000 (EST)
To: Jimmy . Valeriano @ pscmail . ps . net (Jimmy.Valeriano)
Cc: Firewalls @ GreatCircle . COM (Firewalls Mailing List)
In-reply-to: <M759956.001.kjtc0.1.960625183911Z.CC-MAIL*/O=CCMAIL/PRMD=PSC/ADMD=MCI/C=US/@MHS> from "Jimmy.Valeriano" at Jun 25, 96 01:36:00 pm

> > This is a repeat of a question I posted several weeks ago, but I 
> >  have had no satisfactory response from the forum or Checkpoint. 
> >  I cannot believe Checkpoint does not support FTP from a browser 
> >  has anyone got this working throught the AFTPD, this is really
> >  a stupid ommission, our users are asking "Why are we using FW-1" 
> >  if it doesn't support WWW browsers correctly, surely this must
> >  be relatively simple change/upgrade for checkpoint to allow.???
>      
> Dave, et. al. -
> There is a software anomaly in the aftp daemon which causes ftp 
> transfers to behave erratically - terminate abruptly, terminate 
> as if successful after transferring one packet, and so on.
> This is scheduled to be resolved in Checkpoint's release 2.0E, 
> due at some date in the near future.  I do not know why you have 
> had no satisfactory response from Checkpoint - this has been an 
> issue for 6 weeks or so, but I apologize.

This type of problem is going to be present in FW-1 until Checkpoint
realise that SMLI doesn't work unless you recreate all the layers
(which they don't appear to be doing).  i.e. they have to almost create
a proxy before they can provide transparent proxying that is as reliable
and useful as what you'll get in a product such as Gauntlet for services
such as FTP.

The "anomaly" in aftp is not that.  It is just something which highlights
the weaknesses in SMLI as currently used in FW-1.

Darren


Follow-Ups:
References:
Indexed By Date Previous: Fire Walls For Internal Lan
From: "G.S.Anji Reddy" <anji @ OPTIMASW . COM>
Next: Re: LACC: A response from CSI
From: Ian Johnstone-Bryden <ianj-b @ dial . pipex . com>
Indexed By Thread Previous: Re[3]: Checkpoint FTP Problem
From: Brian Murrell <Brian_Murrell @ bctel . net>
Next: Re: Re[2]: Checkpoint FTP Problem
From: Adam Horwitz <adam @ Tripcom . COM>

Google
 
Search Internet Search www.greatcircle.com