Megamon Tech Blog

IT issues resolved

Modify

/etc/udev/rules.d/70-persistent-net.rules

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk62695&js_peid=P-114a7bc3b09-10006&partition=Advanced&product=Security

Getting this error when Installing event policy?

Installing policy for job [All online jobs]
ERROR: Failed to resolve service name – dns
Error processing Ignore rule (problematic field – ‘service’)
Failed to build correlation policy for event ‘Abnormal activity on service’

Goto

Policy -> Event Policy -> Anomalies -> Abnormal activity on service

Validate all predefined entries are in fact valid.

We had a cause where the third entry was defined as

Replacing this with fixed our issues.

We ping sweep networks every minute – sometimes when pinging firewall clusters a random interface does not respond to icmp requests. This occurs when you ping multiple IP’s of the firewall at the same time.

Checkpoint R71

fw ctl set int fw_allow_simultaneous_ping 1

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk38465

for instructions on how to get the command to survive a reboot

vi $FWDIR/boot/modules/fwkern.conf

fw_allow_simultaneous_ping=1

Symptom: you have internet but MSN ( Messanger ) refuses to load.

Solution: Check the MTU of your desktop and the MTU of your gateway / firewall interfaces.

Why? I Found MTU of 1300 on gateway lead to MSN not loading.