• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1254
  • Last Modified:

MS Remote Assist does not work to PC behind Nokia IP390 secured with Checkpoint.

Hi, I am trying to use Remote Assistance on a group of Windows XP SP1 workstations which are now in a network behind a Nokia IP390 firewall.  This previously worked before the Nokia was implemented.

There is only one entry in the firewall rule base, *any *any *any accept.  This is because we are currently monitoring what traffic is flowing through this gateway.

When trying to remote assist a workstation I get this message "The remote server machine does not exist or is unavailable" and I get one checkpoint accept log entry for epmap followed immediately by a reject entry for epmap, with Attack information of "DCE-RPC Enforcement Violation UUID is not allowed through the Rule Base".

I have edited the Checkpoint Smart Center dcerpc.def and changed "define ALLOW_135 0" to "define ALLOW_135 1" and pushed the policies, but this issue still exists.

Does anyone have any ideas what I can try next?
  • 2
1 Solution

Do you have SmartDefense running?
nowonmai666Author Commented:

Smart defense has been disabled or set to monitor only where possible.

I found out that the Smart center is running R65 HFA02 but the Nokia IPSO was not.  HFA02 contains a fix where smart defense is still blocking traffic even though it is disabled.  I've patched both Nokia firewalls, just waiting for a suitable time to turn the rule base back on as they are currently only routing traffic.
nowonmai666Author Commented:
Fixed my problem.  Patched Nokia IPSO to 4.2-Build078,  Checkpoint NGX R65 HFA02.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

KuppingerCole Reviews AlgoSec in Executive Report

Leading analyst firm, KuppingerCole reviews AlgoSec's Security Policy Management Solution, and the security challenges faced by companies today in their Executive View report.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now