Solved

MS Remote Assist does not work to PC behind Nokia IP390 secured with Checkpoint.

Posted on 2007-12-03
3
1,235 Views
Last Modified: 2013-11-16
Hi, I am trying to use Remote Assistance on a group of Windows XP SP1 workstations which are now in a network behind a Nokia IP390 firewall.  This previously worked before the Nokia was implemented.

There is only one entry in the firewall rule base, *any *any *any accept.  This is because we are currently monitoring what traffic is flowing through this gateway.

When trying to remote assist a workstation I get this message "The remote server machine does not exist or is unavailable" and I get one checkpoint accept log entry for epmap followed immediately by a reject entry for epmap, with Attack information of "DCE-RPC Enforcement Violation UUID is not allowed through the Rule Base".

I have edited the Checkpoint Smart Center dcerpc.def and changed "define ALLOW_135 0" to "define ALLOW_135 1" and pushed the policies, but this issue still exists.

Does anyone have any ideas what I can try next?
0
Comment
Question by:nowonmai666
  • 2
3 Comments
 
LVL 14

Expert Comment

by:grimkin
ID: 20407051
HIya,

Do you have SmartDefense running?
0
 

Author Comment

by:nowonmai666
ID: 20409961
Hello

Smart defense has been disabled or set to monitor only where possible.

I found out that the Smart center is running R65 HFA02 but the Nokia IPSO was not.  HFA02 contains a fix where smart defense is still blocking traffic even though it is disabled.  I've patched both Nokia firewalls, just waiting for a suitable time to turn the rule base back on as they are currently only routing traffic.
0
 

Accepted Solution

by:
nowonmai666 earned 0 total points
ID: 21011937
Fixed my problem.  Patched Nokia IPSO to 4.2-Build078,  Checkpoint NGX R65 HFA02.
0

Featured Post

Live: Real-Time Solutions, Start Here

Receive instant 1:1 support from technology experts, using our real-time conversation and whiteboard interface. Your first 5 minutes are always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now