Mar 23

One of the features I use often, and especially in cases when there is some sort of trouble, is the ability to actually see what traffic passes the firewall.

Most admins don’t feel comfortable using the console (over ssh), and ofcourse it is not as trivial as it seems – especially remembering the exact commands. So, for the community, and for my own personal use, I’ll document a small issue I just had, and how I “solved” it.

A customer called, saying: I use the StoneGate VPN to connect to my server with RDP, and all I get is a black screen”.  Now, that’s something that’s (unfortunately) not too uncommon. Google for “MTU”, “Path MTU Discovery” and “Black Hole Detection”, and you’ll get tons of info, which all come down to:

Single packets in ethernet networks have a maximum size of 1500 bytes (RFC 879). 1460 bytes of data + 40 bytes header (ip-addresses, ports, settings etc.). All tunneling protocols (VPN, PPTP,PPPoE, etc.) add some bytes to the header part. This means less room for the data part.

Both “client” and “server”  agree to send packets with max. 1460 bytes of data. The first few packets of the connection aren’t large, perhaps 1000 bytes max, and fit through perfectly. Client and server agree to communicate, draw a frame of the correct size, etc. Then however, comes the Windows Logo, a picture that is over 3000 bytes of size.  That means,  2  large packets are sent.  Somewhere on the connection from server to client, these packets do not fit. So, the picture the server sent, does not reach the client. A black screen of the wanted size just sits there, and waits… and waits…. and waits…..

Since I do not want to discuss what causes this,  but just want to know if it IS an MTU issue, I do following:

  • check if both sides agree to use 1460 bytes of data
  • reduce the packet size on either client or server side to 1310 bytes of data
  • test whether RDP works again

Continue reading »

written by jebATpop-i - 1,584 views \\ tags: , , ,

Jul 29

SMC videos: Enabling Third Party Monitoring

SMC -
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...
No Comments »
This video demonstrates how to take StoneGate Third Party Monitoring features into use. Click the video below to see how you can assign Probing, Logging and Tools Profiles for hosts and routers in StoneGate Management Center 5.0.

align=”left”

This was the last SMC video article by far. Note that all videos are stored in Videos section of StoneBlog Community.

written by teroja - 535 views \\ tags: , , , , ,

Jul 27

SMC videos: Logging Profiles

SMC -
1 Star2 Stars3 Stars4 Stars5 Stars (2 votes, average: 5.00 out of 5)
Loading ... Loading ...
No Comments »
As already explained in this article, you can easily create logging profiles that defines how the syslog that is sent by some third party device is displayed in StoneGate’s Log Browser. This video shows the whole process of creating a new logging profile from scratch.

align=”left”

Remember that you can share your logging profiles in Files section of StoneBlog Community.

written by teroja - 567 views \\ tags: , , , , ,

Jul 24

SMC videos: Third Party Monitoring

SMC -
1 Star2 Stars3 Stars4 Stars5 Stars (2 votes, average: 5.00 out of 5)
Loading ... Loading ...
No Comments »
With StoneGate Management Center 5.0 you can now monitor also your third party devices such as critical servers, routers and firewalls from other vendors. StoneGate’s Third Party Event Management features allows you to monitor the status of device, receive the logs from the device in StoneGate Log Browser, create statistics and reports based on the third party log data and customize commands for the elements’ right-click menu.

See the video below to see how you can monitor your third party devices with StoneGate Management Center.

align=”left”

written by teroja - 497 views \\ tags: , , , , ,

Jul 22

SMC videos: Other Policy Enhancements

SMC -
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
No Comments »
We have recently added many other enhancements in policy editor that makes your daily administration tasks more efficient than ever. The video below introduces some of these policy enhancements such as Undo & Redo and Rule Comment Sections.

align=”left”

written by teroja - 485 views \\ tags: , , , , ,

Jul 20

SMC videos: Create Rules from Logs

SMC -
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 4.00 out of 5)
Loading ... Loading ...
No Comments »
StoneGate’s policies and logs are tightly linked. There are many shortcuts how to move from logs to corresponding rule in the policy and vice versa. The latest addition on this side is that you can now create new rules based on selected log entries. See the example video below about how to create rules from Logs with StoneGate Management Center.

align=”left”

written by teroja - 565 views \\ tags: , , , , ,

Jul 17

SMC videos: Rule Counters

SMC -
1 Star2 Stars3 Stars4 Stars5 Stars (2 votes, average: 5.00 out of 5)
Loading ... Loading ...
No Comments »
The Rule Counters is one of the coolest features of StoneGate Management Center 5.0. This new feature allows you to check how many times each rule in the policy has matched within specified time period. This information is directly available in the policy editor. You can find the unused rules with a couple of clicks and clean up your policies to better reflect the actual information flow. Rule counters are a convenient tool also in troubleshooting tasks.

See the video below to find out how rule counters work in practice.

align=”left”

written by teroja - 585 views \\ tags: , , , , ,

Jul 15

SMC videos: Role Based Access Control

SMC -
1 Star2 Stars3 Stars4 Stars5 Stars (2 votes, average: 3.00 out of 5)
Loading ... Loading ...
No Comments »
The video below gives an practical example how you can restrict administrator’s permissions with the help of Administrator Roles, Access Control Lists and Domains. Note that if you use domains, you can create administrator accounts either in Shared Domain (for administrators that have access to multiple domains) or in any subdomain (when administrator needs access only to that spesific domain).

align=”left”

written by teroja - 547 views \\ tags: , , , , ,

Jul 13

SMC videos: Domains

SMC -
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 4.00 out of 5)
Loading ... Loading ...
No Comments »
StoneGate’s Domains solution gives excellent tools for managing large environments. You can simplify the environments by dividing them to separated domains. At the same time you can still share the common elements like policy templates by keeping them in “Shared Domain”. The Domains are especially useful for Managed Security Service Providers but also large enterprises may find Domains useful when there is need to simplify the environments and divide administrators’ responsibilities.

Have a look at the video below to find out what are Domains all about.

align=”left”

written by teroja - 445 views \\ tags: , , , , ,

Jul 10

SMC videos: Enabling Web Portal

SMC -
1 Star2 Stars3 Stars4 Stars5 Stars (2 votes, average: 5.00 out of 5)
Loading ... Loading ...
No Comments »
The video below gives a practical example how to configure the Web Portal Server properties and how to restrict the access for Web Portal Users.

align=”left”

written by teroja - 477 views \\ tags: , , , , ,