Secure Gateway Users may be Disconnected by CheckPoint Firewall
Secure Gateway Users may be Disconnected by CheckPoint Firewall Secure Gateway Users may be Disconnected by CheckPoint Firewall
Citrix states in their article: CTX103563
CTX103563 - Secure Gateway Users may be Disconnected by CheckPoint Firewall
This document was published at: http://support.citrix.com/kb/entry.jspa?externalID=CTX103563
Document ID: CTX103563, Created on: Mar 11, 2004, Updated: Mar 12, 2004
Products: Secure Gateway for MetaFrame 2.0, Citrix Secure Gateway 1.0, Citrix Secure Gateway 1.1
Symptoms
When Secure Gateway is deployed behind a CheckPoint firewall with the SmartDefense HTTP Worm Catcher feature enabled, users are occasionally disconnected from their ICA session. Bypassing the CheckPoint firewall resolves the issue.
Cause
The CheckPoint SmartDefense setting includes an HTTP worm catcher feature that interferes with Secure Gateway traffic. Traffic to the Secure Gateway server is not always HTTPS traffic, but the CheckPoint firewall treats all traffic on port 443 as HTTPS traffic.
Resolution
Disable the HTTP Worm Catcher SmartDefense feature for SSL connections through the CheckPoint firewall. First, select SmartDefense from the CheckPoint Policy menu.

Then, clear the checkbox for HTTP > General HTTP Worm Catcher.

Under the HTTPS service property, change the Protocol type from HTTP to None.

Status
CheckPoint technical support has acknowledged that this is an issue with the SmartDefense feature.
User login
Who's new
- maczugaher
- locksgydff
- isotheces
- ahundredyears7
- Jacomijntjefu