Log In

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips Forums!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!
  • Students Click Here

*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

Posting Guidelines

Promoting, selling, recruiting, coursework and thesis posting is forbidden.

Students Click Here


Extra hop in one direction - causing session problems?

Extra hop in one direction - causing session problems?

Extra hop in one direction - causing session problems?

We have 2 networks - main ( and sub ( - there is a NetScreen 5GT (called INTERFW01) between the two zones (main = work, sub = untrust) and this NetScreen ( acts as the default gateway for the main network.  This netscreen has a default route of which is also a 5GT (called EXTERNALFW02).  This 5GT is then connected to the internet.

However, we're having some problems sessions to the internet being dropped on the main LAN (at least I presume that's what's happening).  Normal web page access is fine, but anything that requires a constant or lengthy connection (eg Remote Desktop, Messenger, large file download) is troublesome - downloads fail, messenger or RDP looses connection and needs to be re-initiated etc etc etc

When traffic from the main LAN goes to the internet, obvioulsy it goes to INTERFW01, then onto EXTERNALFW02 and the onto the internet and it's destination.  However, when traffic returns obviously, it comes back to EXTERNALFW02 and then onto the requesting host on the main LAN - it doesn't need to go back to INTERFW01.  And (at least in my opinion) herein lies the problem.  I've tried changing the settings on the work zone on INTERFW01 to turn off "If TCP non SYS, send RESET back" but this didn't help.

Like I said, my suspision is that this is because by the session response not coming back through the INTERFW01 - but I don't know how to tell the firewall (or which firewall even).  Obviously we've setup an any any policy from work to work on INTERFW01 but we need something else.  Can anybody help with this at all???

Irish Poetry - Karen O'Connor
Irish Poetry and Short Stories - Doghouse Books
Garten und Landschaftsbau

Red Flag This Post

Please let us know here why this post is inappropriate. Reasons such as off-topic, duplicates, flames, illegal, vulgar, or students posting their homework.

Red Flag Submitted

Thank you for helping keep Tek-Tips Forums free from inappropriate posts.
The Tek-Tips staff will check this out and take appropriate action.

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members!

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close