Re: [FW-1] RSA authentication

2005-08-09 Thread cisco4ng
Mine ACE serverr is 5.1. Agent host, in RSA world, is the Checkpoint firewall. You define an agent host in the ACE Server Steven Leow [EMAIL PROTECTED] wrote: My ACE server is 4.1... I think the agent host meaning client right? cisco4ng wrote: ddi you follow the instructions? 1) Create an

[FW-1] License for Secureclient

2005-08-09 Thread Bhavin Gandhi
[Filename: originalmail.eml, Content-Type: multipart/mixed] The attachment file in the message has been removed by eManager. --_=_NextPart_001_01C59CDF.1FA9977F Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable Dear All, =20 Need to know the

[FW-1] VPN question

2005-08-09 Thread Andrey Maluck
Hi all, I'm trying to set up VPN tunnel between NGX and Planet VRT-311 using simplified mode(through VPN community). For both endpoint objects VPN domains are manually defined and they are simple class C networks. After main mode completion in the Tracker appears the message Encryption

[FW-1] Splat NGX, PPPoE and inbound NAT

2005-08-09 Thread Gosset, Vincent
Hi all, I'm testing Splat NGX with a PPPoE internet connection (dynamic IP). Everything is OK for outbound hide-natted communications. For inbound communications (web server - http 80), I'm using inbound NAT using the firewall's IP (see sk11532). But there is a limitation in this setup: I

Re: [FW-1] AW: [FW-1] SecurID Authentication

2005-08-09 Thread Steven Leow
Hi, I keep getting passcode incorrect at the ACE server activity logs... - For the FW rules, any traffic to and fro the FW are accept... - Client in ACE server setup with Cluster IP as primary, member FW as secondary. Have also set the groups (everyone). - sdconf.rec copied over to the FW -

[FW-1] FW-1 web page error message

2005-08-09 Thread Moon, Curtis
I am running R55 on Windows 2003 server with Smart Defense. Sometimes when a user is surfing the web the connection will time out or the firewall will interrupt the web connection and the user will see the message below in their web browser. FW-1 at gatekeeper: Failed to connect to the WWW

[FW-1] AW: [FW-1] AW: [FW-1] SecurID Authentication

2005-08-09 Thread Roos, Boris
Hi Steven, I had nearly the same problem for a long time with NG FP3. The solution was that the firewall could not resolve the name for the ace server and the ace server must also resolve the right IP address of firewall module. Short: It was a DNS (/etc/host) problem. Rgds, boris

Re: [FW-1] How do we get NGX?

2005-08-09 Thread Christopher Hoff
If you want to load SPLAT, you are required to get a CD from Check Point. If you simply want to load a package for another OS, you can download it from Check Point's download site (http://www.checkpoint.com/downloads/index.html). As far as the upgrade tools, the most recent versions are available

Re: [FW-1] Splat NGX, PPPoE and inbound NAT

2005-08-09 Thread Steve Blackman
Hi Vincent, I'm just dropping you a quick email to find out if you would be interested in taking a free look at a new security and protocol testing product we have just released called Traffic IQ Pro? The product has a wide library of different types of network traffic which can be used to

[FW-1] auto neg

2005-08-09 Thread Loge VK
Hi All, Excuse me for me bit off topic here Is there any limitation of making aut neg on while port speed is set to 1000Mbps, I mean if port speed is set to 1000 then should we always have auto neg on to make it work I know cisco allows this config on their switches. any pointers

Re: [FW-1] Checkpoint Express management

2005-08-09 Thread Christopher Hoff
definitely -Original Message- From: Delava Alain [mailto:[EMAIL PROTECTED] Sent: Tuesday, August 09, 2005 4:35 AM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] Checkpoint Express management Hello, Just a small question : is it OK to manage a Checkpoint Express with a

Re: [FW-1] auto neg

2005-08-09 Thread Reinhard Stich
if you have gig interfaces you have to set port speed, physical auto-neg is not possible there. cheers reinhard ))) Message sent using Nokia One Business Server ((( ))) Internet Security AG - www.internet-security.ag ((( --- Original Message --- From: Loge VK [EMAIL PROTECTED] To:

Re: [FW-1] auto neg

2005-08-09 Thread Rick Centner
I've found it always best to force both sides or leave both set to auto. HTH Rick -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Loge VK Sent: Tuesday, August 09, 2005 12:52 PM To:

Re: [FW-1] How do we get NGX?

2005-08-09 Thread Kim Longenbaugh
If you have a Software Subscription with Checkpoint, you can contact their tech support, and they will give you a link to download an image you can use to burn a cd with the latest and greatest versions. -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL

[FW-1] Free Testing Check Point Paper

2005-08-09 Thread Steve Blackman
Hi All, We have just published a paper providing various ways to easily test the following capabilities of Check Point. * Stateful Inspection, ingress and egress filtering * Application Intelligence, baseline test and protocol validation * SmartDefense * Malicious Code Protector Please feel

[FW-1] IP address change?

2005-08-09 Thread Bernard Jen
I am going to change the external ip address for my firewall server. What should I do? I am having NG FP3. Any procedures I can follow? Thank you for answers. Bernard Jen = To set vacation, Out-Of-Office, or away messages, send an email to

Re: [FW-1] Free Testing Check Point Paper

2005-08-09 Thread Jay Taylor
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 This does look like an interesting product but this e-mail seems more of an advertisement for a commercial product than recommended pen-testing practices. Jay Steve Blackman wrote: Hi All, We have just published a paper providing various ways to

[FW-1] Auditing Configuration Changes

2005-08-09 Thread Edward Sohn
Hello, Can someone tell me their procedures for auditing config changes on FW-1 for windows v.4? I need to ensure we track all config changes. Is this information logged by default? Thanks, Ed = To set vacation, Out-Of-Office, or away

Re: [FW-1] Splat NGX, PPPoE and inbound NAT

2005-08-09 Thread Covington, Chris
More of his spam... --- Chris Covington IT Plus One Health Management 75 Maiden Lane Suite 801 NY, NY 10038 646-312-6269 http://www.plusoneactive.com -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Steve Blackman Sent: Tuesday,

Re: [FW-1] Free Testing Check Point Paper

2005-08-09 Thread Covington, Chris
Can someone remove this spammer? --- Chris Covington IT Plus One Health Management 75 Maiden Lane Suite 801 NY, NY 10038 646-312-6269 http://www.plusoneactive.com -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Steve Blackman

Re: [FW-1] auto neg

2005-08-09 Thread Loge VK
Have you ever tried enforcing both sides to be fixed with 1000Mbps speed? some where on net I found that Gig speed on copper needs to be autonegotiated only they say it is as per some 1000BaseT spec didn't got any reference though on 1000BaseT spec On 8/9/05, Rick Centner [EMAIL