Re: [FW-1] Firewall-1 failure after applying Solaris patches.

2005-08-29 Thread Rajeev Gupta
Hmmm.. I wonder if you will ever get any repsonse from Check Point or Sun? Check Point will go with your results and say ok if that be it, that is what it is. I had R54 or R55 attempts to install on Solaris 9 last week - hfa's did not matter - it continued to core in case I had the

Re: [FW-1] smartcenter question

2005-08-29 Thread Mauricio Munoz
You can limit the tracker´s users privileges by creating a Profile (this can be done when you add an Administrator within the GUI) restricting the options to Log And Monitoring (even with Read/Only option). I hope this helps, Mauricio F. Muñoz Quevedo Security Consultant Este correo y

Re: [FW-1] Question on memory usage for Nokia firewalls

2005-08-29 Thread Quick, Richard A.
I had this same question and posed it to Nokia. I'm running an IP530 with 256 RAM on NGAI R55 HFA_03 at the time. Here is the info that nokia sent me. Dear Rick Quick, Unfortunately there isn't a guide or chart that will show how much RAM will be used based on the number of users or

[FW-1] dhcp relay thru NGX

2005-08-29 Thread Steffen
Hi, I want to relay dhcp requests and replies through NGX on IPSO. I enabled the bootp relay options in Voyager but regardless what rules I set up in dashboard I see drops by the cleanup rule logged. Has anybody an idea how I can enable dhcp relaying? thx Steffen

Re: [FW-1] dhcp relay thru NGX

2005-08-29 Thread Tony Pombo
Turn on BOOTP relay, then follow CheckPoint Solution ID = sk17887 --- Tony Pombo Systems and Security Architect Edict Systems, Inc. 937-429-4288 x279 [EMAIL PROTECTED] -Original Message- From: Mailing list for discussion of Firewall-1

[FW-1] VLANs

2005-08-29 Thread Jørn Dahl-Stamnes
A quick question about adding VLANs to a FW-1. Currently I'm not using any VLAN on a FW-1 (SPLAT R54), but I plan to add 1 or two more networks to the firewall. Since I got a HP ProCurve Switch connected to the FW, I which to set up a VLAN interface on one or two of the interfaces. Today,

[FW-1] VRRP AA-VPN

2005-08-29 Thread Loge VK
Hi, I was wondering whether anybody tried S2S VPN between a remote GW and local Cluster running VRRP AA (opsec) mode. Can we actually achieve load sharing via configuring a vpn with AA mode? Since in AA we define some hosts to use one member of AA as gateway and others for second member, how will

[FW-1] Smartview Reporter and Nokia

2005-08-29 Thread James Jones
Hi there, does anyone know how to add just the smartview reporter add on to the Smartcenter on a Nokia which is a standalone installation ? I have a separate server for the Smartview Reporter Server, and I can only see Smartview Reporter as an option, not just the add on part as other

Re: [FW-1] Firewall-1 failure after applying Solaris patches.

2005-08-29 Thread Simon Ashford
BUT: all the best practice advice I've seen recommends to keep all critical systems fully patched with O/S and other software updates. This was the reason for using the Patch Manager utility in the first place. Also, presumably there will come a time when the version of Solaris distributed with

Re: [FW-1] VRRP AA-VPN

2005-08-29 Thread Reinhard Stich
hi, if you say VRRP AA your mean vrrp actice-actice? if you want active-active you should use nokia IP clustering, not VRRP ... cheers reinhard At 20:50 29.08.2005, you wrote: Hi, I was wondering whether anybody tried S2S VPN between a remote GW and local Cluster running VRRP AA (opsec)

Re: [FW-1] Problem with a WebServer

2005-08-29 Thread Diego F. Lastra S.
The WebServer is a IIS and it's running Microsoft Sharepoint as the application server. The guys at Microsoft told us that is impossible to change the way cookies are sent in binary to the web clients. Is there any other workaround for this problem? Thanks... -Mensaje original- De:

Re: [FW-1] Problem with a WebServer

2005-08-29 Thread Ray
Ahhh, Microsoft, no wonder. :-) What version of FW-1 are you on? I can set that binary feature off on R55. Ray From: Diego F. Lastra S. [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To:

Re: [FW-1] Problem with a WebServer

2005-08-29 Thread Crist Clark
Diego F. Lastra S. wrote: The WebServer is a IIS and it's running Microsoft Sharepoint as the application server. The guys at Microsoft told us that is impossible to change the way cookies are sent in binary to the web clients. Is there any other workaround for this problem? Thanks...

Re: [FW-1] Problem with a WebServer

2005-08-29 Thread Diego F. Lastra S.
SPLAT: This is Check Point VPN-1(TM) FireWall-1(R) NG with Application Intelligence (R55) HFA_09, Hotfix 182 - Build 011 Ray, thanks for your help. -Mensaje original- De: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] En nombre de Ray Enviado el: Monday, August 29,

[FW-1] Check Point Enhanced Alert Functions

2005-08-29 Thread Chris McGill
Hi, I am currently running Check Point NGX (R60), on IPSO 3.9. What I wish to achieve is connect a MODEM into the IP330 (dial-out only) and find some OPSEC or Linux paging software I can use on the box, to page me when a serious alert is tripped. I know this would be easy to do with SNMP or

Re: [FW-1] Check Point Enhanced Alert Functions

2005-08-29 Thread ravi pina
not sure what OPSEC has to do with anything... perhaps you mean open source? never the less, http://www.hylafax.org/ is a package i used 10 years ago. it was simple to setup then so i can't imagine how simple it is to run now. the problem you're going to run into is getting a binary to run