[FW-1] R: [FW-1] Connect Control

2005-10-12 Thread Lorenzo
I have an enterprise license and a connect control license; I installed it as a central one in the management via smart update, but if i issue manually In.lhttpd (I guess this is the command) I get a no license Error; if I install the license on one nnode I don't get this error (still it doesn't

[FW-1] Error [cpshared: test : argument expected]

2005-10-12 Thread Alex Simbun
Hi there, I noticed when I boot up or reboot the firewall services, I saw these line appeared: /opt/CPshrd-R55/bin/cpshared: test: argument expected Can somebody enlighten me about this? Anyway, the firewall startup normally without any problem. Thanks

Re: [FW-1] Office Mode SecureClient

2005-10-12 Thread cp user
Hi Ray, Does your firewall object have the external IP or the internal IP? It has to be the external IP. Yes, my firewall object has the external IP. If it works with hub mode, that tells me it's a routing issue. SecureClient doesn't know how to find the policy server until it's

Re: [FW-1] Security Servers

2005-10-12 Thread Hal Dorsman
If your cpu is still running 100% and in.httpd is eating up all your resources, you need to kill it immediately. It is unnecessary if your are not using security server as far as I know. Hal -Original Message- From: Lino Eduardo Avila Rodríguez [mailto:[EMAIL PROTECTED] Sent: Tuesday,

Re: [FW-1] ISP backup

2005-10-12 Thread Loge VK
it all depends which kind of option u have used u can configure some IP which when becomes unreachable from ISP1 will cause the failover to ISP2 or u can configure to switch based on router's reachability factor On 10/11/05, Michael Schwartzkopff [EMAIL PROTECTED] wrote: Hi, We

[FW-1] SMARTClient

2005-10-12 Thread Ray282828
The administrator of our IP330 has left. I need to install the SMARTClient to configure the Check Point VPN-1/Firewall-1 NG Feature Pack 3 on Nokia IP330. As I am new to Check Point, can someone point me out where I can download this software and any administration guide. Thanks, Ray

Re: [FW-1] Nortel Alteon w/ Check Point

2005-10-12 Thread Loge VK
they are good they have 5100 series which are relatively low-end boxes and 6600/6400 series are high-end ... it all depends where do u want to use them high-end r more suited more data-center or ISP kind of operations... for enterprise use 5100 series is OK. they have new series boxes

Re: [FW-1] SecuRemote on Internal Network

2005-10-12 Thread John Lindblom
The property is set to false and a Site Update doesn't change it, It still doesn't work if we manually change it. Do we need the internal network in the ENC_DOMAIN for this to work or is this setting suppose to work without?

Re: [FW-1] Nortel Alteon w/ Check Point[Scanned]

2005-10-12 Thread Loge VK
I guess it was in their 2.2.7.0 http://2.2.7.0/ release 2.3.1 release is quite stable btw what kind of problems u had been facing On 10/3/05, Tauseef Khan [EMAIL PROTECTED] wrote: I have run that in on alteon switched firewall in High availability. It gave us a lot of problems. I

[FW-1] Edge W 32

2005-10-12 Thread Jeremy Lieb
Does anyone on the list know if the Edge W Appliance is supported with R55? I'm in the process of purchasing one and have found no information on whether it can be used in R55 or if NGX is required. When creating an Embedded profile there is no option for Edge W in the Type field. I assume that is

[FW-1] Upgrade_export/import

2005-10-12 Thread Tony Montesano
Just a quick ? Can I run upgrade_import multiple times on a box? I am attempting to test a migration from Sun to SPLAT for the Management box and just wanted to know if I can just rerun the upgrade_export then upgrade_import to refresh the data on the new box for testing? I've run it once and

Re: [FW-1] Upgrade_export/import

2005-10-12 Thread Kim Longenbaugh
yes -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Tony Montesano Sent: Wednesday, October 12, 2005 10:38 AM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] Upgrade_export/import Just a quick ? Can I run

[FW-1] Nev's new email address

2005-10-12 Thread Neil Kemp
fyi [EMAIL PROTECTED] = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail = To unsubscribe from this

Re: [FW-1] Upgrade_export/import

2005-10-12 Thread Tony Montesano
Thanks. I'll give it a try. Kim Longenbaugh [EMAIL PROTECTED] INGS.COM

[FW-1] OSPF and NG AI

2005-10-12 Thread Joe
I would like to enable OSPF and add 2 weighted static routes pointing the traffic to two routers. After the new area will be created under OSPF option, where can I add weighted static routes? Thanks Joe

[FW-1] SmartDefense drops on 99444

2005-10-12 Thread Shane Presley
I'm getting SmartDefense drops on rule 99444. This should be legitimate traffic between a windows server and our domain controller. Do you know which SmartDefense trigger is causing this? Thanks Shane = To set vacation, Out-Of-Office, or away

Re: [FW-1] OSPF and NG AI

2005-10-12 Thread David S. Barker
Joe, You have to say which operating system you are using.. David S. Barker Senior Security Engineer Compuquip Technologies Phone: 305.436.7272 X 1364 Fax: 305.436.9149 mailto://[EMAIL PROTECTED] 8399 NW 30th Terr, Miami, Fl 33122 Compuquip TECHNOLOGIES Providing Solutions Since 1980

Re: [FW-1] SecuRemote on Internal Network

2005-10-12 Thread David S. Barker
John, What version of Secure Client are you using? Do you have a desktop policy that could be blocking this? This property shouldn't be affected by your encryption domain, only that you have the box checked or not. David S. Barker Senior Security Engineer Compuquip Technologies Phone:

Re: [FW-1] Security Servers

2005-10-12 Thread David S. Barker
Lino, The HTTP Security server is used with many different things, some Smart Defense HTTP settings require it. As does manual auth to port 900, partially automatic http auth, and of course URI resources. If you want to disable it you can edit the fwauthd.conf on the module in the

Re: [FW-1] vpn trouble

2005-10-12 Thread David S. Barker
Are these managed by the same smart center or different smart centers? i.e. one of them is externally managed. If you have these as externally managed, verify that all of the timeouts are the same on both ends. If this is done already, the follow the instructions I referenced for setting

Re: [FW-1] When does nat occur? after routing right?

2005-10-12 Thread David S. Barker
Jacob, This changes on whether you have client side or destination side nat set.. You can view the fw chain, by doing a fw ctl chain You can verify a packet's life yourself using fw monitor with the -p all switch to see it live. see

Re: [FW-1] When does nat occur? after routing right?

2005-10-12 Thread Bhavin Gandhi
Yes NAT would happen after routing processing by outbound kernel. I assume pkt originates from internal host. Cheers, BG -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] Behalf Of jacob c Sent: Wednesday, October 12, 2005 1:05 AM To: