Well, that experiment failed. I installed SecureClient R56 over the top of
R55 as an update.

The first problem is the new "Extended" view shows the profile name on the
Connect mode dialog instead of the site name as the R55 version did. Perhaps
I should have named my profiles a bit more "user friendly"...

Likewise for the gateway name. Extended View now has a line labeled
"Destination:" and gives the name of the gateway. I named it so it was
deliberately obscure and now our people will have an obscure destination to
contend with. <sigh>

The second problem is that Office Mode is not working. The diagnostics say
"Office Mode  No" and "Assigned IP  Failed" and ipconfig /all confirms that
I am not getting an Office Mode IP from my R55 HFA02 gateway even though it
is checked in the site profile. I use ipassignment.conf to get myself a
specific IP based on my ICA certificate, so I tried an FW-1 user name and
Password but Office Mode still doesn't work. Interestingly I am still
getting DNS and probably WINS information from my internal servers, though,
so it looks like just part of it is broken.

The tray icon has changed significantly and I can no longer ask my users if
they "can see the keyhole in padlock" to verify SCV. They all know that if
they can see the keyhole after they are connected, that's bad. The keyhole
is now visible all the time although there is a tool tip balloon that gives
the needed information.

The tray icon "green dot" that showed you were connected has vanished. It
has been replaced by an "X in a red dot" that says you are not connected.
More training issues.

At least now they have to go through some gyrations to un-check the "use
certificate" box because it's buried. It would be nice if we could disable
that "use dial-up" box since we use iPass (OPSEC certified) and checking
that box causes dial-up and brooadband connectivity to fail.

I can't switch between Extended View and Compact View without deleting the
site, but I can go from Compact to Extended OK. Doesn't make sense, although
i do not have Visitor Mode enabled on the gateway. Maybe that's it.

If you use certificate authentication and enter the wrong password, the
original password is now deleted. If you did this on R55 and FP3, the old
password stayed in the field and you had to manually delete it.
Unfortunately, if you enter the wrong password and click on the "bad
password" dialog box with the mouse, the password field, while blanked,
loses focus. If you press the Enter key on the "bad password" dialog, the
focus does stay in the password field.

I sure hope the SecureClient Packaging Tool gets a major update to handle
this beast. It would be nice to be able to gray out that "use dial-up" box
permanently.

Ray

From: Ray Pesek <[EMAIL PROTECTED]>
Reply-To: Mailing list for discussion of Firewall-1
<[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: [FW-1] New R56 version of SecureRemote/SecureClient available
Date: Wed, 7 Apr 2004 22:03:59 -0400

Just noticed it's posted. The release notes do not show any support for NT
4
or Windows 98 any more.  This thing is very different in its look.

Ray

_________________________________________________________________
Persistent heartburn? Check out Digestive Health & Wellness for information
and advice. http://gerd.msn.com/default.asp

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

_________________________________________________________________ Tax headache? MSN Money provides relief with tax tips, tools, IRS forms and more! http://moneycentral.msn.com/tax/workshop/welcome.asp

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to