Well, that experiment failed. I installed SecureClient R56 over the top of R55 as an update.
The first problem is the new "Extended" view shows the profile name on the Connect mode dialog instead of the site name as the R55 version did. Perhaps I should have named my profiles a bit more "user friendly"...
Likewise for the gateway name. Extended View now has a line labeled "Destination:" and gives the name of the gateway. I named it so it was deliberately obscure and now our people will have an obscure destination to contend with. <sigh>
The second problem is that Office Mode is not working. The diagnostics say "Office Mode No" and "Assigned IP Failed" and ipconfig /all confirms that I am not getting an Office Mode IP from my R55 HFA02 gateway even though it is checked in the site profile. I use ipassignment.conf to get myself a specific IP based on my ICA certificate, so I tried an FW-1 user name and Password but Office Mode still doesn't work. Interestingly I am still getting DNS and probably WINS information from my internal servers, though, so it looks like just part of it is broken.
The tray icon has changed significantly and I can no longer ask my users if they "can see the keyhole in padlock" to verify SCV. They all know that if they can see the keyhole after they are connected, that's bad. The keyhole is now visible all the time although there is a tool tip balloon that gives the needed information.
The tray icon "green dot" that showed you were connected has vanished. It has been replaced by an "X in a red dot" that says you are not connected. More training issues.
At least now they have to go through some gyrations to un-check the "use certificate" box because it's buried. It would be nice if we could disable that "use dial-up" box since we use iPass (OPSEC certified) and checking that box causes dial-up and brooadband connectivity to fail.
I can't switch between Extended View and Compact View without deleting the site, but I can go from Compact to Extended OK. Doesn't make sense, although i do not have Visitor Mode enabled on the gateway. Maybe that's it.
If you use certificate authentication and enter the wrong password, the original password is now deleted. If you did this on R55 and FP3, the old password stayed in the field and you had to manually delete it. Unfortunately, if you enter the wrong password and click on the "bad password" dialog box with the mouse, the password field, while blanked, loses focus. If you press the Enter key on the "bad password" dialog, the focus does stay in the password field.
I sure hope the SecureClient Packaging Tool gets a major update to handle this beast. It would be nice to be able to gray out that "use dial-up" box permanently.
Ray
From: Ray Pesek <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1 <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: [FW-1] New R56 version of SecureRemote/SecureClient available Date: Wed, 7 Apr 2004 22:03:59 -0400
Just noticed it's posted. The release notes do not show any support for NT 4 or Windows 98 any more. This thing is very different in its look.
Ray
_________________________________________________________________ Persistent heartburn? Check out Digestive Health & Wellness for information and advice. http://gerd.msn.com/default.asp
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
_________________________________________________________________ Tax headache? MSN Money provides relief with tax tips, tools, IRS forms and more! http://moneycentral.msn.com/tax/workshop/welcome.asp
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
