From: "O'Flynn, Derek" <[EMAIL PROTECTED]>
Reply-To: Mailing list for discussion of Firewall-1
<[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] New ISAKMP Alert - May 4, 2004
Date: Wed, 5 May 2004 12:17:07 -0500
Has anyone tested HFA03 with older SecuRemote/SecuClient? FP3, R54, R55
version. I'm about to update, but have a large FP3, R54 SecuRemote
installed user base I don't want to affect. Of course I'll have to affect
them I guess, but would like to know about it first. It sounds like it's
isolated to the enforcement module and patching them will alleviate the
issue.
Derek
-----Original Message-----
From: Security [mailto:[EMAIL PROTECTED]
Sent: Tuesday, May 04, 2004 10:02 PM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] New ISAKMP Alert - May 4, 2004
it seems to me that what they are saying is that if you have upgraded to
these versions you are ok, I am in need of upgrading the R55 HFA-3.
So if my understanding of what is being said there holds true then the
client versions listed should be safe.
if running a version not listed then you probably are going to have the fun
and joy of pushing a new client
( but that is my assumption)
Good luck
Tom
----- Original Message -----
From: "Ray Pesek" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, May 04, 2004 8:46 PM
Subject: [FW-1] New ISAKMP Alert - May 4, 2004
http://www.checkpoint.com/techsupport/alerts/ike_vpn.html
I'm a little confused by this paragraph:
"Check Point Software customers who do not use Remote Access VPNs or
gateway-to-gateway VPNs, or who have upgraded to current product versions
(VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG FP3 HFA-325, or VPN-1
SecuRemote/SecureClient R56) are NOT affected by this vulnerability."
which references a specific version of SecuRemote/SecureClient, and this
paragraph:
"Check Point knows of no organizations that have had systems affected by
this issue. However, in order to protect VPN-1 Gateways, Check Point
recommends that customers install an update on all enforcement modules."
Does anyone know how the version of SecuRemote/SecureClient fits into all
of
this? I'm reading it as the fix can be applied to either the client OR the
enforcement module and then there is no problem, so patching the
enforcement
module is the preferred method. And hopefully there is no exposure to the
client at all.
Any thoughts?
Ray
_________________________________________________________________
Express yourself with the new version of MSN Messenger! Download today -
it's FREE! http://messenger.msn.com/go/onm00200471ave/direct/01/
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================