From: "Previtera, Sal" <[EMAIL PROTECTED]>
Reply-To: Mailing list for discussion of Firewall-1
<[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Beware R55 HFA08!
Date: Fri, 13 Aug 2004 13:30:46 -0500
What about Checkpoint removing HFA08 download from their web site?
....so other Checkpoint customers do not keep on downloading and
compounding
to this problem.
I just checked it and it is still out there....a little common sense would
help.
-----Original Message-----
From: Ray [mailto:[EMAIL PROTECTED]
Sent: Friday, August 13, 2004 11:22 AM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Beware R55 HFA08!
When we hit this problem with HFA07 six weeks ago, I waited ten days for
the
CP tech to do anything other than ask for a cpinfo. I then got an email
from
the tech that he was going on vacation. Meanwhile the calls from employees
were piling up and we still weren't sure if it was a firewall problem or
not.
I called and talked to a supervisor who put someone good on the case. This
person took only a few hours to validate and duplicate what we were seeing
(as opposed to 10 days) and to figure out it was a problem from HFA05 and
later. We were advised the same day I talked to the supervisor to roll back
the gateway to the previous HFA, which was done. We had gone to HFA07
solely
because we were testing Edge boxes, so this wasn't a big deal.
Then the ASN.1 problem came out and this problem wasn't fixed yet. We were
forced to apply HFA08 and re-introduce the problem into our system. We
suffered with it for another ten days before the interim hotfix was
released. We never were told to rollback from HFA08.
It astounds me that Check Point doesn't think disrupting remote access is a
big concern and that customers should discover the problem on their own
after hours of trying to sort through logs after irate employees have been
calling the Help Desk.
How hard would it have been to put a link to this interim hotfix on the
ASN.1 Alert page, or just a note saying if yo have experienced this
problem,
open a support case?
Ray
>From: [EMAIL PROTECTED]
>Reply-To: Mailing list for discussion of Firewall-1
><[EMAIL PROTECTED]>
>To: [EMAIL PROTECTED]
>Subject: Re: [FW-1] Beware R55 HFA08!
>Date: Fri, 13 Aug 2004 08:18:18 -0500
>
>True, but the point of "if it isn't broke don't fix it" really shouldn't
>apply to security.
>Anything that could be a vulnerability, such as a legacy code on a
>firewall, should be
>assessed, audited, and acted on appropriately.
>
>The thing that baffles me the most is that Check Point told one customer
to
>roll back to a previous version,
>yet provided another customer with a fix above HFA08. The emails did
>provide all the information, such as the OS, but
>I would think that with the architecture of FW-1 that it wouldn't matter.
>This gives me worries about communication within CP support.
>
>-Matt
>
>
>
>
>
>
>|---------+-------------------------------------------->
>| | Hal Dorsman <[EMAIL PROTECTED]> |
>| | Sent by: Mailing list for |
>| | discussion of Firewall-1 |
>| | <[EMAIL PROTECTED]|
>| | KPOINT.COM> |
>| | |
>| | |
>| | 08/12/2004 03:58 PM |
>| | Please respond to Mailing list |
>| | for discussion of Firewall-1 |
>| | |
>|---------+-------------------------------------------->
>
>
>---------------------------------------------------------------------------
-------------------|
> |
> |
> | To: [EMAIL PROTECTED]
> |
> | cc:
> |
> | Subject: Re: [FW-1] Beware R55 HFA08!
> |
>
>
>---------------------------------------------------------------------------
-------------------|
>
>
>
>
>An interesting footnote to the 'approach to hotfixes'
>discussion.
>
>Hal
>
> > -----Original Message-----
> > From: Joe Pope [mailto:[EMAIL PROTECTED]
> > Sent: Thursday, August 12, 2004 9:48 AM
> > To: [EMAIL PROTECTED]
> > Subject: [FW-1] Beware R55 HFA08!
> >
> >
> > Warning if use VPN with R55, especially SecuRemote/SecureClient!
> >
> > After upgrading from HFA04 to HFA08 we started having
> > decryption errors (VPN
> > error code 03) with our SecureClient users. Somehow the
> > logged IP address
> > of the VPN Peer Gateway is getting changed (by the firewall) and then
> > decryption fails. It does not affect all SecureClient users
> > at the same
> > time, and after
> > a few hours the problem goes away! I checked my SecureClient while
> > monitoring my firewall logs, and my SecureClient IP address
> > was not being
> > reported
> > in the firewall logs correctly.
> >
> > I submitted a trouble ticket with Check Point and they know about this
> > problem, and they suggested I roll back to HFA04.
> > They said HFA09 is suppose to fix this problem, but no word on when to
> > expect this fix.
> >
> > =================================================
> > To set vacation, Out-Of-Office, or away messages,
> > send an email to [EMAIL PROTECTED]
> > in the BODY of the email add:
> > set fw-1-mailinglist nomail
> > =================================================
> > To unsubscribe from this mailing list,
> > please see the instructions at
> > http://www.checkpoint.com/services/mailing.html
> > =================================================
> > If you have any questions on how to change your
> > subscription options, email
> > [EMAIL PROTECTED]
> > =================================================
> >
>
>=================================================
>To set vacation, Out-Of-Office, or away messages,
>send an email to [EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your
>subscription options, email
>[EMAIL PROTECTED]
>=================================================
>
>=================================================
>To set vacation, Out-Of-Office, or away messages,
>send an email to [EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your
>subscription options, email
>[EMAIL PROTECTED]
>=================================================
_________________________________________________________________
Get ready for school! Find articles, homework help and more in the Back to
School Guide! http://special.msn.com/network/04backtoschool.armx
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================