the other workaround is to go into the vpn community and remove the remote
firewall from the community.  That way the vpn rule will not take effect
(even when you have implied rules) until you put the remote firewall/vpn
object back inside the vpn community.  

John Markham/NYLIC <[EMAIL PROTECTED]> wrote: You could also try using:

      fw sam -t 7200 -I dst (ip of other side of tunnel)

      The -t is the number of seconds to inhibit the traffic.

      The -I stop all existing and any new connections.

      The dst is the destination.



                                                                           
             Reinhard Stich                                                
             
             -SECURITY.AT>                                              To 
             Sent by: Mailing          [EMAIL PROTECTED] 
             list for                  INT.COM                             
             discussion of                                              cc 
             Firewall-1                                                    
             
             @AMADEUS.US.CHECK         [FW-1] AW:  [FW-1] Temporarily      
             POINT.COM>                disable VPN site to site.           
                                                                           
                                                                           
             08/14/2007 04:20                                              
             AM                                                            
                                                                           
                                                                           
             Please respond to                                             
             Mailing list for                                              
               discussion of                                               
                Firewall-1                                                 
             
             @AMADEUS.US.CHECK                                             
                POINT.COM>                                                 
                                                                           
                                                                           




hello,

you can just disable the rule that allowes traffic within the vpn.

or you can reconfigure the encryption domain temporarely.

br
reinhard

--
Reinhard Stich, Internet Security AG
Mobile email powered by Nokia Intellisync

-----Ursprüngliche Nachricht-----
Von: Gil Hananya
Gesendet: 14.08.2007 10:20:05
An: Gil Hananya;[email protected]
Betreff: [FW-1] Temporarily disable VPN site to site.


Hi,



How can I temporarily disable VPN site to site?

I have VPN site-to-site between two Check Point R55; I need to disable
the VPN for two hours.

How can I do it without delete the rule/VPN?



Thanks Advanced




=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================


       
---------------------------------
Be a better Heartthrob. Get better relationship answers from someone who knows.
Yahoo! Answers - Check it out. 

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to