It depends.  David is right about version 4.0, but in version 4.1, you would
need to install the policy again.  I belive the version 4.1 actually creates
explicit "implied" rules to allow the IPs in the gui-client file to remote
manage the firewall.

Christopher Lee
Sr. System Engineer, CNE, MCSE, CCSE, NSP, CCNA
FutureLink Canada Corp., formerly Charon Systems Inc.
Tel: (416) 503-1100 x8284
PGP FingerPrint: 
B94A 2298 DF6C 65D4 65EF  7724 A863 82D8 9836 052F

> -----Original Message-----
> From: David C. Diemer [mailto:[EMAIL PROTECTED]]
> Sent: October 30, 2000 1:06 PM
> To: [EMAIL PROTECTED]; [EMAIL PROTECTED]
> Subject: Re: [FW1] Editing Gui-Clients file
> 
> 
> 
> No.  Changes are immediate since the FW daemon seems to check
> the file on each access to FW resources.
> 
> 
> David C. Diemer, CCSA, CNE
> Enterprise Security Firewall Engineer
> Georgia Department of Administrative Services (DOAS)
> [EMAIL PROTECTED]
> 404.651.9677
> 
> >>> "Roland Moss" <[EMAIL PROTECTED]> 10/30/00 11:27AM >>>
> 
> 
> 
> When I edit the gui-client file on the firewall manager, do I 
> need to do a
> fwstop before I make the change???
> 
> Thanks...  Roland
> 
> 
> 
> 
> ==============================================================
> ==================
>      To unsubscribe from this mailing list, please see the 
> instructions at
>                http://www.checkpoint.com/services/mailing.html 
> ==============================================================
> ==================
> 
> 
> 
> ==============================================================
> ==================
>      To unsubscribe from this mailing list, please see the 
> instructions at
>                http://www.checkpoint.com/services/mailing.html
> ==============================================================
> ==================
> 


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to