[FW-1] FW-1 and Asterisk PBX

2006-09-25 Thread Markus Hauke
Hi there, I've just configured an Asterisk PBX with some SIP-Phones connected to it on the LAN and an ISDN link. So far everything is working fine. But now I've tried to connect the PBX to an external SIP provider (sipgate.de in this case) through my VPN-1 NGX R61. I configured static NAT for

Re: [FW-1] Connecting Clustered firewalls to two cisco ports?

2006-09-25 Thread Fabrice Barutel
Hi, If your customer wants to have high availability, then he needs two switches or hub between router and the two firewalls (each firewall is on a different switch/Hub). Switches are connected with two links (crossover cables for example). At the end, the last "point of failure" could be the rout

Re: [FW-1] FW-1 and Asterisk PBX

2006-09-25 Thread cisco4ng
This will NOT work as long as your local sip proxy is behind a checkpoint firewall, Juniper/NetScreen or Cisco Pix firewall. These vendors claim to be "sip" compliant; however, it is not a guarantee thing. For this to work properly, you would need something like Session Border Controller

Re: [FW-1] exclude CP firewall from the encryption domain in VPN simplfied mode

2006-09-25 Thread cisco4ng
Scott, Thanks for the info. The checkpoint sk ID sk25675. That being said, I performed "cpstop" on both the Active and Standby SmartCenter and edit the $FWDIR/lib/user.def file with vi editor. I performed "cpstart" on both the Active and Standby SmartCenter after that. The problem

Re: [FW-1] High Availability VRRP Outgoing traffic behavior

2006-09-25 Thread Lino Eduardo Avila Rodríguez
Well First of all, I should say or you use cluster xl or you use vrrp, I think that your problem resides there. I've never seen this configuration and I don't think is correct at all. Try using only vrrp. And verify if everything is working fine. Best regards lino -Original Message- F

Re: [FW-1] High Availability VRRP Outgoing traffic behavior

2006-09-25 Thread Pedro Boavida
Hi, This is a very common scenario when you want to have vrrp and state sync. In such scenario ClusterXL is only used for state synchronization. Best regards, Pedro Boavida -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Lino

Re: [FW-1] IPSO 4.x and Checkpoint NGx combination explaination needed

2006-09-25 Thread no-need to-list
Neither DOES Microsoft.but we still buy their products...Dont we? The software companies need to be responsible of the software they put on in the market...just like manufacturingso we can sue the hell of them. Maybe, just maybe after that, they would do a lot more quality assura

[FW-1] Need help on upgrading

2006-09-25 Thread Clive Luk
Hi Guru, I want to ask if there is a easy method to do a management server upgrade? Actually I want to move all configuration and license from a piece of old hardware to a new hardware. Anything I need to pay attention? Thanks in advance! Cheers, Clive =

Re: [FW-1] exclude CP firewall from the encryption domain in VPN simplfied mode

2006-09-25 Thread Joseph Carlo C. Quiambao
Accept ICMP requests: before last ? On 9/24/06, cisco4ng <[EMAIL PROTECTED]> wrote: LAN_A---(i)Pix(o)---Internet---(Ext)CP_FW(Int)---LAN_B I have a site-to-site VPN between Cisco Pix and Checkpoint Firewall NGx. Traffics are encrypted bewtween LAN_A and VLAN_B without any NAT translation.

Re: [FW-1] Need help on upgrading

2006-09-25 Thread Mark Elsen
Hi Guru, I want to ask if there is a easy method to do a management server upgrade? Actually I want to move all configuration and license from a piece of old hardware to a new hardware. Anything I need to pay attention? Open a command prompt window : > cd %FWDIR%\bin\upgrade_tools