Re: [FW-1] Checkpoint UTM-1 appliances....?

2007-02-21 Thread Ray
One magazine article said the hardware + software cost was the same as the software-only cost, so you were effectively getting the hardware for free. Ray From: sin <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOIN

Re: [FW-1] dbedit

2007-02-21 Thread fwguru
You probably had a corrupted gui_clients file. Try deleting this file and re-creating the gui clients file by executing the "cp_conf client add " The file is located in the $FWDIR/conf dir. HTH, Neil Delacruz On 2/21/07, Paolo Riviello www.paoloriviello.com <[EMAIL PROTECTED]> wrote: Bad f

Re: [FW-1] no logs in smartviewtracker

2007-02-21 Thread pkc_mls
Tauseef Khan a écrit : Hi All I have got a strange problem and wondering is someone there to help me out. I cannot get any log entries in smart view tracker from enforcement module which is a nokia ip 350 ipso 3.9 checkpoint ng r55. I Can telnet management server on any cpmi ports (256, 257, 1819

Re: [FW-1] branch tunnel VPNs between FW-1 and Cisco and Nortel VPNs

2007-02-21 Thread pkc_mls
Kim Longenbaugh a écrit : Hi, We have never utilized the VPN portion of the FW-1 product. hi, 1st : check if you have the proper licences to use the VPN. Now, there's a proposal to do that. Is it possible to set up branch tunnels coming from a Nortel Contivity VPN device and the FW-1, and

Re: [FW-1] dbedit

2007-02-21 Thread Paolo Riviello www.paoloriviello.com
Bad file number This has the following possible causes: A file descriptor did not refer to an open file. A read request was made on a file open only for writing. A write request was made on a file open only for reading. ciao From: Pedro Boavida <[EMAIL PROTECTED]> Reply-To: Mailing li

Re: [FW-1] dbedit

2007-02-21 Thread Paolo Riviello www.paoloriviello.com
so did you try to rebott the system ? you can check out nfile by typing # sar -v 1 5 and try to tune it in etc/system paolo If men could get pregnant, abortion would be a sacrament. (H) From: Pedro Boavida <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1

Re: [FW-1] branch tunnel VPNs between FW-1 and Cisco and Nortel VPNs

2007-02-21 Thread Paolo Riviello www.paoloriviello.com
Off corse take a look to www.cisco.com to see some example. Paolo If men could get pregnant, abortion would be a sacrament. (H) From: Kim Longenbaugh <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Su

Re: [FW-1] no logs in smartviewtracker

2007-02-21 Thread Reinhard Stich
hi, is there a NAT between your mgmt and your module? this can cause problems as you describe it ... br reinhard At 16:11 21.02.2007, you wrote: Hi All I have got a strange problem and wondering is someone there to help me out. I cannot get any log entries in smart view tracker from enforcem

Re: [FW-1] dbedit

2007-02-21 Thread Pedro Boavida
Hi, I wouldn't post on the list if I didn't tried several things before I even tried the following: - Run the upgrade_export utility from NG FP3, installed the NG FP3 management on another platform an run the upgrade_import. I get another error but still cannot log in neither with gui nor wi

Re: [FW-1] dbedit

2007-02-21 Thread Pedro Boavida
Sun SPARC Solaris 8 -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Mark Elsen Sent: quarta-feira, 21 de Fevereiro de 2007 11:14 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] dbedit > Hi, > > I've a strange er

[FW-1] branch tunnel VPNs between FW-1 and Cisco and Nortel VPNs

2007-02-21 Thread Kim Longenbaugh
Hi, We have never utilized the VPN portion of the FW-1 product. Now, there's a proposal to do that. Is it possible to set up branch tunnels coming from a Nortel Contivity VPN device and the FW-1, and from Cisco Pixs to FW-1? The branches all have separate /24 subnets. Of course, I will RTFM on

[FW-1] no logs in smartviewtracker

2007-02-21 Thread Tauseef Khan
Hi All I have got a strange problem and wondering is someone there to help me out. I cannot get any log entries in smart view tracker from enforcement module which is a nokia ip 350 ipso 3.9 checkpoint ng r55. I Can telnet management server on any cpmi ports (256, 257, 18191 etc) from enforcement m

Re: [FW-1] Checkpoint UTM-1 appliances....?

2007-02-21 Thread sin
no-need to-list wrote: > I am familiar with the UTM edge devices low end.has anyone deployed the > high-end of these devices? > > Any comments? they just released them. so far we had no customers requesting any of those appliances, but i'm curious to see what would I gain by buying one of t

[FW-1] Checkpoint UTM-1 appliances....?

2007-02-21 Thread no-need to-list
I am familiar with the UTM edge devices low end.has anyone deployed the high-end of these devices? Any comments? Looking for earth-friendly autos? Browse Top Cars by "Green Rating" at Yahoo! Autos' Green

Re: [FW-1] Edge WLAN to internal network

2007-02-21 Thread Christian ALT
RTFM The answer is that the default policy disables this function. To enable it I had to change the policy to add a rule that allows the trafic from WLAN to LAN. Hope this helps someone else. Christian -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PRO

[FW-1] Edge WLAN to internal network

2007-02-21 Thread Christian ALT
Hi all, Today I have installed an edge device with Wifi integration. In my configuration the WLAN should be able to access the internal LAN. This is not possible and I would like to know if this is by design or if it is possible to change this setting. Thanks Christian ALT Telecom and Logistics

Re: [FW-1] dbedit

2007-02-21 Thread Paolo Riviello www.paoloriviello.com
it should be on unix platform, it looks like if something is going wrong in file descriptors usage, try to restart your management server it could be enough! let us know cheers Paolo From: Mark Elsen <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1

Re: [FW-1] dbedit

2007-02-21 Thread Mark Elsen
Hi, I've a strange error with a CheckPoint NG FP2 Management Center. I cannot log in with the management client even though th client machine is an authorized gui client and the user/pass didn't changed. If I run dbedit, I give right or wrong user credentials and have always the following error

[FW-1] dbedit

2007-02-21 Thread Pedro Boavida
Hi, I've a strange error with a CheckPoint NG FP2 Management Center. I cannot log in with the management client even though th client machine is an authorized gui client and the user/pass didn't changed. If I run dbedit, I give right or wrong user credentials and have always the following error:

Re: [FW-1] change cluster XL load sharing mac address

2007-02-21 Thread Paolo Riviello www.paoloriviello.com
Usually you should disable IGMP snooping and manually add static cam entry into your switch. Cheers Paolo If men could get pregnant, abortion would be a sacrament. (H) From: Hugo van der Kooij <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1

Re: [FW-1] change cluster XL load sharing mac address

2007-02-21 Thread pkc_mls
Hugo van der Kooij a écrit : On Tue, 20 Feb 2007, pkc_mls wrote: I'd like to change the default multicast mac address used for checkpoint cluster interface in Load sharing mode, because my network equipment (Nortel) doesn't accept the 01:00:5e mac address. I can change it manually using dbed