Re: [FW-1] objects_5.0.C file and database revision control

2007-03-02 Thread Rajeev Gupta
You can still edit objects_5_0.C file manually using vi or other edit tools. There are couple of things that one has to be careful while doing manual edit: 1. back up existing file (the file format is such that during edits/cut/pastes/deletion, one can end up deleting some bit more leading to fil

Re: [FW-1] objects_5.0.C file and database revision control

2007-03-02 Thread Reinhard Stich
hi, you still _can_ use any editor (like vi) to modify the objects_5_0.C file, but (as it was in 4.1) you have to be very careful. so you _should_ use the dbedit-tool ... br reinhard At 15:35 02.03.2007, you wrote: Hi everyone, Can someone confirm this for me? In Checkpoint 4.1, one can m

Re: [FW-1] objects_5.0.C file and database revision control

2007-03-02 Thread Gary Scott
I think I have tweaked the objects file to one extent or another in almost every version including fp-3. I think too guidbedit was introduced as a safer way to edit the objects and other files. -GS -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED

Re: [FW-1] telnet timeout : tcp packet out of state

2007-03-02 Thread Pedro Boavida
Hi, Is the telnet the only service you have defined for tcp/23 ? Once the tcp session is established, I believe there are no different timeouts for each kind of subsequent packet. Best regards, PB -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTE

[FW-1] objects_5.0.C file and database revision control

2007-03-02 Thread cisco4ng
Hi everyone, Can someone confirm this for me? In Checkpoint 4.1, one can modify the objects.C file because there is NO database revision control mechanism so this practice is acceptable in checkpoint version 4.1 In checkpoint NG Feature Pack 3, NG with AI R55(w) and NGx R60/R61/R62, one can NO

Re: [FW-1] telnet timeout : tcp packet out of state

2007-03-02 Thread Matthias Leu
pkc_mls wrote: > Hi all, > > If I allow the telnet and let a telnet window open without typing > anything within, I have a timeout after > some minutes. > > smartview tracker shows the following : > Type: Log > Action: Drop > Protocol: tcp > Service: t

Re: [FW-1] telnet timeout : tcp packet out of state

2007-03-02 Thread pkc_mls
Matthias Leu a écrit : Hi, you can adapt the timeout per service. Have a look at the object representing the service and select 'Advanced'. Here you can chose an individual timeout for e.g. telnet. Hope it helps, best regards, Matthias I already tried to modify the timeout for telnet, without

[FW-1] telnet timeout : tcp packet out of state

2007-03-02 Thread pkc_mls
Hi all, If I allow the telnet and let a telnet window open without typing anything within, I have a timeout after some minutes. smartview tracker shows the following : Type: Log Action: Drop Protocol: tcp Service: telnet (23) Information: TCP pa

[FW-1] Smart host SMTP delayed response on port 25.

2007-03-02 Thread
Dear ALL, We are using Check Point firewall gateway NGX alongwith its VPN module, there are about more than 800 mail users. I used to receive all internet bound emails on firewall (which acts as smart host) and later firewall sends it to my mail server which is resided inside the internal lan (ov

[FW-1] Ha: [FW-1] Just noticed error on policy push

2007-03-02 Thread Artyom S. Davidov
Hi Ken! We've also encountered this error some time ago. It looks like that there is some limitation exists on a number of SmartDefense and Web Intelligence protections that could be enabled simultaneously. The easiest way to solve this error is to disable some of the unnecassary in your case S