[FW-1] Hacker 'handshake' hole found in common firewalls - but not CP!

2011-04-13 Thread Ray
Good job, Check Point! http://www.networkworld.com/news/2011/041211-hacker-exploit-firewalls.html NSS Labs independently tested the Check Point Power-1 11065, the Cisco ASA 5585-40, the Fortinet Fortigate 3950, the Juniper SRX 5800, the Palo Alto Networks PA-4020, and the SonicWall NSA E8500.

[FW-1] RES: [FW-1] Cluster SPLAT - Hardware problems - Replace servers

2011-04-13 Thread Gustavo Rocha de Andrade
Hi list, If there is a level 3 hardware between the smart center and the clusters, do not forget to clear the arp table of level 3 hardware or you could not be able to install the policy. regards Gustavo Andrade Analista de Segurança da Informação Pl True Access Consulting S/A Fone: (61) 3217

Re: [FW-1] Cluster SPLAT - Hardware problems - Replace servers

2011-04-13 Thread Eugeniu Patrascu
On Wed, Apr 13, 2011 at 18:31, Leandro Vilela wrote: > Hy list, > I'm having a cluster that SPLAT with hardware problems. > I purchased two new servers and need to replace equipment. I did the > settings of the new servers identical to the former but not the policies > yet. The idea is to simply u

[FW-1] Cluster SPLAT - Hardware problems - Replace servers

2011-04-13 Thread Leandro Vilela
Hy list, I'm having a cluster that SPLAT with hardware problems. I purchased two new servers and need to replace equipment. I did the settings of the new servers identical to the former but not the policies yet. The idea is to simply unplug the old cluster, reconnect the new servers with same IP an

[FW-1] Odp: Re: [FW-1] Delay on shell prompt

2011-04-13 Thread Zbigniew Jakubowski
Hi there, Not using DNS is a mojor problem like not taking care of proper time keeping. Of course you can solve this problem like this thread is suggesting but I would still opt for propper DNS name resolving. Cheers Z. Jakubowski = To set va

[FW-1] force proxy id for an ipsec tunnel

2011-04-13 Thread pkc mls
Hi all, Is there a way to force the proxy IDs checkpoint will use for a dedicated tunnel ? I'd like to specify a shorter network for a vpn with a remote part, due to overlapping. (10.10.0.0/16 -> 10.10.2.0/24). but other tunnels use 10.10.0.0/16 already and tunnels ends up to the same vpn