Re: [FW-1] backing up Secureplatform Enforcement Modules

2008-01-14 Thread Rick Dipper
have hundreds of firewalls all over the world, so its worth the effort for us. Rick Rick Dipper BT Operate - Global Firewall Lead Engineer +44 (0)208-587-4958 Meet Me Code 27301496# UK : +44 (0) 870 241 2993 0800-032-1608 All non-trivial abstractions, to some degree

[FW-1] Nokia - Getting Started

2008-01-14 Thread Rick Dipper
Folks I have a Nokia IP650 to get working, as this is hardware I have never used have no idea where to start. I have lots of experience with Checkpoint on Sun / Splat. Does anybody have a link to the manufacturers manuals, an hour with Google has not helped. Thanks Rick Scanned by Chec

Re: [FW-1] NG FP3 backup/restore procedure

2007-11-29 Thread Rick Dipper
We image the system & make a bootable CD to reload the image - search google for instructions. The other changes (policy, routing table) are pushed down from the manager. Rick -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Yasa

Re: [FW-1] how to sniff encrypted traffic

2007-11-21 Thread Rick Dipper
Use fw monitor Tcpdump does not always load into the IP stack in the place you expect. Rick -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: 21 November 2007 11:11 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.

Re: [FW-1] default policy

2007-11-16 Thread Rick Dipper
The default policy can be changed, which is worthwhile if you are rolling out lots of firewalls. PhoneBoys book has a worked example. Enjoy Rick -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of cisco4ng Sent: 15 November 200

Re: [FW-1] Rule most used

2007-11-13 Thread Rick Dipper
I'd write a short script to look at the output from fw log -n, and count the usage of rules. This assumes of course you have all rules set to log. Rick -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Edouard Zorrilla Sent: 09 Nove

Re: [FW-1] NGX managment HA and secureclient query!!

2007-11-06 Thread Rick Dipper
It should all work just fine, if the primary fails. With all DR plans, the only way you know it will work for sure is to test it. Rick -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of john maverick Sent: 06 November 2007 03:33 To: