[FW-1] Multi-processor configuration

2006-05-17 Thread William Iselin
I need to know if and how Check Point can be assigned a specific CPU in multi-processor machines. The firewall in question is NG FP3. SecureKnowledge says that with NG FP3 there is support for Multi-CPU and that you can set it to use only one CPU, but I couldnt find anything regarding using a sp

[FW-1] Connection Persistence

2004-11-10 Thread William Iselin
I have found that some firewalls' properties have the "connection persistence" field under the Advanced tab while others do not (NG AI R55 HFA 08). Does anyone know why this might be? The only thing I can think of is licensing, but what feature would that fall under? I've looked at many installe

Re: [FW-1] Proxy ARP not working with manual NAT with Secure Platform NG AI R55

2004-10-07 Thread William Iselin
ECTED] Subject: Re: [FW-1] Proxy ARP not working with manual NAT with Secure Platform NG AI R55 I have done both from the every beginning of destination client side and automatic arp configuration, but not seem to be working. Cheers, Phil -Original Message- From: William Iselin [mailto:[

Re: [FW-1] HIDE nat problem

2004-10-06 Thread William Iselin
what have you done to troubleshoot the issue so far? You should check if proxy arp is configured properly for the nat IP, check the smarview tracker to see if translation is showing up there, finally do a tcpdump if necessary to see what IP is going out the external interface. Regards, Bill -

Re: [FW-1] Proxy ARP not working with manual NAT with Secure Platform NG AI R55

2004-10-06 Thread William Iselin
You don't need to add manual arp entries. Go into Global Properties -> NAT and make sure the defaults are selected, which is all of them (but the 'automatic arp configuration' is what's important here). It will create arps for both automatic nat and manual nat. HTH, Bill -Original Message

Re: [FW-1] Secureclient failed to update Site but can connect to firewall

2004-10-06 Thread William Iselin
It might be that the Policy Server isn't running. If that's the case you should be able to manually start it. cprestart should also start it but you don't want to have to do that on a production firewall if you don't have to. Bill -Original Message- From: dogbert [mailto:[EMAIL PROTECTE

Re: [FW-1] SecureRemote not Assigning an IP to client

2004-10-05 Thread William Iselin
You need SecureClient, not SecuRemote. Also you need to use Office Mode to actually assign the client itself an IP address. IP pool nat only translates the clients IP at the gateway. Regards, Bill -Original Message- From: Brian Hope [mailto:[EMAIL PROTECTED] Sent: Tuesday, October 05, 200

[FW-1] policy push fails if more than 44 firewalls chosen

2004-09-30 Thread William Iselin
Has anyone seen this before? CP R55 HFA 09 mgmt. When installing to all modules, the push fails. Trying to push to various firewalls in various numbers, we found out that it doesn't matter which firewalls are chosen, but if more than 44 are chosen it fails. The failure seems to be only a probl