[FW-1] Policy/routebased routing

2013-11-06 Thread a bv
Hi, On my R70 SPLAT , we added a new interface with a new (and second for the box) real ip which is connected to an other isp. I would like to configure a network block/clients traffic pass by/to the new isp, not the old default gateway. Other old networks flow as is, through the old isp. How can

Re: [FW-1] Need for a sk content

2013-10-02 Thread a bv
; and GAiA up to R75.40 or so didn't include the right version of the igb > driver, so you need to download it. Newer versions (R76 / R77) have the > updated driver built-in. > > > On Wed, Oct 2, 2013 at 9:59 AM, a bv wrote: > > > Hi, > > > > Im trying to in

[FW-1] Need for a sk content

2013-10-02 Thread a bv
Hi, Im trying to install a network adapter on SPLAT and my tries bring me to below sk but i dont have an active access so please someone can provide me the contents of the sk please? Regards https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid

Re: [FW-1] Seperating standalone to distrubed

2013-06-12 Thread a bv
2013/6/11 pkc_mls > Le 11/06/2013 13:31, a bv a écrit : > > Hi, >> How can i seperate standalone R70 and further SPLAT installations to >> gateway and management >> modules (especially gateway stands alone at the current hardware, >> management will reinstall

[FW-1] Seperating standalone to distrubed

2013-06-11 Thread a bv
Hi, How can i seperate standalone R70 and further SPLAT installations to gateway and management modules (especially gateway stands alone at the current hardware, management will reinstalled at virtual machine etc?) what must be the steps? And what to be carefull Regards ==

[FW-1] smartviewmonitor time

2013-06-07 Thread a bv
Hi, After a reboot on R70 , when i look at the counters at the smartview monitor and choose since system installed i only see the start from current month and year Why i cant see the past? regards = To set vacation, Out-Of-Office, or away messag

Re: [FW-1] Some problems unidentified

2013-06-04 Thread a bv
ies look in capacity optimization) -- the problem description has > all the classic earmarks of it. I'd wager that the gateway is still > configured with the default 25K connections. > > > On Tue, Jun 4, 2013 at 2:56 AM, a bv wrote: > > > Hi, > > > > On a

[FW-1] Some problems unidentified

2013-06-04 Thread a bv
Hi, On a R70 SPLAT standalone enviroment the near time cases: 1. People/clients started to be unable to resolve DNS addresses from the enterprise. Its said to be that no change or something else done at internal dns servers but im not sure. 2. after 2 week from below case ites reported that at

Re: [FW-1] High wa at vmstat

2013-04-24 Thread a bv
Hi, Any idea about how to find out to reason and fix it? iostat command seem doesnt exit on SPLAT Regards 2013/4/16 a bv > Hi, > > On a SPLAT firewall which somethings took so long I ran vmstat 1 10 and > get the below. It seems that wa has high values. How can i found out the

[FW-1] High wa at vmstat

2013-04-16 Thread a bv
Hi, On a SPLAT firewall which somethings took so long I ran vmstat 1 10 and get the below. It seems that wa has high values. How can i found out the reason and fix it? Regards vmstat 1 10 procs ---memory-- ---swap-- -io --system-- -cpu-

[FW-1] error at /var/log/messages

2013-04-15 Thread a bv
*Hi, * *I saw new entries at R70 SPLAT /var/log/mesaages like below but knowledgebase didnt help to found out yet to understand the reason and what does this mean.? * *Any idea about the error (especially understanding it not only fix). * *Regards * * FW-1: opq_state_set: number of entries in st

Re: [FW-1] Smart-1 consololidation error

2013-03-08 Thread a bv
distribution or copying of this message is > strictly prohibited and sanctioned by law. If you receive this message by > error, please immediately send it back and delete the message received. > > -Original Message- > From: Mailing list for discussion of Firewall-1 > [mailto:FW-1-MAILIN

Re: [FW-1] Policy installation really slow on R70

2013-03-07 Thread a bv
gt; The hot fix reference is as follows hotfix fox_hf_ha40_031 > > Might be worth a query!! > > -Original Message- > From: Mailing list for discussion of Firewall-1 > [mailto:FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM] On Behalf Of a bv > Sent: 22 January 2013 15:11 > To: FW-

[FW-1] sending data (cpinfo etc ) to checkpoint

2013-03-05 Thread a bv
Hi, whats your policy , or opinion of sending data of your gateways/prdoucts to checkpoint? There are lots of things to be solved by opening case, but is it ok to send cpinfo for your point of security? Regards = To set vacation, Out-Of-Office, or

[FW-1] Choosing open server or appliance for firewall

2013-03-01 Thread a bv
Hi, Nowadays i find some Checkpoints performance reporting scripts from checkpoint support site but they run mostly at the versions below R71 etc which doesnt fit for me. I wanna ask the list how do you select your next appliance or server which will run your Checkpoint firewalls? Regards

Re: [FW-1] Smart-1 consololidation error

2013-02-28 Thread a bv
This didnt worked from the initial configuration of the appliance , i nevre created a successful condolidation seesion 2013/2/28, pkc_mls : > Le 28/02/2013 15:04, a bv a écrit : >> Hi, >> >> I have a R70.30 smart 1 box configured long time . and that time couldnt >>

[FW-1] Smart-1 consololidation error

2013-02-28 Thread a bv
Hi, I have a R70.30 smart 1 box configured long time . and that time couldnt create a consolidastion seesion on evenntia reporter and use the appliance. I tried again to create a consolidation error and get the error "Failed to get the default parameters from server/database". How can i fix this?

Re: [FW-1] GAIA cluster policy installation problem

2013-02-28 Thread a bv
I also added 3rd network adapters 2013/2/28 a bv : > Hi, > > I found use state syncronization status check box on cluster > properties and unchecked it and then try to installa the policy but it > still didnt worked > > 2013/2/28 a bv : >> thanks how can i do that? >

Re: [FW-1] GAIA cluster policy installation problem

2013-02-27 Thread a bv
Hi, I found use state syncronization status check box on cluster properties and unchecked it and then try to installa the policy but it still didnt worked 2013/2/28 a bv : > thanks how can i do that? > > 2013/2/28 Reinhard Stich : >> hi, >> >> are you sure you set 2 in

Re: [FW-1] GAIA cluster policy installation problem

2013-02-27 Thread a bv
thanks how can i do that? 2013/2/28 Reinhard Stich : > hi, > > are you sure you set 2 interfaces to "cluster"? just disable "state sync" > for the test ... > > br > reinhard > > > At 23:29 27.02.2013, you wrote: >> >> Hi, >> >> I have downloaded and setup an R76 cluster with 1 management and 2 >>

[FW-1] GAIA cluster policy installation problem

2013-02-27 Thread a bv
Hi, I have downloaded and setup an R76 cluster with 1 management and 2 gateways on vmware. all machines have 2 virtual adapters which are on 2 virtual host only networks. I have created the cluster and established the trust. at the cluster properties i tried to set eth0 and eth1 intrerfaces with I

Re: [FW-1] Performance pack and usage limitations

2013-02-21 Thread a bv
and do you know if there are plans to break the limitaions of performance pack usage like qos etc. ? Regards 2013/2/21 a bv : > Hi, > > I wanna ask if you deploy Perfromance pack on your firewalls , at what > conditions , do you gain performance really and if so how can you &

[FW-1] Performance pack and usage limitations

2013-02-21 Thread a bv
Hi, I wanna ask if you deploy Perfromance pack on your firewalls , at what conditions , do you gain performance really and if so how can you monitor and calculate? Regards = To set vacation, Out-Of-Office, or away messages, send an email to lists..

Re: [FW-1] Enabling SecureXL,Corexl etc modules on GAIA

2013-02-19 Thread a bv
also the performance pack 2013/2/19 a bv : > Hi, > > It seems that webbased initial setup of GAIA doesnt give the option to > choose the modules SecureXL, Corexl etc. And after opening the web > based management i didnt saw releated entries, and sysconfig also > doents see

[FW-1] Enabling SecureXL,Corexl etc modules on GAIA

2013-02-19 Thread a bv
Hi, It seems that webbased initial setup of GAIA doesnt give the option to choose the modules SecureXL, Corexl etc. And after opening the web based management i didnt saw releated entries, and sysconfig also doents seem to work on shell (expert mode too). How can i enable/disable these modes and

[FW-1] SPLAT user (admin) password policy

2013-02-15 Thread a bv
Hi, I couldnt find the password policy /compelixity of the SPLAT in checkpoint support site or on console etc. CAn you share it? id like to give screenshot about it regards = To set vacation, Out-Of-Office, or away messages, send an email to lists

[FW-1] Cluster- what to expect

2013-02-05 Thread a bv
Hi, Havent been working on Checkpoint Cluster , im trying the reinvent the wheel for me. How and why to deploy cluster? What benefits and what problems i have to wait? Howmust i personally prepare for it (knowledge, troubleshooting etc). And will 2 gateway machines as gateway and 2 management serv

[FW-1] Policy installation really slow on R70

2013-01-22 Thread a bv
Hi, On a R70 SPLAT the policy installation is slow , sometimes it takes so many minutes too install the policy how can i find out the reason and fix it? Regards = To set vacation, Out-Of-Office, or away messages, send an email to lists...@amadeus.u

[FW-1] Uptime

2013-01-17 Thread a bv
Hi, I ran the uptime command on R70 SPLAT after a long time and saw that it says 1 day and etc . also i looked at the smartview monitor that it says 2 days . I looked at /var/log/secure file and only saw my username which normally im the only admin. Also tried to look at /var/log/messages and like

[FW-1] Load on memory error again and again

2012-11-14 Thread a bv
Hi, On an R70 SPLAT these days i started to get the load on memory error and fail again the policy installation fails. I tried many times again and again but couldnt done via Smartdashboard . I found a new sk on CP support and read there and edited the grub.conf file to increase the vmalloc parame

[FW-1] TCP packet out of state: First packet isn't SYN tcp_flags: RST

2012-11-13 Thread a bv
Hi, On a standalone R70 SPLAT i see TCP packet out of state: First packet isn't SYN tcp_flags: RST log entries. And an user whos IP has many logs like below and also green pass logs says that he cant see the most images on sites like facebook etc . The logs are not at the IPS log side at the fire

[FW-1] Support issues and case opening

2012-10-10 Thread a bv
Hi, What must the way to open a case when you are renewing yearly at Checkpoint? When you try to open a case they close it nearly immediatly and reports and says that open the case through a partner. When you return to partners they sometime say that we have to a new support aggreement with them

Re: [FW-1] Policy installation takes too long

2012-10-04 Thread a bv
Hi, Its already disabled at Global properties. It maybe nice to take cpinfo and sombe debug and submit to Checkpoint within a case maybe but the support choices gives headache you gotta get help from partner to open case etc. Regards 2012/9/28 pkc_mls : > Le 28/09/2012 9:34, a bv a éc

Re: [FW-1] Policy installation takes too long

2012-09-28 Thread a bv
change or hotfix to fix this? Regards 2012/9/25 a bv : > I deleted 3-4 unused policy package from the gateway which were there > more tahn 4 years , there are still come DBrevision which i usually > find the path and move it the releated folders to an other folder. But > still it t

Re: [FW-1] Policy installation takes too long

2012-09-25 Thread a bv
-Original Message- >> From: Mailing list for discussion of Firewall-1 >> [mailto:FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM] On Behalf Of a bv >> Sent: Thursday, September 13, 2012 1:45 AM >> To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM >> Subject: [FW-1] Policy

[FW-1] Policy installation takes too long

2012-09-13 Thread a bv
Hi, On SPLAT R70 generally it takes too much time to policy install. What can be the reasons , how to find out the reasone and fix it? how to improve it? Also sometimes get load on memory fail error Regards = To set vacation, Out-Of-Office, or awa

[FW-1] IPS syncronization between standalone gateways

2012-09-11 Thread a bv
Hi, I would like to syncronize IPS policy between 2 standalone SPLATS. 1 is R70 other is 75.20 for now. R70 is the production one and the other is its backup and mostly offline. Whta ways will you offer to update the signatures and syncronize the IPS policies between them for both operations and

Re: [FW-1] Policy installation error

2012-09-03 Thread a bv
Cyber 51. Can i have comments and recommandations about these titled trainings? Regards 2012/9/3 pkc_mls : > Le 27/08/2012 10:24, a bv a écrit : > >> I have created an object and a rule thats all, After i get the error >> and try a little i removed the rule (not the object) and

[FW-1] Cluster and ips

2012-09-03 Thread a bv
Hi, What configurations are syncronized in clusters? Are IPS signatures and profiles/policies are synconrized without an exception? Regards = To set vacation, Out-Of-Office, or away messages, send an email to lists...@amadeus.us.checkpoint.com in

Re: [FW-1] Policy installation error

2012-08-27 Thread a bv
[FW-1] Policy installation error > > Do you modified the name of a Object (host, group, etc..)? this error is > related when you wrote a special character on it, for example: ´ ' ! , etc.. > when the fw cant compile the policy with this and get the memory error. > > > &

Re: [FW-1] Preventing facebook, youtube etc access

2012-08-06 Thread a bv
Yes i know but if dont have them (at least for now) Regards 2012/8/6 Independent IT Consultant : > APP Control / URL Filtering is designed for this. IPS isn't. > > On Mon, Aug 6, 2012 at 8:30 AM, a bv wrote: > >> Hi, >> >> How can we block facebook youtub

[FW-1] Preventing facebook, youtube etc access

2012-08-06 Thread a bv
Hi, How can we block facebook youtube twitter etc access from our SPLAT with IPS to some users which some also have direct http https access generally? Is there a security rule can help? (overlapping?) . Couldnt see builtin ips signature , is a custom header rejection or something else can be w

[FW-1] Policy installation error

2012-07-31 Thread a bv
Hi, >From yesterday i started to get error load on memory error and cant install policy on R70 SPLAT. My search brings me the idea to check for the non-English characters in comments etc but i couldnt found out anyone with my eye . Any suggestion to find out and fix the issue? (urgent need) Rega

Re: [FW-1] Detecting and preventing reverse shell connections

2012-07-30 Thread a bv
Will the SSH over non-Standart protocols protection on IPS will be enough to dedect and block the reverse shells? Regards 2012/4/10 a bv : > Hi, > > How can we detect and prevent reverse ssh shell connections with > Checkpoint FW-1 ? With IPS, Application Control etc? Either the

Re: [FW-1] R75.20 listening on port 80

2012-07-26 Thread a bv
I have found below article Tried to do second solution couldnt test form external interface but still from LAN interface port 80 responds http://my-it-memo.blogspot.com/2011/12/checkpoint-r75-new-feature-violated-pci.html 2012/7/25 a bv : > Hi, > > I have tried to do a port s

[FW-1] R75.20 listening on port 80

2012-07-25 Thread a bv
Hi, I have tried to do a port scan to my offline R75.20 SPLATs DMZ IP with a cross connected laptop and get a resut that port 80 is open. Also tried to telnet to LAN interfaces IP to port 80 and and connection opened. Tried to use get commands with telnet and netcat but couldnt get results . Then

Re: [FW-1] Changing IPsec SAs and IKE SAs

2012-07-19 Thread a bv
Yes my firewall will but what about my peer /remote fw will it accept the new negotiation and will the tunnels will be up? Regards 2012/7/19 pkc_mls : > Le 18/07/2012 1:12, a bv a écrit : > >> Or deleting IKE and IPSec key from the firewall, then trying a >> connection t

Re: [FW-1] Changing IPsec SAs and IKE SAs

2012-07-18 Thread a bv
Or deleting IKE and IPSec key from the firewall, then trying a connection through vpn will it trigger the remote/peer firewall to clear its releated key table , generate new one and succesfully create the vpn tnunnel/connections? Regards 2012/7/17 a bv : > Hi, > > on the Splat we ca

[FW-1] Changing IPsec SAs and IKE SAs

2012-07-17 Thread a bv
Hi, on the Splat we can see and able to see the current IKE and IPSec SAs by the command vpn tu. But is there any way to add an IKE and IPsec SAs manually? What i want to do is to fool one of my firewalls like mac spoofing etc. Cause : I have a production fw R75 which correctly makes Site site

Re: [FW-1] VPN and certificate issues

2012-07-17 Thread a bv
I use preshared key at the communities so , i guess that that certificate must not have any affect on that site-to site vpn am i wrong? My aim was for the backup firewall was building a clean one which is R75.20 , old one is R75. 2012/7/17 Reinhard Stich : > At 10:19 17.07.2012, you wrote: >> >>

[FW-1] VPN and certificate issues

2012-07-17 Thread a bv
Hi, Is the certificate seen under my gateway object -vpn tab Repository of certificates available to the gateway is used any step in VPN connections? especially Siteto Site VPN communication? If so what i have to the if i bring down my production firewall and plug a backup one to the line (for

Re: [FW-1] Site to Site VPN errors

2012-07-16 Thread a bv
I also captured some traffic at that little time with fw monitor and have the capture also 2012/7/16 a bv : > I also tried to create the vpnd.elg file and i have it > > 2012/7/16 pkc_mls : >> Le 16/07/2012 3:29, a bv a écrit : >> >>> I tried to run the vpn debug com

Re: [FW-1] Site to Site VPN errors

2012-07-16 Thread a bv
I also tried to create the vpnd.elg file and i have it 2012/7/16 pkc_mls : > Le 16/07/2012 3:29, a bv a écrit : > >> I tried to run the vpn debug commands and i have elg files . I try to >> inspect them with ikeview but didnt found out much yet. I try to add >> the scree

Re: [FW-1] Site to Site VPN errors

2012-07-16 Thread a bv
/16 a bv : > I tried to run the vpn debug commands and i have elg files . I try to > inspect them with ikeview but didnt found out much yet. I try to add > the screenshot below > > Regards > > > > > > > > > 2012/7/16 pkc_mls : >> Le 16/07/2012 9:50, a

[FW-1] Site to Site VPN errors

2012-07-16 Thread a bv
Hi, I have some Site to Site VPNs running on an R70 SPLAT running without a problem. Installed a second fw R75.20 SPLAT from scratch trying to make the whole same configuration (general and vpns). But after switching the firewall to R75.20 Site to site vpns doesnt seem to work. 1 of them only s

[FW-1] The boot options

2012-07-13 Thread a bv
Hi, Since boot directly cant remember the options in splat like online debug mode , offline debug mode, maintance mode. What does these provide and when and to use them? Regards = To set vacation, Out-Of-Office, or away messages, send an email to

[FW-1] Safe files to remove form /opt

2012-07-09 Thread a bv
Hi, /opt size is little on SPLAT it gets full easily and the upgrade_export doesnt able t work . Moving db_revision files from there doesnt get enough. So what are the files /folders safe to remove from here to gain space at /opt? Regards = To set

Re: [FW-1] (Again) Firewall Availability monitoring and reporting

2012-06-18 Thread a bv
Ted Can you please provide me more information about the services and contact information? You can also private mesaage me. And also to the list this subject is still hot to me . thanks 2012/5/7 a bv : > Hi, > > What i want to do is monitor and report firewall and its services > ava

[FW-1] Policy installation gets slow

2012-06-14 Thread a bv
Hi On an R70 standalone SPLAT sometimes policy installation gets really slow. Mostly if you have a chance to reboot it after that it works better. How to find out the reason and make it faster? Regards = To set vacation, Out-Of-Office, or away mes

[FW-1] upgrade_export fail sometimes on R75.20 SPLAT

2012-06-11 Thread a bv
Hi, On an R75.20 SPLAT upgrade_export command sometimes ends with errors which talks about an error file on /opt something else. But mostly cant find anything useful on the log. And sometimes after a little time (maybe waiting, maybe after rebooting the system , maybe after cpstop cpstart i d

[FW-1] VPN connection steps

2012-06-08 Thread a bv
Hi, Can someone clearly write and explain the steps the site-to site vpn connection establishment between Checkpoint firewalls? Regards = To set vacation, Out-Of-Office, or away messages, send an email to lists...@amadeus.us.checkpoint.com in the

[FW-1] Timezone

2012-06-07 Thread a bv
Hi, What must be the timezone settings of the gateways? Is choosing the correct country from sysconfig work always? For example i live in Paris and choose Paris from sysconfig while installing or at any time. Does it work correctly? There are places which changes their time in the year so what mu

[FW-1] NTP usage for firewall

2012-06-04 Thread a bv
Hi, What are your opinions about using a time server for checkpoint firewalls ? Are there any problems that can happen using them? Do you prefer internal or extenal time servers etc? Regards = To set vacation, Out-Of-Office, or away messages, se

Re: [FW-1] Site to Site VPN errors

2012-06-04 Thread a bv
t's dying. > > On Mon, Jun 4, 2012 at 5:03 AM, a bv wrote: > >> Hi, >> >> Trying to maintain 2 synced by hand firewalls 1 is R70 SPLAT and the >> other is R75.20 SPLAT . There are some Site 2 Site VPN definitions but >> at the R75.20 they

[FW-1] Site to Site VPN errors

2012-06-04 Thread a bv
Hi, Trying to maintain 2 synced by hand firewalls 1 is R70 SPLAT and the other is R75.20 SPLAT . There are some Site 2 Site VPN definitions but at the R75.20 they gave errors and didnt worked. Each give different errors . 1 gives Error:Encryption failure:packet is dropped as there şs no vaild SA

[FW-1] Changing LAN interface IP configuration

2012-05-30 Thread a bv
Hi, On a R75.20 SPLAT i have changed the IP address of the LAN interface and it seems to work fine , but when i look at the console to the login screen i see the http...myold IP . And sometimes i see at the login screen about webuis http daemon start error how can i fix this ip issue correctly?

[FW-1] cpstop cpstart times

2012-05-30 Thread a bv
Hi, What time does it take your firewall to cpstop and cpstart (each) normally? under load? Are there errors or delays you hav within them? Regards = To set vacation, Out-Of-Office, or away messages, send an email to lists...@amadeus.us.checkpoint.c

[FW-1] NTFS support for SPLAT

2012-05-22 Thread a bv
Hi, For the sake of moving big files form my R75.20 SPLAT (like snapshots etc) im trying to find out a way. I tried to ftp them to a windows 7 PC but after i transfer them and make md5sums of the files they dont match so im not trustin them integrity. So may be the easy way taking them with an us

[FW-1] Strange policy installation problem

2012-05-21 Thread a bv
Hi, I got a R75.20 SPLAT installed and configured with hand (not used a cnfiiguration backup) . It was working well (offline) a few days ago. I logined it with a cross cable and laptop with dashboard and started to change the vpn communities encryption algorityms then after a few days later when

Re: [FW-1] Web visualization tool gives error

2012-05-15 Thread a bv
I tried some more trys and get Security Management myuser not found Failed to bind to DB Error reason:General access denied error ... 2012/5/15 a bv : > Hi, > > I have a script which can be ran manually uses web visualization  tool > to export the policy to the html format. (on an

[FW-1] Web visualization tool gives error

2012-05-15 Thread a bv
Hi, I have a script which can be ran manually uses web visualization tool to export the policy to the html format. (on an R70 . I have downloaded Web Visualization Tool for SecurePlatform / Linux (R71 and Above) version and copied to a folder of R75.20 boxes folder Tried to run the connand with

Re: [FW-1] R: [FW-1] Application Control Blade update error

2012-05-11 Thread a bv
INT.COM] Per conto di a bv > Inviato: venerdì 11 maggio 2012 10:25 > A: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM > Oggetto: [FW-1] Application Control Blade update error > > Hi, > > On a testy R75.20 which access the net for updates through proxy the > application update

[FW-1] Application Control Blade update error

2012-05-11 Thread a bv
Hi, On a testy R75.20 which access the net for updates through proxy the application update process through smartdashboard started to give error today. It shows that downloading the update package but at last i get the error Failed to copy the package into to the Security Manegement. Couldnt fin

[FW-1] Firewall switch operations

2012-05-10 Thread a bv
Hi, what are the things when you do a firewall switch operation( change 1 with other)? Configuration,rule sycn, arp ? What else? For a successful working firewall switch? Regards = To set vacation, Out-Of-Office, or away messages, send an email t

[FW-1] Understanding audit logs

2012-05-10 Thread a bv
Hi, Its sometimes hard to understand the audit logs , or find the thing you want to on Checkpoint gateways . Is there a good resource , way , document these? Regards = To set vacation, Out-Of-Office, or away messages, send an email to lists...@ama

[FW-1] Smartdashboard error

2012-05-09 Thread a bv
Hi, I have couple of versions of smartconsole installed at my PC. I have some problems with that PC these days blue screens , nonbooting (windows system files releated not found errors etc). We have tried to fix thix xp box but still problems. My problem is now my R75.20 Smartdashboard doesnt wor

Re: [FW-1] Used network objects seem unused

2012-05-07 Thread a bv
Thanks, At these objects it says unused so there is a mistake here i can see them used on rulebase thats what im wondering. regards 2012/5/7 Tom Louis : > you know you can click on the object and go to where used > > -Original Message----- From: a bv Sent: Monday, May 07, 2012 7

Re: [FW-1] Cluster installation node by node ?

2012-05-07 Thread a bv
il: ste...@ascltd.co.uk > > Security is a process, not a product. > > > > On 07/05/2012 09:01, "a bv" wrote: > >>Hi, >> >>Is it possible to install and use the first node of a cluster and wait >&g

[FW-1] Used network objects seem unused

2012-05-07 Thread a bv
Hi, For a r75.20 splat i logon with smartdashboard go to the search and query network objects and query unused objects and i see some objects which i can see on rulebase being used . So it seems to be a false positive . Sometimes it shows some really unused objects i delete them. Why do you t

Re: [FW-1] Remote Access VPN Configuration

2012-05-07 Thread a bv
l need to apply > patches or upgrades on it. > > I suggest to verify in detail each client's Release Notes before making a > decision. > > Good luck wth your tests. > > Regards > > On Thu, May 3, 2012 at 2:46 AM, a bv wrote: > >> Many thanks ill try as soon a

[FW-1] Cluster installation guide needed

2012-05-07 Thread a bv
Hi, Its been while to get in deep with Checkpoint and Cluster . Ill need to setup cluster soon so i need the find the official cluster documentation and some other tutorials (video etc) for installation and configuration. Which document will hlp me at the documentation packages i couldnt be sure (

[FW-1] Cluster installation node by node ?

2012-05-07 Thread a bv
Hi, Is it possible to install and use the first node of a cluster and wait for the others installation till then use the first as an standalone production firewall? regards = To set vacation, Out-Of-Office, or away messages, send an email to lists

Re: [FW-1] (Again) Firewall Availability monitoring and reporting

2012-05-07 Thread a bv
something wrong) for Smartevent but i dont know if and how can use it as the availablity monitoring and calculating.? Regards 2012/5/6 pkc_mls : > Le 03/05/2012 2:24, a bv a écrit : > >> Hi, >> >> Im again in need of  firewall availability and reporting. Is the

[FW-1] (Again) Firewall Availability monitoring and reporting

2012-05-03 Thread a bv
Hi, Im again in need of firewall availability and reporting. Is there a solution you can recommend? There are companies at web which says we are doing firewall external monitoring but i doent know how do they technically do that and how reliable and good working . Regards =

Re: [FW-1] Remote Access VPN Configuration

2012-05-03 Thread a bv
uot;set > domain for remote access community". > > Hope this helps. > > Regards > > > On Fri, Apr 20, 2012 at 6:22 AM, a bv wrote: > >> Hi, >> >> For the succesfullly giving Remote Access VPN service to the users >> what are the required and met

[FW-1] Connectivity problem with utm-edge and gateway

2012-05-03 Thread a bv
Hi, Having a utm edge giving internet connection service behind a gateway device. The devices interfaces are 10.x.x.x which looks to the LAN and other is 192.168.x.x which looks to the gateway. Sometimes the internet connection from utm-edge and from the proxy behind gets lost. When i tried to p

Re: [FW-1] Changing mac address at SPLAT

2012-04-30 Thread a bv
Hi, Many thanks changing the MAC adresses at the /etc/sysconfig/netconf.c seem to work (i rebooted , restarted the networking services , made the interfaces down and up) and the addresses didnt changed backwards. Regards 2012/4/26 a bv : > Hi, > > Thank for your interest if its po

Re: [FW-1] Changing mac address at SPLAT

2012-04-25 Thread a bv
Hi many thanks for the answer but I couldnt found the sk65092 on the Checkpoint site can you also please provide me the URL of the knowledgebase and content of the knowledgebase? Regards 2012/4/23 pkc mls : > Le 19/04/2012 10:24, a bv a écrit : >> >> Hi, >> >> &g

[FW-1] Abnormal trafic statistics on smartview monitor

2012-04-24 Thread a bv
Hi, Through a FW-1 , after the net connection became unavailable for hours , i opened the smartview monitor and looked at the traffice of eitherbound and only http statistics seem to be 5-6 times the lines bandwith. I guess these are temporary numbers but why this numbers occur? Regards

[FW-1] Remote Access VPN Configuration

2012-04-20 Thread a bv
Hi, For the succesfullly giving Remote Access VPN service to the users what are the required and methodically steps? Following Documentation always doesnt work. 1- Configuring remote access community creating a user and installing the client on PC and trying to create the site and connection did

[FW-1] Changing mac address at SPLAT

2012-04-19 Thread a bv
Hi, For the sake of firewall switching operations i would like change the make the set the all mac addresses of the different SPLATS same interfaces (eth0 will be xxx eth1 will be yy on all fws. I looked at the knowledgebase (https://supportcenter.checkpoint.com/supportcenter/portal?js_pe

[FW-1] License issue

2012-04-17 Thread a bv
Hi, There are 2 boxes running R70 and R75.20 1 production and 1 is its backup . There are 3 interfaces on them eth0 DMZ eth1 LAN eth2 EXT The offline ones LAN IP is diffent then others for now to be able to reachable from LAN to manage. When it will get online it will be the same IP as the pro

[FW-1] Watching,monitoring firewall availability

2012-04-11 Thread a bv
Hi, I would like to monitor and report Checkpoint firewalls (FW-1 and utm-edges ) internal and exactly . What are the scenarios, ways, tools for these? Regards = To set vacation, Out-Of-Office, or away messages, send an email to lists...@amadeus.

[FW-1] Detecting and preventing reverse shell connections

2012-04-10 Thread a bv
Hi, How can we detect and prevent reverse ssh shell connections with Checkpoint FW-1 ? With IPS, Application Control etc? Either the connection is made directly throught the firewall or proxy? Regards Scanned by Check Point Total Security Gateway. =

[FW-1] smart-1 new consolidation error

2012-04-04 Thread a bv
Hi, I have a firewall and a smart-1 box on LAN which turst established. While i try to create a new colsolidation session from Evntia manager select the firewall as the log server, tehn select default settings i get the error Failed to get default parameters from server /database. I previously so

[FW-1] Utm-edge audit

2012-03-22 Thread a bv
Hi, Utm edges can send access logs to the syslog servers, but are there any methods for detailed audit logging . Its basicly managed by the web interface so any one can login to the web interface and make changes (by knowing or guessing the user/pass comb) . On the fw-1 audit logs are created and

[FW-1] Smart-1 configuration

2012-03-12 Thread a bv
Hi, You have bougth a smart-1 box and made the initial setup (next next etc) . And you have some gateways etc which producing log and you want these logs to be used within the box. How you must configure the smart-1 to get these gateways data? Regards Scanned by Check Point Total Security Gatewa

[FW-1] IPS signature tracking options

2012-03-07 Thread a bv
Hi, There are options for the IPS signatures tracking options like log , alert, mail, snmp trap. I generally use the log option , but if others (alert , mail etc) does its job and also logs the events as usual and be able to see on smartviewtracker everytime i would use the other options. Also

[FW-1] VPN clients especially for R70

2012-02-08 Thread a bv
Hi, I would like to know about the current vpn client programs for Checkpoint gateways especially for windows xp and for R70 gateway . But current clients make some confusion. Is securemote and secureclient etc? Which client do i have to use for R70 gateway and xp client? regards

Re: [FW-1] Connecting /sending utm-edge logs to smart-1 boxes

2012-02-01 Thread a bv
found any data? And i also want edge to send logs both to the its current log destination and to the smart-1 box simultaneously without a loss. Regards 2012/1/16 a bv : > Hi, > > Addition to some fw1- gateways , we have some small edge boxes some of > which sending their logs to FW-1

  1   2   3   4   >