[FW-1] unsubscribe

2002-05-19 Thread Tony Wong
= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail = To unsubscribe from this mailing list, please see the

[FW-1] Nt domain logon across NAT

2002-02-22 Thread Tony Wong
I have the following setup:     Windows2000---FW1--NT_PDC (192.168.1.2)    (192.168.1.1)    (public_ip)    (public_ip)     windows2000 machine is behind the firewall Firewall-1 is doing NAT with 2 interfaces the NT domain controller has a public ip address o

[FW-1] VPN between NG FP1 and Cisco 2514

2002-02-17 Thread Tony Wong
I am trying to setup a VPN with IKE between a Cisco 2514 with IPsec 56 bit encryption and a NG firewall. When I try to ping from the cisco side to the checkpoint side, I can only see decrypt messages in the logs from cisco to checkpoint. I am not seeing any encrypt messages.   I basically ca

[FW-1] Migrating objects from 4.1 to NG

2002-01-21 Thread Tony Wong
I migrated my rules and objects from 4.1 to NG.   When I do a fw checkobj   I got the following:   Warning: Cannot find IP Protocol in service ftp_mapped - must be done manually ---   Also when I try to reinstall the policies, I got the following:     Services

[FW-1] moving rules and objects from 4.1 to NG

2002-01-06 Thread Tony Wong
I just setup and new NG box and would like to move the rules and objects from my old 4.1 box to this new box. Any advice would be appreciated.   Thanks

[FW-1] NG and solaris 8 x86

2002-01-04 Thread Tony Wong
Will NG work on solaris 8 x86?

[FW1] Where to install RealSecure Network Sensors

2001-06-22 Thread Tony Wong
We have the following topology:           LAN SWITCH--FW-1-CISCO3620         NO DMZ.     where should I install the network sensors and OS sensors?     Thanks

[FW1] drop on domain-tcp service - help

2001-06-21 Thread Tony Wong
I am getting a lot of drops in my log:   all the the same time within the same second or every other second on   Service: domain-tcp source address: changes every line in the log viewer protocol: tcp s_port: changes but are all high ports: 11854, 28190, 46563 etc etc etc   info: unknown esta

[FW1] VPN between 2 sites -- deny access to users

2001-06-15 Thread Tony Wong
We have a VPN between 2 Firewalls (Sites) and the rrules are as follows:   Site1        Site2        ANY        Encrypt Site2        Site1        ANY        Encrypt     With this configuration, users can access the Firewall. What do I need to do to clock all user access to the firewall?

[FW1] Nmap and Fw-1 open ports

2001-06-12 Thread Tony Wong
For a properly secured firewall when scanned with Nmap with the -p0 option, Should there be no ports opened?   I got 3 ports opened and I supposed they are the Management ports 258, 256 etc.   Thanks

[FW1] Blocking ICMP

2001-06-09 Thread Tony Wong
How does blocking ICMP make my firewall more secure?

[FW1] Learning more about FW-1

2001-06-06 Thread Tony Wong
I would like to learn more about Firewall-1. We have 2 offices both running a single gateway Firewall-1 on NT 4 sp6a.   So far we have implemented:   NAT on both Firewalls for the local network. VPN between the 2 networks is setup and communications between the two LANS and firewalls is enc

[FW1] IIS 4.0 and firewall-1

2001-06-05 Thread Tony Wong
We have a couple of IIS4.0 servers Static natted behind Firewall-1. The rule is:   ANY    WEB1,2,3    HTTP/HTTPS/TCP HIGH PORTS    ACCEPT   The internet can access these serversa   What can i do to secure these servers. I am already on the latest service pack and do frequent security updates

[FW1] Intrusion Detection for Firewall-1

2001-06-02 Thread Tony Wong
Can someone please recommend a good Intrusion detection product for Firewall-1 on NT4 sp6a?   We would like to get some alert whenever someone scans out Firewall or services that are dropped.   I looked at a few like ISS, snort. Where would I install these programs on the NT 4 Firewall itsel

[FW1] StoneBeat FullCluster on NT

2001-05-23 Thread Tony Wong
Has anyone had any experience installing and setting up StoneBeat FullCluster on NT4?   Any tips or help appreciated.   Thanks

[FW1] State Table

2001-05-16 Thread Tony Wong
I am trying to understand  how the state table works in checkpoint fw-1. What is the state table. What happens to the state table when I stop and start the fw-1 service. What happens to connections when the service stops and starts?   Say I was doing a ftp file transfer or http file transf

[FW1] Blocking vbs attachments in sp2

2001-05-12 Thread Tony Wong
Can i please get some help on how to clock vbs attachements before these emails reach my mail server?   Thanks

[FW1] Dr. Watson error with fw_strong32.exe

2001-04-24 Thread Tony Wong
WE have a VPN setup between a Firewall-1 and a Cisco router. VPN is established and both LANs can communicate with each other.   Problem is after some time  I get a Dr. Watson error and VPN connection is lost   "The application, WIN32/fw_strong.exe, generated an application error. The error

Re: [FW1] How can I move objects and rules from NT to Solaris?

2001-04-14 Thread Tony Wong
Ftp rules and objects in ascii format - Original Message - From: "John Li" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, April 10, 2001 12:41 PM Subject: [FW1] How can I move objects and rules from NT to Solaris? > > > Or is it possible? > > TIA. > -John > > > > ==

[FW1] vpn between cisco 2514 and Firewall1

2001-04-13 Thread Tony Wong
I am trying to establish a VPN session between a cisco 2514 and firewall-1 I am getting this message in log viewer:     IKE log received notification from peer: no proposal chosen   Also:   IKE log: phase 1 completion. DES/SHA1/ Preshared secrets Negotiation ID: IKE log received no

Re: [FW1] encryption for FW-1 management

2001-04-07 Thread Tony Wong
---action > > > firewall modules firewall manage. > fw1 groups accept > > > and a reverse rule > > hope this helps > > when this works change teh accept to encrypt > > > > > > "Roelandts, Guy"

[FW1] port 110 to Internal mail server through DMZ

2001-04-07 Thread Tony Wong
We have the following setup     (MAIL SERVER)LAN--CHECKPOINT--CISCO> INTERNET                     |               DMZ(MAIL RELAY and DNS)     All mail is coming into the Mail relay server and forwarded in the internal exchange server