Re: [FW-1] Firewall-1 NT Syslog

2002-12-19 Thread nicolas figaro
this page shows syslog freeware daemon for windows http://www.kiwisyslog.com/ nicolas figaro nicolas figaro a écrit: search syslog windows NT with your favourite web search engine. could your share your experience with the product you'll select afterwards ?? thanks nicolas figaro X Xpid

Re: [FW-1] Traceroute problem

2002-12-19 Thread Brandon Lynch
The two are not the same. Windows tracert uses ICMP echo request and ICMP echo reply. Unix traceroute sends a UDP datagram to a port between 33000 and 33999. The expectation is that there won't be an application listening on one of those ports. Assuming no application is listening an ICMP UDP

Re: [FW-1] A certificate with this name already exists,please specify a different name and try again.

2002-12-19 Thread David Hassilev
I had this happen yesterday. I ended up having to remove the object from the policy editor and then add it again. [EMAIL PROTECTED] 12/18/02 07:58AM Hi All,I had a SIC failure between my HQ and a remote enforcement point. Ireinitialised the remote enforcement point, and when I go to do the

Re: [FW-1] Syn packet for established connection Error in Rule Base with NG

2002-12-19 Thread Bernd Zimmermann
Hi, try to decrease the session timeout of your service bernd Patrick, Glen [SMTP:[EMAIL PROTECTED]] wrote: ITSupport Stationery Hi guys, I'm having problems with a new NG install running on SecurePlatform. We have connections dropped between two boxes, which was not

[FW-1]

2002-12-19 Thread boobe jouke
Hi I am installing NG on Red-Hat Linux 7.3 and it does not work. What should I do ?. _ MSN 8 helps eliminate e-mail viruses. Get 2 months FREE*. http://join.msn.com/?page=features/virus

Re: [FW-1] Traceroute problem

2002-12-19 Thread Russell Washington
Can't tell you exactly what the scoop is, but as I recall Unix uses UDP for traceroute, while Windows boxes use ICMP. Can't explain to you precisely why you have an ICMP issue, but I'd start looking at your implied rules (see if ICMP is allowed) and yadda yadda... And then there's that thing

Re: [FW-1]

2002-12-19 Thread William Mathews
Could you be a tad more specific? What flavor NG, What kernel version 7.3, what do you mean by does not work, etc. ---boobe jouke spoketh: Hi I am installing NG on Red-Hat Linux 7.3 and it does not work. What should I do ?.

Re: [FW-1] behaviour of IPSEC

2002-12-19 Thread Russell Washington
Firewall B may not be logging IKE negotiation (check Global Properties). In administering a lot of VPNs I've seen that a policy push will sometimes trigger a renegotiation... But that seems to depend on what Firewall B is (haven't nailed down the specifics yet) :( -Original Message-

Re: [FW-1] Certification

2002-12-19 Thread Russell Washington
Is FP3 coursework even out there? I took MGT II at the beginning of November and they were still on FP2. -Original Message- From: Reinhard Stich [mailto:[EMAIL PROTECTED]] Sent: Thursday, December 19, 2002 3:55 AM To: [EMAIL PROTECTED] Subject: Re: [FW-1] Certification well, in fact

Re: [FW-1] NG FP3 and SecurID not working

2002-12-19 Thread Greg Polanski
1. Start the ACE GUI and watch the activity log when working with the FW (agent) 2. rm /var/ace/securid and clear the node secret in the GUI 3. Cause authentication, either via sdshell or the FW. 4. Check the node naming and interfaces. In ACE, the

Re: [FW-1]

2002-12-19 Thread Hal Dorsman
You could start by being more specific about what doesn't work. Hal Hal Dorsman Network Administrator Rocky Mountain Elk Foundation Missoula, Montana USA [EMAIL PROTECTED] (406)523-4576 I am installing NG on Red-Hat Linux 7.3 and it does not work. What should I do ?.

Re: [FW-1]

2002-12-19 Thread Zeltser, Roman
Try again. (unless you provide more details) ** Roman Zeltser, @National Computer Center, DNE RS Information Systems -Original Message- From: boobe jouke [mailto:[EMAIL PROTECTED]] Sent: Thursday, December 19, 2002 3:17 PM To: [EMAIL PROTECTED] Subject:

Re: [FW-1]

2002-12-19 Thread jimbo
my car doesn't work. whats wrong with it? -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED]]On Behalf Of boobe jouke Sent: 19 December 2002 20:17 To: [EMAIL PROTECTED] Subject: [FW-1] Hi I am installing NG on Red-Hat Linux 7.3 and it does

Re: [FW-1]

2002-12-19 Thread Brandon Lynch
I think this fellow is taking us ALL for a ride. Here we are laughing, meanwhile he's laughing at US for taking him seriously. :) On Thu, 2002-12-19 at 16:19, jimbo wrote: my car doesn't work. whats wrong with it? -Original Message- From: Mailing list for discussion of Firewall-1

Re: [FW-1]

2002-12-19 Thread Hal Dorsman
Reinstall the engine. -Original Message- From: jimbo [mailto:[EMAIL PROTECTED]] Sent: Thursday, December 19, 2002 2:19 PM To: [EMAIL PROTECTED] Subject: Re: [FW-1] Importance: High my car doesn't work. whats wrong with it? -Original Message- From: Mailing list for

Re: [FW-1] CLusterXL on Windows 2000

2002-12-19 Thread Christopher Collins
It was our external router. It was ignoring the Multicast MAC address that the cluster was sending out. We have added a static ARP entry for it and it is now working. Thanks for the input. Chris -Original Message- From: Daniel Fischer (J) [mailto:[EMAIL PROTECTED]] Sent: December

Re: [FW-1] Certification

2002-12-19 Thread Ham, MichaelX
FP3 Courseware is not available. I took Mangement 1 on this past Monday and it still uses FP2. Michael Ham System Administrator -Original Message- From: Russell Washington [mailto:[EMAIL PROTECTED]] Sent: Thursday, December 19, 2002 9:16 AM To: [EMAIL PROTECTED] Subject: Re: [FW-1]

[FW-1] Answer file with SecuRemote installation- possible??

2002-12-19 Thread Aaron Reynolds
Does anyone know if it is possible to use an answer file with a SecuRemote installation (Build 4200) to be specific? This allows the ability to blindly answer the questions during the install, without the end user having to do anything. Thanks. -Aaron

Re: [FW-1]

2002-12-19 Thread Brian Lintz
# rpm --install gasoline-0.87.rpm (you may need .89 or .92, depending on your system..) -Original Message- From: jimbo [mailto:[EMAIL PROTECTED]] Sent: Thursday, December 19, 2002 3:19 PM To: [EMAIL PROTECTED] Subject: Re: [FW-1] my car doesn't work. whats wrong with it? -Original

Re: [FW-1] losing ssh connections through HA pair

2002-12-19 Thread Aaron Reynolds
Title: [FW-1] losing ssh connections through HA pair Do you know if fetching a policy from the secondary, would cause the primary to clear its connections table? That is the only way that I can see that I would have lost my connection, after having just been using it 2 minutes earlier.

Re: [FW-1] NG FP3 and SecurID not working

2002-12-19 Thread Yim Lee
Your might also want to snoop the interfaces on both the ace and fw boxes. Make sure it has the right ip address. Yim --- Greg Polanski [EMAIL PROTECTED] wrote: 1. Start the ACE GUI and watch the activity log when working with the FW (agent) 2. rm /var/ace/securid and clear

[FW-1] memory leak in Secureplatform FP3??

2002-12-19 Thread Damien Hart
Hi people, Since setting up MRTG to monitor some components of my Secureplatform FP3 installation two weeks ago I have watched my free real memory gradually drop from over 180 Meg to 39 Meg as I write this message... Has anyone else noticed this happening? I am not using any VPNs if that makes

[FW-1] Static NAT problem I think..

2002-12-19 Thread Don Leeper
I am running FP3 on a Dell 1650. I am running W2K SP3 and I am using Intel NIC's. My problem is that some days I will come in and the devices that are NAT'd can't get out and you can't get in. I reboot the box and it doesn't fix it. I then remove nat then I can browse. I put it back and

Re: [FW-1] memory leak in Secureplatform FP3??

2002-12-19 Thread Read, Andrew
In my test environment, I have not noticed any drop in the free memory. But then, there's not much activity there either. Looks like I won't be putting this into production until mid January now, but I'll keep an eye on this and feedback any results. Andrew -Original Message- From:

Re: [FW-1] How to change the name of network interface

2002-12-19 Thread Guangcheng Wen
Hello, Thanks a lot and sorry for my late reply. hdorsman That is a security feature built into FW-1 so that the system hdorsman does not come up with unprotected interfaces. You will need to hdorsman disable your startup script (S95firewall1 ?) by renaming it then hdorsman reboot so the fw

Re: [FW-1] How to change the name of network interface

2002-12-19 Thread Guangcheng Wen
Hello, Thanks for your reply. crist.clark Question, though, why do you want to rename your interface? I crist.clark am a little confused about at what level you actually want to crist.clark name it. Device level naming is done in the OS, and I am not crist.clark even sure if you can

[FW-1] changing the remote management

2002-12-19 Thread imran
Hi, We have been outsourcing our firewall management until now and due to a problem with the management we decided to change that policy and take our management inhouse. since we are not in very good terms with out outsource company so I am having considerable difficulties in managing the

Re: [FW-1] memory leak in Secureplatform FP3??

2002-12-19 Thread Damien Hart
it must be related to load because it drops alot less on the weekends than it does on weekdays... Damo In my test environment, I have not noticed any drop in the free memory. But then, there's not much activity there either. Looks like I won't be putting this into production until mid