Re: [FW-1] VPN between CP NG FP2 and Nokia IP30

2003-01-30 Thread Jason Costomiris
On Wednesday, January 29, 2003, at 03:12 PM, Eyal Rif wrote: Hi, I am currently trying to setup a VPN betwee CP NG FP2 and Nokia IP30. i am currently working with simplfied mode,i am trying to setup a vpn with preshared secert. I want to tell CP NG FP2 to use a certain preshared secert in

[FW-1] solved Nokia 330 install problem

2003-01-30 Thread N.J. Reuvers
People, my problem was solved by using SecureCRT instead of hyperterminal. Thank you all for your quick response. By the way, i did a Nokia IP120 install using hyperterminal and had no problems. Weird! Kind regards, -- N.J. Reuvers Schippers Consultancy B.V. Oude Boteringestraat 71 P.O. Box

Re: [FW-1] VPN between CP NG FP2 and Nokia IP30

2003-01-30 Thread Brokenshire, Steve
You can setup a VPN to an IP30 as I have done it. You have to use a manual setup but you can use pre shared secrets. What you can't do until FP3 is push a policy out as you need the plugin which I am told only works on FP3 -Original Message- From: Jason Costomiris [mailto:[EMAIL

[FW-1] split dns not workong on NG

2003-01-30 Thread Hans van den Boomen
Hi All, Have you tried to configure office mode ? This works just fine for me. Regards, Met vriendelijke groet, Hans van den Boomen AVAS Acal Value Added Services

Re: [FW-1] Subnet Mask question

2003-01-30 Thread Stefan Funk
Thanks for all the responses! cheers Stefan |-+-- | | Stefan Funk| | | [EMAIL PROTECTED] | | | Sent by: Mailing list for | | |

[FW-1] AW: [FW-1] SecurePlatform support question

2003-01-30 Thread Joerg Fritsch
Title: SecurePlatform support question Hello, I have running several firewalls on RedHat Linux; --even mission critical clusters like our RainWall. According to my experience Check Point Linux is a stable configuration. There are even products like the performance pack which do not run

[FW-1] how to configure implicit client authentication in NG FP2

2003-01-30 Thread Gil, Ruben
Hello, I´m trying to configure implicit client authentication in NG FP2. There wasn´t problem with 4.1, but we can´t get it with NG FP2. Thanks, = To set vacation, Out Of Office, or away messages, send an email to [EMAIL

Re: [FW-1] split dns not workong on NG

2003-01-30 Thread Stuart Carrison
yes we tried office mode with same result... everything but split dns works. -Original Message-From: Hans van den Boomen [mailto:[EMAIL PROTECTED]]Sent: 30 January 2003 09:00To: [EMAIL PROTECTED]Subject: [FW-1] split dns not workong on NGHi All, Have you tried to

[FW-1] How to export objects list?

2003-01-30 Thread Victor Bonomi
Gurus, Due to a corruption on the Objects Database (my box gets very instable without a reason), I need to re-create all the objects (hosts, nets, services, etc) on another machine. I don't want to import the /conf dir. I really need to do all it over. I was wondering whether I can export the

Re: [FW-1] AW: [FW-1] SecurePlatform support question

2003-01-30 Thread Stuart Carrison
Title: SecurePlatform support question Is performance the issue? We run NG FP2 on a DL380 with W2K SP3. The server has two P3 1.2Ghz processors and 512Mb RAM. Processor usage averages out at about 5%, physical memory usage is just 120Mb. Our internet connection isn't massive: 4Mb/s. We never

Re: [FW-1] How to export objects list?

2003-01-30 Thread Volker Tanger
Greetings! Victor Bonomi wrote: Due to a corruption on the Objects Database (my box gets very instable without a reason), I need to re-create all the objects (hosts, nets, services, etc) on another machine. I don't want to import the /conf dir. I really need to do all it over. I was wondering

Re: [FW-1] solved Nokia 330 install problem

2003-01-30 Thread Roelandts, Guy
Hi, I have seen that too while installing several IP120's Met vriendelijke groeten - Bien à vous - Kind regards Guy ROELANDTS EMEA GS Internet Expertise Centre - CCSE-NG Hewlett-Packard Belgium B.V.B.A./S.P.R.L. E-mail : [EMAIL PROTECTED] Tel: +32(02)729.77.44 (options 3 - 3 - 1) Fax:

[FW-1] Please trim replies

2003-01-30 Thread Martin Peikert
Without any cause ;) From focus-sun@securityfocus. Original Message Subject: Administrivia: Please trim replies Hi folks, Just a reminder to please trim replies. When responding, please include only the text to which you are responding, and preferrably put your responses below

Re: [FW-1] Update expiry date on NG FP2, was RE: User login expiry

2003-01-30 Thread Jonathan Jackson
Dave, Check the expiry of the generic* user. Also, on a split management-module setup you'll need to edit the objects_5_0 file on the management for it to be pushed up to the modules on policy push. Hope it helps, Jonathan -Original Message- From: ext David Gillett [mailto:[EMAIL

Re: [FW-1] user authentication with HTTPS

2003-01-30 Thread Serwatko Pawe
Hello I'am using FW-1 NG FP3 with the latest hotfixes. I have a problem with http through proxy on 443 port. I made changes in fwauthd.conf (added line 443 fwssd in.ahttpd wait 0) and bounce firewall. Next I changed a servis hhtps - advanced - Protocol type: HTTP, and resource: with proxy and

[FW-1] route problem in ClusterXL

2003-01-30 Thread Alberto
Hi! I'm trying to use a ClusterXL with load sharing. It's three networks, clients, servers and external. I'm checking connectivity with pings. Text policy allows everything. It's CP NG FP3 HF1. Between private networks there's no problem. Problem is when trying to ping from clients or servers

Re: [FW-1] VPN beteween NG FP3 and CISCO VPN Concentrator

2003-01-30 Thread Tumarinson, Max
Actually Cisco VPN Concentrator does support AES starting from release 3.6 -Original Message- From: Mitchell Rowton [mailto:[EMAIL PROTECTED]] Sent: Wednesday, January 29, 2003 8:43 PM To: [EMAIL PROTECTED] Subject: Re: [FW-1] VPN beteween NG FP3 and CISCO VPN Concentrator In addition

Re: [FW-1] Suggestions for creating a manageable firewall policy

2003-01-30 Thread Connell Margo A. (DBM1MAC)
I apologize for not being more specific. The four source objects need to talk to all 900 objects. Unfortunately, it is not the same ports for every object. For example one destination may require http, https open. Another may require tcp-1494 and udp-highports. Another needs only http,

[FW-1] SMTP Rule - 4.1 and NG FP3

2003-01-30 Thread Christopher Collins
Hi, I have an SMTP question relating to 4.1 but further down I would like to see how it would relate to NG FP3, as we will be moving to that shortly. Objects: MAILSERVER 192.168.100.1 STATIC NAT: 200.200.200.200 MAILSERVER-EXT 200.200.200.200 Rule for outbound mail: Source

Re: [FW-1] FW-1-MAILINGLIST Digest - 27 Jan 2003 to 28 Jan 2003 (#2003-28)

2003-01-30 Thread Valerie Leveille
The format for the text file is unforgiving. It has to be specifically as follows with one site per line and a return character at the end of each line: IP addr or URLTABpath/leave blank if you want to block entire siteTABsome hexidecimal characterRETURN At 03:00 AM 1/29/2003, you wrote: Date:

[FW-1] How to disable topology update on startup?

2003-01-30 Thread Vadim Kuznetsov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I have 4.1 SP6 and securemote is 4200 How can i prevent securemote to pop and ask for update site on startup? userc.C:update_topology_at_start (false) objects.C props::desktop_update_at_start (false) And I do not want

[FW-1] Time format in FW LOG

2003-01-30 Thread Partha C
Hi all, i was trying to find a logs from Fw.log file for a specific period. but i was not able to find the time format for the same. The command which i gave was fw log -c drop -b stime stamp etime stamp /fw.log Its silly to ask this question but i was not able to do that..the time format which i

Re: [FW-1] FW-1-MAILINGLIST Digest - 28 Jan 2003 to 29 Jan 2003 (#2003-29)

2003-01-30 Thread Valerie Leveille
It's now called SmartView Tracker. At 03:00 AM 1/30/2003, you wrote: Date:Wed, 29 Jan 2003 11:19:05 +0100 From:Thomas Borger [EMAIL PROTECTED] Subject: where is the log viewer - FP3 Hi, For you is my question surely very simple but I`m wondering about my not available log viewer. What

Re: [FW-1] User login expiry

2003-01-30 Thread David Gillett
No, these are accounts in the FW-1 database, not the host OS. -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED]]On Behalf Of Yim Lee Sent: January 29, 2003 16:30 To: [EMAIL PROTECTED] Subject: Re: [FW-1] User login expiry Dave, Are

Re: [FW-1] Blue Screen on Windows 2000 installing FW1 Service Packs

2003-01-30 Thread Chontzopoulos Dimitris
Is the CD a 3DES version? Have you tried installing the FW-1 Service Packs from a lower to greater basis (e.g. SP2, then SP3, then SP4, then SP5, then SP6)? Have you tried updating the driver of your NIC's? Are there any extra firewall applications running (personal firewalls e.t.c.)? Do you have

Re: [FW-1] user authentication with HTTPS

2003-01-30 Thread Steven J. Surdock, PE
Here is what I had to do... The following changes appeared to have fixed problems I was having with FP2: 1) Use dbedit to modify the following parameters: :http_connection_method_transparent (true) :http_connection_method_proxy (true) :http_connection_method_tunneling (true)

Re: [FW-1] SMTP Rule - 4.1 and NG FP3

2003-01-30 Thread Crist Clark
Christopher Collins wrote: Hi, I have an SMTP question relating to 4.1 but further down I would like to see how it would relate to NG FP3, as we will be moving to that shortly. Objects: MAILSERVER 192.168.100.1 STATIC NAT: 200.200.200.200 MAILSERVER-EXT 200.200.200.200 Rule for

[FW-1] L2TP and NG FP3

2003-01-30 Thread Bob Ramsdell
I am trying to establish a VPN between a Windows 2000 PC and a NG FP3 firewall. Both the firewall and the Windows PC have been configured according to CP KB article sk15390. At this point the connection is failing with the error encryption failure: Cannot identify peer which appears in the log

[FW-1] New NG Server

2003-01-30 Thread Robert Mezzone
Title: Message I'm in the process of replacing our existing FW-1 box with new hardware and an upgrade to NG. What is the general consensus in regards to using WIN2K or NT server. I've read some posts and even heard some concerns during a FW-1 training class about running on WIN2K. I'd like to

Re: [FW-1] route problem in ClusterXL

2003-01-30 Thread jim parker
Yeah I've been wondering the same thing, if youset its own external interface as its own default gateway it works, but that seems somewhat odd... I've asked for a cp technie to come in and discuss it... -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL

[FW-1] Logon Scripts

2003-01-30 Thread John Smithson
Gurus, I'm new to the secure client and Checkpoint NG FP3.We are on the process of testing the secure client with Checkpoint (on IPSO). Our domain is NT 4 ( no active dir). We will be using Radius to authenticate user on our domain. What is the process to launch logon scripts once user get

Re: [FW-1] New NG Server

2003-01-30 Thread Covington, Chris
Title: Message If you'd like to rid yourself of NT, just take the same box you would use, skip a 2000 $erver license, and throw Secureplatform on it. Chris -Original Message-From: Robert Mezzone [mailto:[EMAIL PROTECTED]] Sent: Thursday, January 30, 2003 4:00 PMTo:

Re: [FW-1] New NG Server

2003-01-30 Thread John Swensson
Title: Message NT vers Win2k? it should be Win2k vers Linux, and you should pick Linux, IMHO -john -Original Message-From: Robert Mezzone [mailto:[EMAIL PROTECTED]]Sent: Thursday, January 30, 2003 1:00 PMTo: [EMAIL PROTECTED]Subject: [FW-1] New NG Server I'm in

Re: [FW-1] New NG Server

2003-01-30 Thread Scott Churchman
Granted I am a vendor of a certified Check Point Appliance so I am bias. I would take a strong look at Secure Platform based systems. Ask yourself these questions about Check Point on Windows: Is the license cost effective? Is the maintance required to update cost effective? Is

[FW-1] Get Topology Error

2003-01-30 Thread vulnerabilities
Hy, we have to notice an our customer's problem: in NG-FP3 Smart Dashboard when they try to make get topology (not interfaces with antispoofing yet configured) they see to return the following error: Error Internal. They have two Nokia IP440 under HA: VRRP Status and SNMP state are correct.