Re: [FW-1] AW: [FW-1] [FW1] FW: CVP and smtp header problems

2004-04-08 Thread Steve Baker
I suspect that the CVP is reading the ! as an indicator of a shell script to follow or 
some other script and so it or the firewall is rejecting the address. One thing to try 
would be to use \ before the !, which should alert the CVP that the ! belongs there. 
If that works, at least you'll know what the problem is, though i'm not sure what 
you'd need to do to actually fix it long term.

uunet\!mcvax\!tuvie\!keba\!georg (in the mail via uucp example given)
 why?
 it is an very old mail character (mail via uucp)
 ...uunet!mcvax!tuvie!keba!georg

 cheers georg

 -Ursprüngliche Nachricht-
 Von: Mailing list for discussion of Firewall-1
 [mailto:[EMAIL PROTECTED] Im Auftrag von Reinhard
 Stich
 Gesendet: Donnerstag, 08. April 2004 13:55
 An: [EMAIL PROTECTED]
 Betreff: Re: [FW-1] [FW1] FW: CVP and smtp header problems


 hi,

 ! ist not an allowed character in email-addresses. so if fw1 blocks that
 this is fine.

 cheers
 reinhard

 At 16:01 07.04.2004, you wrote:
 Hello,
 
 I have a nokia cluster  with FW1 AI R54 .
 I use an a Trend Micro antivirus system connected through CVP mode with
 the firewall.
 When somebody send me a mail whose sender name is like this :
 [EMAIL PROTECTED] , I have a data format error.
 It is caused by the character ! ( exclamation mark )  in the name of the
 sender.
 I suspect a CVP problem.
 
 Does anybody can help me.
 
 Thanks.
 
 =
 To set vacation, Out-Of-Office, or away messages,
 send an email to [EMAIL PROTECTED]
 in the BODY of the email add:
 set fw-1-mailinglist nomail
 =
 To unsubscribe from this mailing list,
 please see the instructions at
 http://www.checkpoint.com/services/mailing.html
 =
 If you have any questions on how to change your
 subscription options, email
 [EMAIL PROTECTED]
 =

 --
 Reinhard Stich, ASSIST [EMAIL PROTECTED]
 Internet Security AG, 1150 Wien, Johnstrasse 29
 Tel: +43 1 3709440 RS784-RIPE Fax: +43 1 3709440-10

 =
 To set vacation, Out-Of-Office, or away messages,
 send an email to [EMAIL PROTECTED]
 in the BODY of the email add:
 set fw-1-mailinglist nomail

 =
 To unsubscribe from this mailing list,
 please see the instructions at
 http://www.checkpoint.com/services/mailing.html
 =
 If you have any questions on how to change your
 subscription options, email
 [EMAIL PROTECTED]
 =

 =
 To set vacation, Out-Of-Office, or away messages,
 send an email to [EMAIL PROTECTED]
 in the BODY of the email add:
 set fw-1-mailinglist nomail
 =
 To unsubscribe from this mailing list,
 please see the instructions at
 http://www.checkpoint.com/services/mailing.html
 =
 If you have any questions on how to change your
 subscription options, email
 [EMAIL PROTECTED]
 =

=
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=


Re: [FW-1] Changing the log path because space issues

2004-04-14 Thread Steve Baker
Also, keep in mind if you're running FP3, you probably want to install HFA319 or 
greater if you want proper disk space monitoring. I changed my log path a while back 
and for some reason the disk space alerting mechanism was still reading from the main 
disk, not the dedicated log disk. Turns out it was a bug that was fixed in that hotfix 
or later.

-s
 Hi Nuno,
 you must navigate to HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\FW1\5.0 in regedt32
 and add a string value 'FWLOGDIR' pointing to the new log directory. Then bounce
 the firewall.

 Regards,
 Victor Bonomi.



 -Original Message-
 From: Mailing list for discussion of Firewall-1
 [mailto:[EMAIL PROTECTED] On Behalf Of Nuno André
 Martins Camasão
 Sent: quarta-feira, 14 de abril de 2004 06:07
 To: [EMAIL PROTECTED]
 Subject: [FW-1] Changing the log path because space issues

 Hi,

 I've Checkpoint NG with Windows2003 and I would like to change the log files to
 another disk in the server.
 Any clues? Some ini file or something like that.

 Thanks in advance,
 Nuno

 =
 To set vacation, Out-Of-Office, or away messages, send an email to
 [EMAIL PROTECTED]
 in the BODY of the email add:
 set fw-1-mailinglist nomail
 =
 To unsubscribe from this mailing list,
 please see the instructions at
 http://www.checkpoint.com/services/mailing.html
 =
 If you have any questions on how to change your subscription options, email
 [EMAIL PROTECTED] =

 =
 To set vacation, Out-Of-Office, or away messages,
 send an email to [EMAIL PROTECTED]
 in the BODY of the email add:
 set fw-1-mailinglist nomail
 =
 To unsubscribe from this mailing list,
 please see the instructions at
 http://www.checkpoint.com/services/mailing.html
 =
 If you have any questions on how to change your
 subscription options, email
 [EMAIL PROTECTED]
 =

=
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=


Re: [FW-1] NG FP3 fwlddist log messages

2004-06-07 Thread Steve Baker
Well, in poking around on the knowledge base for a minute, I found two references to 
this error message that you might want to take a look at.  Those being:  SK8118  
SK23642, both make reference to part of the error message you included in your post 
(but the part you  or what came after it appears necessary to fully understand the 
problem).


Without having any information about your environment, I can't really say specifically 
what is causing it, but hopefully those will help.


 Hi,


 I started having  [LOG_CRIT] kernel: fwlddist_adjust_buf   messgae on my
 console lately, and firewall stops during a short period of 2-3 sec periodicaly
 everytime we see the message on the console. I checked the mailing list and most
 people relate this problem to Interface Speed mismatch, but seems like
 everything is OK (no error messages on both switch and firewall)..Any other
 opinion why this could happen? or is this really a link-state problem...I am
 trying to apply HFA-325 now do you think that could solve my problem after I
 apply it? Thanks

 ***
 Cihan SUBASI
 Garanti Technology
 Internet ve Yazilim Hizmetleri
 Tel:(90)(212)4783426 GSM:(90)(533)(2750353)
 Fax:(90)(212)6576150
 http://www.garantitechnology.com http://www.garantitechnology.com/

 mailto:[EMAIL PROTECTED]

 Success is a wonderful thing, but never underestimate the value of failure.

 Failure teaches many more things than success ever can.

 ***






 This message and attachments are confidential and intended solely for the
 individual(s) stated in this
 message.If you received this message although you are not the addressee you are
 responsible to keep the
 message confidential .The sender has no responsibility for the accuracy or
 correctness of the
 information in the message and its attachments.Our company shall have no
 liability for any changes
 or late receiving,loss of integrity and confidentiality,viruses and any damages
 caused in
 anyway to your computer system.

 Bu mesaj ve ekleri mesajda gonderildigi belirtilen kisi/kisilere ozeldir ve
 gizlidir.Bu mesajin muhatabi
 olmamaniza ragmen tarafiniza ulasmis olmasi halinde mesaj iceriginin gizliligi
 ve bu gizlilik yukumlulugune
 uyulmasi zorunlulugu tarafiniz icin de soz konusudur.Mesaj ve eklerinde yer alan
 bilgilerin dogrulugu ve
 guncelligi konusunda gonderenin ya da sirketimizin herhangi bir sorumlulugu
 bulunmamaktadir.Sirketimiz
 mesajin ve bilgilerinin size degisiklige ugrayarak veya gec ulasmasindan,
 butunlugunun ve gizliliginin
 korunamamasindan, virus icermesinden ve bilgisayar sisteminize verebilecegi
 herhangi bir zarardan
 sorumlu tutulamaz.

 =
 To set vacation, Out-Of-Office, or away messages,
 send an email to [EMAIL PROTECTED]
 in the BODY of the email add:
 set fw-1-mailinglist nomail
 =
 To unsubscribe from this mailing list,
 please see the instructions at
 http://www.checkpoint.com/services/mailing.html
 =
 If you have any questions on how to change your
 subscription options, email
 [EMAIL PROTECTED]
 =

=
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=


Re: [FW-1] checkpoint on nokia ip 350

2004-06-07 Thread Steve Baker
You can get the R54 version of Smartdashboard from the downloads section of the 
checkpoint website, it should be a free download. As far as any of the actual FW1 
software, you can probably download it from there as well, but it will only work for 
15 days unless you have a valid license.


 ok. So can i have please a ftp link to download the good management station
 software (smartdashboard, etc...)
 running with CheckPoint-1 / FW-1 on a nokia ip 350 ?

 Best regards
 - Original Message -
 From: Figaro, Nicolas [EMAIL PROTECTED]
 To: [EMAIL PROTECTED]
 Sent: Monday, June 07, 2004 11:45 AM
 Subject: Re: [FW-1] checkpoint on nokia ip 350


  Hi,
 
  Your management station must have a version more recent or the same than
 your module.
 
  So you should upgrade your management to r55.
  If you don't wan't to upgrade your management station, you can install an
 older version of checkpoint
  on your ip 350.
 
  NF
 
   -Original Message-
   From: Dominique Anokré [mailto:[EMAIL PROTECTED]
   Sent: Monday, June 07, 2004 11:35 AM
   To: [EMAIL PROTECTED]
   Subject: [FW-1] checkpoint on nokia ip 350
  
   I have installed CheckPont-1 / FW-1 on a nokia IP350 but when
   i try to connect to the nokia firewall using the
   smartdashboard i get this error message : imcompatible
   version of server.
  
   before i get the message to accept the finger print (so there
   is a communication between the client  the smartcenter )
  
   So where is the problem ?  the client i installed is from a
   cd named Checkpoint Suite R55
  
   thanks !
  
 
  =
  To set vacation, Out-Of-Office, or away messages,
  send an email to [EMAIL PROTECTED]
  in the BODY of the email add:
  set fw-1-mailinglist nomail
  =
  To unsubscribe from this mailing list,
  please see the instructions at
  http://www.checkpoint.com/services/mailing.html
  =
  If you have any questions on how to change your
  subscription options, email
  [EMAIL PROTECTED]
  =

 =
 To set vacation, Out-Of-Office, or away messages,
 send an email to [EMAIL PROTECTED]
 in the BODY of the email add:
 set fw-1-mailinglist nomail
 =
 To unsubscribe from this mailing list,
 please see the instructions at
 http://www.checkpoint.com/services/mailing.html
 =
 If you have any questions on how to change your
 subscription options, email
 [EMAIL PROTECTED]
 =

=
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=


Re: [FW-1] CP express

2004-06-07 Thread Steve Baker
The express software and licensing is specifically geared toward organizations with 
500 users or less.

All of the datasheets etc are located at:

http://www.checkpoint.com/products/express/index.html


 Hi all!

 Does anybody know what the difference is between an Express gateway
 (CPXP-SC3-xxx-NG) and the traditional vpn-1 gateway (CPMP-VPG-xxx-NG)?

 Thanks in advance.

 --
 A n u s k a A r a g ó n
 Servicio Informático  e-mail: [EMAIL PROTECTED]
 Universidad de La Rioja   Tf.:+34 941 299233
 Av. de La Paz 93, 26004 Logroño   Fax:+34 941 299180

 =
 To set vacation, Out-Of-Office, or away messages,
 send an email to [EMAIL PROTECTED]
 in the BODY of the email add:
 set fw-1-mailinglist nomail
 =
 To unsubscribe from this mailing list,
 please see the instructions at
 http://www.checkpoint.com/services/mailing.html
 =
 If you have any questions on how to change your
 subscription options, email
 [EMAIL PROTECTED]
 =

=
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=


Re: [FW-1] Provider-1 - Can´t open SmartDashboard in one CMA.

2004-06-16 Thread Steve Baker
Assuming that none of your GUI clients can connect,  you could be having a problem 
with disk space on the SmartCenter Server (See sk23575).  You may want to check that 
first.

-Steve


 Hi,
 I have a problem with Provider-1 that I have installed in a Sun E280 with
 Solaris 8. The CheckPoint Provider-1 version that I am running is NG+AI R55.
 The problem is that one of CMA doesn´t permit to open the SmartDashboard
 displaying the classic following  message ... [EMAIL PROTECTED] is already
 connected to SmartCenter Server: ip_cma_address But there insn´t GUI
 client connected. I restarted everything and rebooted all GUI clients and at
 last, the Provider-1. I think that I have a problem with database. But I´ve
 no idea how to solve this situation. Has anyone any idea? Is there a flag
 that are locked?!

 Thanks,

 Gustavo.

 =
 To set vacation, Out-Of-Office, or away messages,
 send an email to [EMAIL PROTECTED]
 in the BODY of the email add:
 set fw-1-mailinglist nomail
 =
 To unsubscribe from this mailing list,
 please see the instructions at
 http://www.checkpoint.com/services/mailing.html
 =
 If you have any questions on how to change your
 subscription options, email
 [EMAIL PROTECTED]
 =

=
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=


Re: [FW-1] Remote VPN Gateway can't be reached by HTTPs

2007-10-24 Thread Steve Baker
If I understand you correctly, the VPN device on the other side and the
webserver, which is accessable via HTTP (443) have the same IP. Assuming
that you do not have to pass HTTPS over the VPN tunnel for any other reason
(i.e. to another server) you could also go into the VPN community advanced
properties and add https as an excluded service. I believe this would solve
the problem you are having..

Thanks,
Steve


On 10/24/07, pkc_mls [EMAIL PROTECTED] wrote:

 Rafaël Olivier a écrit :
  Hi,
 
  Thanks for your answers !
 
  The connection to webserver is supposed to go directly on the Internet,
 not through the VPN Tunnel.
 
  So, VPN errors should not occur.
 
  But the webserver and remote gateway (for Site2Site VPN) are the same
 machine (same IP). That may conflict.
 
  (I already opened a case at Checkpoint Support, but sometimes takes some
 time to get answers ;-) ).
 
  Olivier.
 
 
 check in the topology that the remote vpn domain doesn't include the IP
 of the webserver you'd like to reach.

 =
 To set vacation, Out-Of-Office, or away messages,
 send an email to [EMAIL PROTECTED]
 in the BODY of the email add:
 set fw-1-mailinglist nomail
 =
 To unsubscribe from this mailing list,
 please see the instructions at
 http://www.checkpoint.com/services/mailing.html
 =
 If you have any questions on how to change your
 subscription options, email
 [EMAIL PROTECTED]
 =


=
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=


Re: [FW-1] R71 upgrade

2010-10-01 Thread Steve Baker
The problem you're having is that when you copy the upgrade tools from the
CD/ISO. you need to copy migrate, migrate.conf, upgrade_export and
upgrade_import files. The error you posted shows that the migrate.conf file
is missing.

1) Copy migrate, migrate.conf, upgrade_export and upgrade_import to a
directory on the machine you want to export
2) run 'migrate export filename
3) Copy resulting file to new SmartCenter
3) cd $FWDIR/bin/upgrade_tools on your new smartcenter
4) run migrate import /path/to/file

And you will be good to go.


On Fri, Oct 1, 2010 at 11:23 AM, Gary Scott accesslimi...@yahoo.com wrote:

 Thanks M. N., I did use the upgrade_exports that came on the R71 and R71.10
 CD's, copied them to the SCS's, and my SCS's are plugged into the network.
 I am
 seeing the same failure on several managers.





 
 From: M. N. mqnguy...@gmail.com
 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM
 Sent: Fri, October 1, 2010 11:16:58 AM
 Subject: Re: [FW-1] R71 upgrade

 Gary,
 Make sure you are using the upgrade_export version that came with R71.10.

 Just copy it over your R65 box and use it.

 This fixed our issues completely.

 Also make sure your  new SCS is plugged into the  network.


 -Original Message-
 From: Mailing list for discussion of Firewall-1
 [mailto:fw-1-mailingl...@amadeus.us.checkpoint.com] On Behalf Of Gary
 Scott
 Sent: Friday, October 01, 2010 10:26 AM
 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM
 Subject: [FW-1] R71 upgrade

 Has anyone had any success running the upgrade_export utility for R71 or
 R71.10
 against a manager running R65 or R70? I am seeing a failure on windows and
 splat, new or old installs. Thanks,

 Here are the logged errors:

 [1 Oct  9:01:47] -- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] -- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] -- AddExpansionMacro
 [1 Oct  9:01:47] -- AddExpansionMacro
 [1 Oct  9:01:47] -- SetupMacroExpansions
 [1 Oct  9:01:47] .-- GetAceDir
 [1 Oct  9:01:47] [GetAceDir] Checking ACEDATA environment variable
 [1 Oct  9:01:47] [GetAceDir] ACEDATA is not defined
 [1 Oct  9:01:47] .-- GetAceDir
 [1 Oct  9:01:47] .-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] .-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] .-- AddExpansionMacro
 [1 Oct  9:01:47] [AddExpansionMacro] Setting macro 'ACEDIR' to '/var/ace/'
 [1 Oct  9:01:47] .-- AddExpansionMacro
 [1 Oct  9:01:47] .-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] .-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] .-- AddExpansionMacro
 [1 Oct  9:01:47] [AddExpansionMacro] Setting macro 'UAGDIR' to
 '/opt/CPuas-R65'
 [1 Oct  9:01:47] .-- AddExpansionMacro
 [1 Oct  9:01:47] .-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] .-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] .-- AddExpansionMacro
 [1 Oct  9:01:47] [AddExpansionMacro] Setting macro 'SECUREXLDIR' to
 '/opt/CPppak-R65'
 [1 Oct  9:01:47] .-- AddExpansionMacro
 [1 Oct  9:01:47] .-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] .-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] .-- AddExpansionMacro
 [1 Oct  9:01:47] [AddExpansionMacro] Setting macro 'SVRDIR' to
 '/opt/CPrt-R65'
 [1 Oct  9:01:47] .-- AddExpansionMacro
 [1 Oct  9:01:47] -- SetupMacroExpansions
 [1 Oct  9:01:47] -- CommandLineArgsManager::CommandLineArgsManager
 [1 Oct  9:01:47] [CommandLineArgsManager::CommandLineArgsManager] Found
 argument: ./upgrade_export
 [1 Oct  9:01:47] [CommandLineArgsManager::CommandLineArgsManager] Found
 argument: hpguy-export-r71
 [1 Oct  9:01:47] -- CommandLineArgsManager::CommandLineArgsManager
 [1 Oct  9:01:47] -- CommandLineArgsManager::ParseCommandLine
 [1 Oct  9:01:47] .-- CommandLineArgsManager::ParseExePath
 [1 Oct  9:01:47] ..-- SplitPath
 [1 Oct  9:01:47] [SplitPath] Splitting path './upgrade_export'
 [1 Oct  9:01:47] [SplitPath] Result:
 Directory part: './'
 File part: 'upgrade_export'
 [1 Oct  9:01:47] ..-- SplitPath
 [1 Oct  9:01:47] ..-- AddExecutableExtension
 [1 Oct  9:01:47] ..-- AddExecutableExtension
 [1 Oct  9:01:47] ..-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] ..-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] ..-- AddExpansionMacro
 [1 Oct  9:01:47] [AddExpansionMacro] Setting macro 'EXEPATH' to './'
 [1 Oct  9:01:47] ..-- AddExpansionMacro
 [1 Oct  9:01:47] .-- CommandLineArgsManager::ParseExePath
 [1 Oct  9:01:47] .-- CommandLineArgsManager::InitApplicationConfig
 [1 Oct  9:01:47] ..-- GetConfig
 [1 Oct  9:01:47] ...-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] ...-- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] ...-- ReadFwsetFile
 [1 Oct  9:01:47] -- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] -- UpgradeMacroReplacer::Instance
 [1 Oct  9:01:47] [ReadFwsetFile] Going to read file './migrate.conf'
 [1 Oct  9:01:47] [ReadFwsetFile] ERR: Failed to open file: No such file or
 directory
 [1 Oct  9:01:47] ...-- ReadFwsetFile
 [1 Oct  9:01:47] [GetConfig] ERR: Failed to get config file
 [1 Oct  9:01:47] ..-- 

Re: [FW-1] RES: [FW-1] Cluster SPLAT - Hardware problems - Replace servers

2011-04-16 Thread Steve Baker
Woops, should have said $FWDIR/conf/local.arp. Typing too fast with not
enough coffee! :)

On Sat, Apr 16, 2011 at 11:11 AM, Steve Baker sfb...@gmail.com wrote:

 Make sure if you have manual proxy ARP defined that you get the info out of
 $FWDIR/local.arp as well and adjust as necessary as well.



 On Fri, Apr 15, 2011 at 2:30 PM, Alexey Baltacov drongt...@gmail.comwrote:

 Hello,
 You can upgrade the cluster members one-by-one in order to be able to
 do fail back fast in case something going wrong.
 It will also minimize the down time to minimum if any. In case you are
 upgrading just hardware and not Checkpoint version it should be done
 without any downtime. Be sure you are working broadcast on old and new
 hardware before entering it to cluster
 In case you are going to upgrade to newer checkpoint version be sure
 your management is on the same version or newer.

 On Thu, Apr 14, 2011 at 6:42 PM, Sergio Alvarez seral...@gmail.com
 wrote:
  As an extra suggestion, after reset SIC and before installing policy,
 got to
  the cluster topology and use the get topology buttons at the top to
 force
  the Management (Smartcenter) pull the interface names and configuration
 from
  your new cluster members, make sure everything looks ok with the virtual
  (cluster) IPs and then, install policy.
 
  I'm not quite sure why, but even when the interfaces might be called the
  same (example: eth0, eth1, etc.), I have seen issues in which traffic
 won't
  flow, after a change of hardware.
 
  Finally, don't forget to add licenses to your new cluster members, use
  SmartUpdate, right click on each cluster member, select get licenses
 for
  it to realize there are no licenses on those boxes and finaly attach the
  licenses accordingly.
 
  Hope this is useful.
 
  Regards
 
  On Wed, Apr 13, 2011 at 2:20 PM, Gustavo Rocha de Andrade 
  gusta...@trueaccess.com.br wrote:
 
  Hi list,
 
  If there is a level 3 hardware between the smart center and the
 clusters,
  do not forget to clear the arp table of level 3 hardware or you could
 not be
  able to install the policy.
 
  regards
 
  Gustavo Andrade
  Analista de Segurança da Informação Pl
  True Access Consulting S/A
  Fone: (61) 3217-1911
  
  De: Mailing list for discussion of Firewall-1 [
  FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM] em Nome de Leandro Vilela
 [
  dflean...@gmail.com]
  Enviado: quarta-feira, 13 de abril de 2011 12:31
  Para: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM
  Assunto: [FW-1] Cluster SPLAT - Hardware problems - Replace servers
 
  Hy list,
  I'm having a cluster that SPLAT with hardware problems.
  I purchased two new servers and need to replace equipment. I did the
  settings of the new servers identical to the former but not the
 policies
  yet. The idea is to simply unplug the old cluster, reconnect the new
  servers
  with same IP and name of previous re-create the SIC with the
 SmartCenter
  and
  implement policies.
  I wonder if I need to make any further configuration to replace the
  machines
  .
  Thanks in advance ...
 
  Regards
  Leandro VIlela
 
 
  Scanned by Check Point Total Security Gateway.
 
  =
  To set vacation, Out-Of-Office, or away messages,
  send an email to lists...@amadeus.us.checkpoint.com
  in the BODY of the email add:
  set fw-1-mailinglist nomail
  =
  To unsubscribe from this mailing list,
  please see the instructions at
  http://www.checkpoint.com/services/mailing.html
  =
  If you have any questions on how to change your
  subscription options, email
  fw-1-ow...@ts.checkpoint.com
  =
  Scanned by Check Point Total Security Gateway.
 
  =
  To set vacation, Out-Of-Office, or away messages,
  send an email to lists...@amadeus.us.checkpoint.com
  in the BODY of the email add:
  set fw-1-mailinglist nomail
  =
  To unsubscribe from this mailing list,
  please see the instructions at
  http://www.checkpoint.com/services/mailing.html
  =
  If you have any questions on how to change your
  subscription options, email
  fw-1-ow...@ts.checkpoint.com
  =
 
 
 
 
  --
  Sergio Alvarez
  CISSP | CCSE+
 
  =
  To set vacation, Out-Of-Office, or away messages,
  send an email to lists...@amadeus.us.checkpoint.com
  in the BODY of the email add:
  set fw-1-mailinglist nomail
  =
  To unsubscribe from this mailing list,
  please see the instructions at
  http://www.checkpoint.com/services/mailing.html
  =
  If you have any questions on how to change your