Re: [FW-1] Changing Administrator Passwords

2007-01-26 Thread sin
Crist Clark wrote: We need to change passwords of administrators defined using the 'cpconfig' command line interface. In R55, when given the choice, you ask to add a new administrator, but chose the name of an existing one. You then can change the password and other characteristics. In

Re: [FW-1] vpn1 edge adsl cannot connect

2007-01-26 Thread Alex
i repeat myself what about: #sk32128 is the edge defined as edge adsl in smartcenter ? you have to have the edge x adsl in the dropdown window of the edge object not simply select a edge x!! in this sk entry you can find a dbedit script to add the edge adsl properties in the objects file

Re: [FW-1] vpn1 edge adsl cannot connect

2007-01-26 Thread pkc_mls
Alex a écrit : i repeat myself what about: #sk32128 is the edge defined as edge adsl in smartcenter ? sir yes sir ! you have to have the edge x adsl in the dropdown window of the edge object not simply select a edge x!! sir yes sir ! in this sk entry you can find a dbedit script to add

Re: [FW-1] BSOD - help needed

2007-01-26 Thread Chris Bunyan
Hi Ansar - BSOD details are: Driver_Irql_not_less_or_equal 0x00d1 in fw.sys HP Management Log details are: Blue Screen Trap (BugCheck, STOP: 0x00D1 (0xECE52CBC, 0x0002, 0x, 0xF709388F)) Thanks for help Chris -Original Message- From: Mailing list for discussion of

Re: [FW-1] BSOD - help needed

2007-01-26 Thread Chris Bunyan
Hi Neil - BSOD details are: Driver_Irql_not_less_or_equal 0x00d1 in fw.sys HP Management Log details are: Blue Screen Trap (BugCheck, STOP: 0x00D1 (0xECE52CBC, 0x0002, 0x, 0xF709388F)) The Debugging Tool pointed to fw.sys driver at fault. All that changed just before

Re: [FW-1] BSOD - help needed

2007-01-26 Thread Chris Bunyan
Hi Ray, No, I haven't done major HP updating, only the network card drivers. I tend to work on the basis of 'if its working, don't fix it', but of course this principle fails in this case as the server isn't working as it should. I'll consider the HP update along with any other ideas, unless

Re: [FW-1] BSOD - help needed

2007-01-26 Thread Neil Pike
Chris, Looks like a bug in fw.sys caused by the smart defense update then. In which case it's down to Checkpoint to debug and fix the issue (if they haven't already got a fix for it). With a full blue-screen dump it should be relatively easy for their developers to track it down. BSOD

Re: [FW-1] vpn1 edge adsl cannot connect

2007-01-26 Thread Hugo van der Kooij
On Fri, 26 Jan 2007, pkc_mls wrote: in this sk entry you can find a dbedit script to add the edge adsl properties in the objects file the script produces errors. So fix the script and do it again. I do not have the fixes at hand but anyone who have played with dbedit for a while may find

Re: [FW-1] BSOD - help needed

2007-01-26 Thread Hugo van der Kooij
On Fri, 26 Jan 2007, Chris Bunyan wrote: All that changed just before problem started was a SmartDefense Update Well call me stupid but I have a bad feeling with firewalls on windows. But I have an even worse feeling on SmartDefense updates on older versions firewalls. You may try to

Re: [FW-1] Websense with Client Auth

2007-01-26 Thread fwguru
Claudia, Client Auth does not work with a URI resource when setting the authentication to Agent Auto Sign On. It should work with all the other settings. I know it works with Manual and Partially Automatic using a URI Resource. Neil Delacruz On 1/25/07, Claudia Cordova [EMAIL PROTECTED]

Re: [FW-1] Changing Administrator Passwords

2007-01-26 Thread cisco4ng
Sergio is partially correct. In NGx, while it is true that you can only creat a single admin user from the CLI (cpconfig), Checkpoint has a SK that documented to allow you to create multiple admin users from the CLI. I can't think of it at the moment. Basically, you use dbedit or

Re: [FW-1] BSOD - help needed

2007-01-26 Thread Ansar Mohammed
This is most likely a CP issue. Run your updates manually. Additionally, you can rule out third party software by de-installing antivirus and specialized NIC software (like teaming for instance). -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:FW-1-

Re: [FW-1] vpn1 edge adsl cannot connect

2007-01-26 Thread pkc_mls
Hugo van der Kooij a écrit : On Fri, 26 Jan 2007, pkc_mls wrote: Remove the empty lines. They should not be there and they will prevent a correct application of the fix. Hugo. I tried to run the script line after line manually. here is the result : dbedit modify sofaware_gw_types

Re: [FW-1] vpn1 edge adsl cannot connect

2007-01-26 Thread Hugo van der Kooij
On Fri, 26 Jan 2007, pkc_mls wrote: Alex a écrit : i repeat myself what about: #sk32128 is the edge defined as edge adsl in smartcenter ? sir yes sir ! you have to have the edge x adsl in the dropdown window of the edge object not simply select a edge x!! sir yes sir ! in this sk

[FW-1] Edge X, NAt with vpn ?

2007-01-26 Thread Herold Heiko
Should the Edge X device be able to NAT nodes from LAN for connections going through an enterprise vpn ? Edge X, fw 6.0.74, connected to a NGAIR55 management station with libsw 6.0.81. Lan network is 10/8 (customer, don't ask), DMZ port is 172.19.29/24. Local vpn endpoint are a couple of NGAIR55

[FW-1] RPC over HTTPS for remote Outlook Access

2007-01-26 Thread Millan, Raul
I have a OWA server installed in the DMZ, and the Exchange Server in the LAN. We want to let our Outlook clients outside the network to connect to their Exchange inboxes, so it doesn't require a VPN connection. I've been trying to find documentation about this using FW-1, but all I get

[FW-1] Secondary Keeps Reporting Primary Down in ClusterXL

2007-01-26 Thread Crist Clark
I've got two ClusterXL pairs managed from a single SmartCenter. One of the pairs is causing me some pain. Looking at Control messages in the logs, I see the secondary firewall (gcc1fw2) claiming that the member 1 is down, so it comes up, then it goes back to standby. I presume, although it doesn't

Re: [FW-1] Secondary Keeps Reporting Primary Down in ClusterXL

2007-01-26 Thread Hugo van der Kooij
On Fri, 26 Jan 2007, Crist Clark wrote: I've got two ClusterXL pairs managed from a single SmartCenter. One of the pairs is causing me some pain. Looking at Control messages in the logs, I see the secondary firewall (gcc1fw2) claiming that the member 1 is down, so it comes up, then it goes back

Re: [FW-1] BSOD - help needed

2007-01-26 Thread Ray
The reason I mentioned it is we just had two IBM servers running SAP fail to restart (on different days). Both of them hung with the little colored line at the bottom. The only thing that fixed them was to run IBM's UpdateExpress firmware updater. No clue as to why this did not happen before.

Re: [FW-1] RPC over HTTPS for remote Outlook Access

2007-01-26 Thread Ray
Can you run it to the OWA server? I've always seen it run to the Exchange server itself. Are the clients on XP SP2? I think that's a requirement as well. Ray From: Millan, Raul [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1

Re: [FW-1] RPC over HTTPS for remote Outlook Access

2007-01-26 Thread Fred Katsumi
We did this a year ago and don't remember running into much problem with regard to FW1. I don't know if this article would help. http://support.microsoft.com/default.aspx?scid=kb;en-us;827330 What exactly are you having problem with? If your front end exchange is in DMZ you have to let it

Re: [FW-1] Secondary Keeps Reporting Primary Down in ClusterXL

2007-01-26 Thread Crist Clark
On 1/26/2007 at 3:19 PM, Hugo van der Kooij [EMAIL PROTECTED] wrote: On Fri, 26 Jan 2007, Crist Clark wrote: I've got two ClusterXL pairs managed from a single SmartCenter. One of the pairs is causing me some pain. Looking at Control messages in the logs, I see the secondary firewall