Re: [FW-1] High wa at vmstat

2013-07-03 Thread Clive Luk
Dear all UTM-1 guru, I am currently running a 2 members UTM-1 3070 cluster (R70.5). We are planning to change the management IP address. The current IPs are as following. The current objects in SmartDashBoard are: utm-1-cluster (172.16.0.1) on Internal interface utm-1-fw1 (172.16.0.11) on

Re: [FW-1] CP UTM-1 R70.5 policy question

2013-01-30 Thread Clive Luk
, and you're trying to prune that access with a few specific drop rules.) Does that make sense, or did I explain the concept badly? -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM] On Behalf Of Clive Luk Sent: Tuesday, January

Re: [FW-1] CP UTM-1 R70.5 policy question

2013-01-29 Thread Clive Luk
fundamental differences in architecture between Juniper (and Cisco, for that matter) and Check Point. Juniper and Cisco use interface-centric ACLs, whereas Check Point is an object-oriented firewall. On Tue, Jan 29, 2013 at 1:09 AM, Clive Luk cl...@sl.nsw.gov.au wrote: Hi all, I am just wondering

[FW-1] CP UTM-1 R70.5 policy question

2013-01-28 Thread Clive Luk
Hi all, I am just wondering if I can define a policy restricted by zone. As I can see on the CP tracker there is inzone, outzone. I have UTM-1 with multiple interfaces. 1 x Internet 1 x DMZ 1 x Staff internal 1 x Wireless 1 x Public internal I am wondering if I can have a policy define to

Re: [FW-1] UTM-1 upgrade advice needed

2011-12-04 Thread Clive Luk
even the logs get rotated. it is actually failing my nightly scheduled backup job of the UTM-1 configuration. due to the space issue. Thanks in advance! Cheers! On 30/11/11 22:44, Hugo van der Kooij wrote: On 30.11.2011 00:52, Clive Luk wrote: Dear list, I just want some advice on UTM-1

Re: [FW-1] UTM-1 upgrade advice needed

2011-11-30 Thread Clive Luk
configuration. due to the space issue. Thanks in advance! Cheers! On 30/11/11 22:44, Hugo van der Kooij wrote: On 30.11.2011 00:52, Clive Luk wrote: Dear list, I just want some advice on UTM-1 upgrade. I am currently running 2 UTM-1 R70.40. I am thinking of upgrading. Should I stick with R70

[FW-1] UTM-1 upgrade advice needed

2011-11-29 Thread Clive Luk
Dear list, I just want some advice on UTM-1 upgrade. I am currently running 2 UTM-1 R70.40. I am thinking of upgrading. Should I stick with R70? or should I go to R75? The reason I am upgrading is I found the appliances has been acting weird when I installing the policy. Check Point

[FW-1] Bandwidth throttle

2007-11-14 Thread Clive Luk
Dear List, I am wondering if checkpoint can handle bandwidth throttling. I am currently running R60. Thanks in advance! Cheers! Scanned by Check Point VPN-1 UTM NGX R65 with Messaging Security = To set vacation, Out-Of-Office, or away

Re: [FW-1] Bandwidth throttle

2007-11-14 Thread Clive Luk
-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Bandwidth throttle Clive Luk wrote: Dear List, I am wondering if checkpoint can handle bandwidth throttling. I am currently running R60. Yes, it's called Flood Gate in checkpoint and as of NGX is free of charge. Scanned by Check Point VPN

[FW-1] DNS implied rule - best practice

2007-04-11 Thread Clive Luk
Hi all, I just got one question. Is that a best practice to leave/allow the implied rule for DNS traffic going from any to any? Is that vulnerable? Should I just setup my own policy to allow DNS traffic accordingly? If I am going to setup my own policy would that affect the performance on the

[FW-1] VPN issue wiht secureRemote

2007-04-05 Thread Clive Luk
Dear list, I have one issue with my VPN. When I am at home connected back to my work via secureRemote. I can access all resource on 172.16.* (as this is the physical interface on FW). However, I can't access any other resources which on not on the physical interface. For example, we have a

[FW-1] Securemote/secureclient connected successfully but can't accss internal resource

2006-12-26 Thread Clive Luk
Hi all, I hope someone can help me out here. I have try everything I could. I have newly setup a cluster NGX R60 firewall with RSA authentication manager with SecurID working. They all running on Solaris 9. I have also tested the connection from my home to the cluster FW. I have connected

Re: [FW-1] Securemote/secureclient connected successfully but can't accss internal resource

2006-12-26 Thread Clive Luk
. Regards On 12/26/06, Clive Luk [EMAIL PROTECTED] wrote: Hi all, I hope someone can help me out here. I have try everything I could. I have newly setup a cluster NGX R60 firewall with RSA authentication manager with SecurID working. They all running on Solaris 9. I have also tested

Re: [FW-1] Need help on upgrading

2006-09-26 Thread Clive Luk
Thanks Guys! I will give it a go. Cheers, Clive -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Sergio Alvarez Sent: Wednesday, 27 September 2006 12:05 AM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Need

[FW-1] Need help on upgrading

2006-09-25 Thread Clive Luk
Hi Guru, I want to ask if there is a easy method to do a management server upgrade? Actually I want to move all configuration and license from a piece of old hardware to a new hardware. Anything I need to pay attention? Thanks in advance! Cheers, Clive

[FW-1] R60 CPHA broadcast traffic

2006-08-15 Thread Clive Luk
Hi list, I have setup a CP R60 high availability new mode using clusterxl. I am just wondering if it is normal that there lots of broadcast traffic generating on all interfaces? Cheers, Clive = To set vacation, Out-Of-Office, or away messages,

Re: [FW-1] R60 CPHA broadcast traffic

2006-08-15 Thread Clive Luk
are necessary for cluster-status health checks, when a Check Point ClusterXL clustering solution is implemented. -GS -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Clive Luk Sent: Tuesday, August 15, 2006 8:11 PM To: FW-1-MAILINGLIST

[FW-1] hardware firewall recommendation

2006-08-02 Thread Clive Luk
Dear list, I want to get some suggestions from you guys on what hardware firewall to get. My requirement is to be able to handle gigabit traffic. As 2 of my internal interfaces will need to pass through a lot of traffic. To the internet it's ok to have 10/100. I have not much experience on H/W

[FW-1] silly Cluster HA question.

2006-07-20 Thread Clive Luk
Dear list, I have just setup a cluster HA gateway in my test area. I have one question(I am not sure if this is normal). In my cluster gateway, I have 2 cluster members. For example cluster1 is active and cluster2 is standby. Cluster2 can ping the Virtual IP. But cluster1 can't. is that normal?

Re: [FW-1] Solaris 9 BGE card and NGX60

2006-07-12 Thread Clive Luk
with BGE interface, but NGX R60 is suppose to have resolved those issue. I have installed NGX R60 with HFA3 on V240 server and it works fine. Try adding the line bge accept in the file /etc/fw.boot/ifdev if it is not already there. Ramki CCNA, CCSE-NGAI Clive Luk wrote: Dear List, I am

[FW-1] Solaris 9 BGE card and NGX60

2006-07-11 Thread Clive Luk
Dear List, I am trying to do a new installation on my newly bought two SUN FIRE V240. Actually I want to setup as a cluster. However, When I installed NGX60 to a freshly built box, it seems that CP doesn't recognise the bge card. Does anyone has the same problem? Is there anyway I can solve it.

Re: [FW-1] Activation key forgotten

2006-05-29 Thread Clive Luk
Hi Szurok, I am not sure if that is the right solution. Correct me if I am wrong. I think you can reset the Activation Key by using cpconfig and choose Secure Internal Communication To reset the activation key. Cheers, Clive -Original Message- From: Mailing list for discussion of

Re: [FW-1] Cluster - Load sharing/High availability

2006-05-21 Thread Clive Luk
to use the Virtual Tunnel Interface, a new option in R60. Regards, Reinoud. -Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM wrote: - To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM From: Clive Luk [EMAIL PROTECTED

Re: [FW-1] Cluster - Load sharing/High availability

2006-05-19 Thread Clive Luk
. If this machine fails, control is passed to the next highest priority machine. If that machine fails, control is passed to the next machine, and so on. regards Zubair -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] Behalf Of Clive Luk Sent: Friday, May

[FW-1] Cluster - Load sharing/High availability

2006-05-18 Thread Clive Luk
Dear CP gurus, I have just one question regarding the clustering on NGX60. High Availability Will have 2 or more members. When the primary cluster down the secondary will pickup. Without load sharing in between, Load Sharing Will have 2 or more members. Loan will share among members. For

[FW-1] new installation

2006-05-17 Thread Clive Luk
Dear CP gurus, I am trying to do a fresh installation on a solaris 9. Here is my question and step. I want to install a FW gateway and smartcenter on 2 different box. I am wondering what to choose on FW gateway and what to choose on a smartcenter. Here are the options. 1.[ ] VPN-1 Pro. 2.[ ]

Re: [FW-1] export configuration

2006-05-04 Thread Clive Luk
. 4. Follow the cluster configuration guidelines to configure the smart dashboard objects for the cluster. Install policy on the cluster. You will need a common IP, sync network etc. Regards, Clive Luk wrote: Dear FW-1 list members, Hope someone can help me here. Let me explain my

Re: [FW-1] export configuration

2006-05-04 Thread Clive Luk
-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] export configuration If you want to migrate to R60, use the upgrade_export for R60. The error message indicates /conf/rulebases_5_0.fws does not exists. Did you check if the file exists under $FWDIR/conf. Ramki CCNA, CCSE-NGAI Clive Luk wrote

[FW-1] hotfix question

2006-05-03 Thread Clive Luk
Hi all, One more silly question. http://www.checkpoint.com/downloads/latest/hfa/vpn1pro_express.html#r60 is this the latest hotfix for NGX60? Thanks! Cheers, Clive = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL

[FW-1] export configuration

2006-05-03 Thread Clive Luk
Dear FW-1 list members, Hope someone can help me here. Let me explain my situation. I am currently running single NGX55 on Solaris 8 and SmartCenter on a different box (Solaris 9). I have been assigned to a project to setup a cluster(load balance/fail-over) firewall. I have just setup a test

Re: [FW-1] hotfix question

2006-05-03 Thread Clive Luk
Subject: Re: [FW-1] hotfix question Yes. HFA-03 is the latest hotfix for R60. Regards, Ramki Clive Luk wrote: Hi all, One more silly question. http://www.checkpoint.com/downloads/latest/hfa/vpn1pro_express.html#r60 is this the latest hotfix for NGX60? Thanks! Cheers, Clive

Re: [FW-1] export configuration

2006-05-03 Thread Clive Luk
a common IP, sync network etc. Regards, Clive Luk wrote: Dear FW-1 list members, Hope someone can help me here. Let me explain my situation. I am currently running single NGX55 on Solaris 8 and SmartCenter on a different box (Solaris 9). I have been assigned to a project to setup a cluster

[FW-1] Mailing list archive

2006-04-04 Thread Clive Luk
Hi all, Has fw-1-mailinglist got archive anywhere? Thanks in advance! Cheers, Clive = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail

Re: [FW-1] export log question

2006-02-02 Thread Clive Luk
it does after an install. Did you try the export after? It may work now (depending on if your licensed, I think). Christian Chiaverini -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Clive Luk Sent: Wednesday, February 01, 2006 8

Re: [FW-1] export log question

2006-02-01 Thread Clive Luk
, it will not work. Remember the 2006-01-30_235900.log also has pointer files associate with it. The output file can be anywhere but the input file (-i) has to be in the $FWDIR/log directory. cisco4ng Clive Luk [EMAIL PROTECTED] wrote: Hi cisco4ng, Thanks for the quick reply. I am

Re: [FW-1] export log question

2006-02-01 Thread Clive Luk
:[EMAIL PROTECTED] On Behalf Of Clive Luk Sent: Wednesday, February 01, 2006 5:46 PM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] export log question Thanks cisco4ng Christian! I have tried to export the log in the default log directory. But still no luck. However, I have

[FW-1] export log question

2006-01-31 Thread Clive Luk
Hi all, I hope someone can help me here. I want to export a raw log to an ASCII file. I have used this command: fw logexport -n -m raw -i fw.log -o out.txt However, I got the following error message. ld.so.1: fw: fatal: relocation error: file fw: symbol __user_mode_inet6__: referenced symbol

[FW-1] VPN quesiton

2005-12-14 Thread Clive Luk
Hi all, I am new to CP. I would like a help of setting up a VPN tunnel from our LAN to another external company' LAN. I have found some doco on the net. However, on my SmartDashboard. I couldn't find a 'VPN' column. I am using SmartDashboard NG with Application Intelligence (R55) Build 127. It

Re: [FW-1] VPN quesiton

2005-12-14 Thread Clive Luk
Hi Lars, Thanks for your quick reply. I have checked. I have got the VPN checked. I am sure we have got the license. Is there any quick way to check to confirm that we have the VPN license? Thank you! Kind Regards, Clive -Original Message- From: Mailing list for discussion of

Re: [FW-1] VPN quesiton

2005-12-14 Thread Clive Luk
Hi, One more thing is I don't even have the VPN Manager Tab. Is that something simple? Cheers, Clive -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Lars Troen Sent: Thursday, 15 December 2005 12:02 PM To:

Re: [FW-1] VPN quesiton (Solved)

2005-12-14 Thread Clive Luk
Thanks RK! I can see it now! Cheers, Clive -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Ramakrishnan Pillai Sent: Thursday, 15 December 2005 1:34 PM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] VPN

Re: [FW-1] VPN quesiton

2005-12-14 Thread Clive Luk
) -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Clive Luk Sent: Thursday, 15 December 2005 11:51 AM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] VPN quesiton Hi all, I am new to CP. I would like a help of setting up a VPN

[FW-1] Allow email is sending to some address

2005-04-06 Thread Clive Luk
Hi all, Is Checkpoint possible to setup a rule to allow an email send to a few email address? E.g. Source from Any Destination to smpt.mailserver.com Email send to [EMAIL PROTECTED] or [EMAIL PROTECTED] are accepted but not others? Cheers, Clive

[FW-1] Need help on SmartDashboard R55

2004-10-28 Thread Clive Luk
services are up and running. For more information use the SmartView Status application. Can someone please help. I can install and verify the policy. But just can save it. Thanks, Clive Luk = To set vacation, Out-Of-Office, or away messages, send an email