Sometimes SmartTracker as well as fw sam fail to do the trick.

I’m not sure why, its just a checkpoint bug.

In that case I just nuke it right out of the table it’stored in via:

 

fw tab –t “sam_blocked_ips” –x

 

You will be asked to confirm destruction and then it wipes the table clean so all addresses you were blocking are removed.

It’s not elegant but hey man sometimes you need a scalpel and sometimes you need an axe.

 

Peace,

sakaba

 

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
Sent: Tuesday, July 15, 2003 5:37 AM
To: [EMAIL PROTECTED]
Subject: RE: [ISSForum] How to unblock the IP from Checkpoint NG FP3

 

There is a "Clear Blocking" option under "tools" menu in SmartTracker (Log viewer) in NG, it that's what you are after.

 

Jack

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
Sent: Monday, 14 July 2003 7:34 p.m.
To: [EMAIL PROTECTED]
Subject: [ISSForum] How to unblock the IP from Checkpoint NG FP3
Importance: High

Dear Sirs,

 

Would you tell me how to unblock the IP from Checkpoint NG FP3, because I have try the following command 'fwm sam -C -i srv xxx.xxx.xxx.xxx'

 

The reply from the firewall like the below:

 

Unknown command "sam"
Usage:
fwm ver [-h] ...                                 # Display version
fwm load [opts] [filter-file|rule-base] targets  # Install Policy on targets
fwm unload [opts] targets                        # Uninstall targets
fwm dbload [targets]                             # Download the database
fwm logexport [-h] ...                           # Export log to ascii file
fwm gen [-RouterType [-import]] rule-base        # Generate an inspection
                                                 # script or a router
access-list
fwm dbexport [-h] ...                            # Export the database
fwm ikecrypt <key> <password>                    # Crypt a secret with a key
                                                 # (for the dbexport
command)
fwm dbimport [-h] ...                            # Import to database

 

Thanks !

 

Tony Wu

Reply via email to