Re: [FW-1] hardware requirements

2004-07-26 Thread Nick Brandson
Try the following web Systems Reported as Working http://www.checkpoint.com/products/supported_platforms/reported.html Recommended Hardware http://www.checkpoint.com/products/supported_platforms/recommended.html Or you can try Safe-IP from HP, a bundle appliance from CP HP, with Rainfinity for

[FW-1] XAUTH support to allow authentication of dial-up user in addition to IPSec authentication

2004-07-26 Thread Dittl,Klaus-Dieter HG-Dir its-ds
Hi, what i am looking for is to combine the authentication ( secure-id) for dial-up user and IPSec authentication ( with Certificates). what i found out is that there is no way. I hope in the community is someone how has the acknowledge. What we use ist CP-NG- FP3 HFA 325 and SC-R55. Regards,

[FW-1] Smartdefense and flows

2004-07-26 Thread Tom Stala
I am having a discussion at work about how SmartDefense works with flows. From what I know of how CheckPoint handles the connection it checks source destination and what it is doing and then allows the connection to flow through at a lower level in the OSI. It places the basic information of

Re: [FW-1] VPN Secureremote routing problem

2004-07-26 Thread Chris Hoff
Are all the subnets defined properly for you VPN domain? Could it be the 2 subnets you can get to fine are directly attached to the firewall, while the third is off a router (WAN)? If this is the case, you would not be able to use the All IP addresses behind gateway based on Topology

[FW-1] SecuRemote command line executable

2004-07-26 Thread Mateo [EMAIL PROTECTED]
Hi... Somebody knows if there are some command in windows to Star Up the SecuRemote or SecureClient agent? Saludos, Mateo Cabrera - Soporte Técnico Security Advisor www.sadvisor.com = To set vacation, Out-Of-Office, or away messages, send an

[FW-1] AW: [FW-1] hardware requirements

2004-07-26 Thread Martin, Gregor
If you need more then just a Firewall-1 then try the following link: http://www.crossbeamsystems.com/securitysolutions.asp The Appliances from Crossbeam Systems provides an all-in-one security solution. Regards, Gregor -Ursprüngliche Nachricht- Von: Nick Brandson [mailto:[EMAIL

Re: [FW-1] VPN Secureremote routing problem

2004-07-26 Thread Ray
Are the operating systems all the same on each computer? Are you trying to tracert by IP address or DNS name? Which version of SecuRemote: the original R55 release or the R55 HFA02 release? Does an nslookup on the internal host return the correct IP address? The reason I'm asking is that XP has

[FW-1] Tips in replacing management server/firewall

2004-07-26 Thread McKinlay, Ken
Greetings, I have just received a new Nokia firewall to replace my older Nokia IP440 management server/firewall. The current system is running NG with FP 3 and I have 3 other firewalls being managed from it. Is there a how-to or at least some tips on how to, relatively painlessly, migrate the

Re: [FW-1] SecuRemote command line executable

2004-07-26 Thread Joe Pope
These work for SecuRemote/SecureClient R55: scc startsc (starts SecuRemote/SecureClient) scc stopsc (stops SecuRemote/SecureClient) You can find the reference for command-line on the VPN-1 NG with Application Intelligence (R55) PDF document available from Check Point. The SecureClient

Re: [FW-1] VPN Secureremote routing problem

2004-07-26 Thread Matt Arntsen
Check that your subnets are listed in the encryption domain on the firewall rulebase. Seems like the private IP's are not being sent through the VPN. matt -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of SIBEL MEREY Sent: Monday,

[FW-1] vpn1 encription problem

2004-07-26 Thread Schiavetta, Massimo
Hi all i'm experiencing a strange problem with a vpn on NG3: i want to let go thru the tunnel 2 machines, one on the inside-net of the fw, the other reaching the fw-inside thru a couple of router i got the corrects routes, added the 2nd machine to the fw topology, but only the one on the

Re: [FW-1] SCV questions

2004-07-26 Thread Joe Pope
Gary, Welcome to the wonderful world of SCV checking! I have had severe headaches from this and Check Point has not been very helpful with figuring this out! Here is what you should try: 1. Under GLOBAL PROPERTIES, go to REMOTE ACCESS SECURE CONFIGURATION VERIFICATION (SCV). Hopefully you are

[FW-1] VPN Tunnel stability and throughput performance between 2 Nokia IP440's running NG FP3.

2004-07-26 Thread Alan Choyna
Hey people, We're moving to a co-locate environment, and my client wishes to use a VPN tunnel between 2 Nokia ip440's running NG PF3 to connect the internal Network to our DMZ networks at the co-locate space about 50 miles away. l'm pitching for a dedicated T1 line to our IP440 at the co-lo,

Re: [FW-1] SmartCenter Blocking on R55?

2004-07-26 Thread Darren Martz
Thank you for the response Nathan. We can connect with the GUI client but only on the original IP addresses I assigned during the initial installation. I will try unloading the policy tomorrow - our firewall is at a colocation facility. You comment on adding a FW rule surprised me, and perhaps I