Re: [FW-1] VPN Secureremote routing problem

2004-07-28 Thread SIBEL MEREY
** High Priority ** Ray, thank you very much, after your mail i unistalled tcp/ip protocol and than reinstalled it. So now it works:) Thanks again.. [EMAIL PROTECTED] 28.07.2004 04:41:40 Yes, NT does the same thing. If there is a NIC installed in the computer, it holds the DHCP IP address

Re: [FW-1] Veritas IPSO

2004-07-28 Thread Hannu Liljemark
On Sun, Jul 25, 2004 at 09:38:34AM -0700, Nick Brandson wrote: My colleague wants to back up the OS (IPSO) as well? Is it necessary to do so? Just use IPSO's own backup feature and schedule it to do nightly backups or whatever. If it's just a enforcement, I don't see any reason to take

[FW-1] Securemote DNS

2004-07-28 Thread Alaric Turner
We have an intreasting problem, Laptop users use Securemote (R56) to connect to the corporate LAN when they are off on the raod, this works fine. As part of this I've got a split brain DNS setup so when resolving internal names the clients use an internal DNS server all traffic is encrypted.

[FW-1] ISP Redundancy

2004-07-28 Thread Ilia Shapira
I have ISP Redundancy configured on my FW, I use one DSL line with Cisco Router and another one with PPPOE DSL Modem. I use Load Sharing configuration. The status of my both connections is ok, but I see that all the traffics goes via my first connection and no traffic goes to my second modem. When

[FW-1] SecuRemote command line interface+ open windows (in transparent mode)

2004-07-28 Thread Mateo [EMAIL PROTECTED]
Guys.. Sorry that insist with this problem... I only want to know if there are some command (via command line interface) to type and open the secuRemote window that permit me to create e.g a new site, update the topology...etc, the classic SecuRemote window. How to open this window with a

Re: [FW-1] Veritas IPSO

2004-07-28 Thread Wayne Ho
One of the reason you want to backup the enforcement point is the routing table which is not saved in management station. Wayne --- Hannu Liljemark [EMAIL PROTECTED] wrote: On Sun, Jul 25, 2004 at 09:38:34AM -0700, Nick Brandson wrote: My colleague wants to back up the OS (IPSO) as well?

[FW-1] Cluster node goes disconnected

2004-07-28 Thread Shane Presley
Hi there, I have an NG AI cluster with two firewalls. Each is Solaris 8. They run High Availability, New Mode. Several times a day (4-6) I get an alert that the primary node has become disconnected. Specifically I have the SmartCenter Server set to alert me for disconnects, so I get an e-mail:

Re: [FW-1] Securemote DNS

2004-07-28 Thread Demetrio Leon Guerrero (DLG)
In your previous configuration you may have had Split-Tunnelling enabled. Split-Tunnelling allows local and VPN access. In newer versions of the VPN Client, Split-Tunnelling is turned-off because it may open vulnerabilities to your network. DLG Lattestone Corporation Phone : 703-716-1066 Fax

[FW-1] Checkpoint R55 and VPN1 Edge

2004-07-28 Thread neil.kemp
Good afternoon all. I have a customer who is looking at putting a VPN1 edge box in at a remote site, to encrypt traffic between the main site and this remote site. Has anyone installed these so they are controlled by the main sites R55 firewall at all ? Is it easy to do / straight foreward to

Re: [FW-1] SecuRemote command line interface+ open windows (in transparent mode)

2004-07-28 Thread Huiqi_Liu
Mateo Cabrera wrote: I only want to know if there are some command (via command line interface) to type and open the secuRemote window that permit me to create e.g a new site, update the topology...etc, the classic SecuRemote window. How to open this window with a command? Any ideas? You

[FW-1] AW: [FW-1] Cluster node goes disconnected

2004-07-28 Thread Klaass, Randolf
Hi, A reason could be that your switches can not handle multicast pakets. You have to switch this to broadcast. Please have a lot at the clusterxl.pdf of checkpoint and you will find following statement: 'cphaconf set_ccp broadcast/multicast' Regards randolf -Ursprüngliche

Re: [FW-1] Securemote DNS

2004-07-28 Thread Stefan Schweizer
There is an Option called something like: :allow_clear_traffic_while_disconnected (false) set it to true There is a second one which sounds similiar to the above, something like: allow_clear_in_encryption_domain check that too. Regards, Stefan Am 28.07.2004 um 13:28 schrieb Alaric Turner: We have

Re: [FW-1] SecuRemote command line interface+ open windows (in transparent mode)

2004-07-28 Thread Mateo [EMAIL PROTECTED]
I forgot to say it, I tried with scc command but it don?t resolve my requirement ): Thanks Any other ideas? Saludos, Mateo Cabrera - Soporte Tecnico Security Advisor www.sadvisor.com -Mensaje original- De: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] nombre

Re: [FW-1] Checkpoint R55 and VPN1 Edge

2004-07-28 Thread Chris Hoff
Neil, First of all, the person would have to have main site setup in a Distributed fashion. From there you neeed to decide how you want to manage it - through SmartDashboard, or SmartLSM. SmartLSM is for managing a large amount of devices - Check Point says in the hundreds to thousands of

Re: [FW-1] VPN Secureremote routing problem

2004-07-28 Thread Ray
Glad you got it working! Ray From: SIBEL MEREY [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Re: [FW-1] VPN Secureremote routing problem Date: Wed, 28 Jul 2004 11:00:04 +0300 ** High Priority ** Ray, thank you very much,

Re: [FW-1] Checkpoint R55 and VPN1 Edge

2004-07-28 Thread Neil Kemp
At the moment, the main firewall will be a Nokia IP380 running checkpoint with management station and firewall installed on the same unit, so it sounds as though it may not be possible anyway at this stage. If things change, then it will be managed through SmartDashboard. There is only going to be

[FW-1] New HFA's posted + a new ASN.1 Alert

2004-07-28 Thread Ray
http://www.checkpoint.com/techsupport/hfa.html HFA08 for NG R55 HFA412 for NG R54 An ASN.1 hotfix for NG FP3 Here's the Alert for the ASN.1 patch that's applicable to all versions if aggressive mode is implemented: http://www.checkpoint.com/techsupport/alerts/asn1.html Ray

Re: [FW-1] New HFA's posted + a new ASN.1 Alert

2004-07-28 Thread Ray
In rereading it, it appears it may be applicable even if aggressive mode isn't enabled. Ray From: Ray [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: [FW-1] New HFA's posted + a new ASN.1 Alert Date: Wed, 28 Jul 2004 16:59:54