Re: [FW-1] Best RADIUS server

2004-08-04 Thread Charis Nassis
If you have a Windows Server you may use Internet Authentication Service, which is the Microsoft Radius server. This worked fine for me. To install the service on Win2k advanced server: Add/Remove Programs | Add/Remove Windows Components | Networking Services | Internet Authentication Service.

[FW-1] TCP Sequence Validator

2004-08-04 Thread Markus Hofbauer
Hi all, Anyone seen this message in Smartview Tracker? TCP Sequence Validator: SYN retransmit with different sequence We can see that a previous session was terminated correctly with a RST. A new connection attempt is dropped with the message above. After a RST fw-1 keeps the session in one

Re: [FW-1] Edge 4.5 firmware released - v4.5.37

2004-08-04 Thread Russell Aspinwall
Hi, I have downloaded the latest firmware release for an Edge X, however when I attempt to install it, the download completes but I get a message to check the version is correct. So I tried the previous version and got the same error. Do you have to log in via the private network in order to

Re: [FW-1] Edge 4.5 firmware released - v4.5.37

2004-08-04 Thread Ray
I didn't try the one from the CP site but I did try the one they released on the Early Availability site two days ago (same version). I inadvertently grabbed the s version instead of the x version/S200 version and got the same error. Looks like all they have on the CP site is the x version. When I

[FW-1] Enivornment Variable+before to apply the later HOTFIX (HFA_412)

2004-08-04 Thread Mateo [EMAIL PROTECTED]
Hey... I did try to apply the HFA_412 in a NOKIA 440, with IPSO 3.7, NG_AI_R54, and i did have a problem with the environment variable. The following error does appear: CPDIR is not defined as ENV variable... Execution aborted Somebody knows how to setup this before to apply the patch? Thanks a

Re: [FW-1] Asn.1 vulnerabilty without aggresive mode

2004-08-04 Thread Carric Dooley
This is apparenty a subject for debate. On Thu, 29 Jul 2004, Jochen Vogel wrote: Hi, Is there any vulnerability if i doesn´t use aggresive mode? = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the

Re: [FW-1] Enivornment Variable+before to apply the later HOTFIX (HFA_412)

2004-08-04 Thread Mateo [EMAIL PROTECTED]
And, how does to check this? Thanks matt Saludos, Mateo Cabrera - Soporte Tecnico Security Advisor www.sadvisor.com -Mensaje original- De: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] nombre de [EMAIL PROTECTED] Enviado el: miercoles, 04 de agosto de 2004 13:50

Re: [FW-1] Best RADIUS server

2004-08-04 Thread Carric Dooley
I have worked with a few and I really like Funk SBR. On Thu, 29 Jul 2004 [EMAIL PROTECTED] wrote: Hello, I have a simple question: I'm looking for a RADIUS server, and in addition to my research, I thought I'd ask all of you what you think the best commercial and/or freeware RADIUS server

Re: [FW-1] Enivornment Variable+before to apply the later HOTFIX (HFA_412)

2004-08-04 Thread Grabowski, David
Sounds like FW-1 isn't running/installed on your box. CPDIR and FWDIR aren't defined if the package isn't running/installed. -Original Message- From: Mateo [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: Wednesday, August 04, 2004 12:01 PM To: [EMAIL PROTECTED] Subject: [FW-1]

Re: [FW-1] Enivornment Variable+before to apply the later HOTFIX (HFA_412)

2004-08-04 Thread Mateo [EMAIL PROTECTED]
This is not possible, because the nokia are now in producction. The FW-1 and SVN foundation are installed and running Saludos, Mateo Cabrera - Soporte Tecnico Security Advisor www.sadvisor.com -Mensaje original- De: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED]

Re: [FW-1] BSOD whilst installing Securemote R56 on Win2k

2004-08-04 Thread Ray
Which version of SR are you using? You should be using R55 HFA03 or R56 HFA01, not the FP3 version. They're backward compatible with the FP3 gateway. Ray From: Alan Choyna [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: [FW-1]

Re: [FW-1] Asn.1 vulnerabilty without aggresive mode

2004-08-04 Thread Ray
My reading says yes. Aggressive mode allows a single packet attack, meaning a single packet with a spoofed source IP could be used to compromise your gateway and you wouldn't have any way of tracking it to the source IP. The attack if aggressive mode is disabled means the source IP could not be

Re: [FW-1] Enivornment Variable+before to apply the later HOTFIX (HFA_412)

2004-08-04 Thread Hal Dorsman
Type 'set' at the command line and look for the environment variable CPDIR. If it is not correct, go to the root directory and look at .profile. The last line should begin with a . (source command) and the path to .CPprofile.sh. You can set this manually from the command line by sourcing the