Re: [FW-1] Site to Site VPN using Checkpoint NG AI and Watchgaurd 700x

2004-09-02 Thread Naseer Inamdar
Hi, Still facing problem: I have configured VPN gateways, I think I am able to establish the tunnel. But still communication is not possible giving the following error observed at in Watchguard traffic monitor: Here w.x.y.z is Checkpoint firewall NG AI (R55) VPN gateway and a.b.c.d is

Re: [FW-1] How to alert when VRRP status changes

2004-09-02 Thread Hannu Liljemark
On Wed, Sep 01, 2004 at 02:04:20PM -0400, Firewall Administrator wrote: Any tips from anyone out there who has something in place? I haven't seen anything mentioned in the Checkpoint or Nokia documentation regarding a mechanism for detecting and alerting on VRRP changes. I don't know about

Re: [FW-1] SecureClient and Internal Network Access

2004-09-02 Thread Ray
Hi Bob, Is there some reason you can't go to a current version of the firewall and SecureClient? You are putting a lot of risk into the picture if you plan on using such an old version in the real world. To see if the FP2 version is an issue, you can download an evaluation version of R55 which

[FW-1] Out of Office

2004-09-02 Thread Justin Menga
I will be Out of the Office Start Date: 3/09/2004. End Date: 6/09/2004. Hi I'm on leave Friday 3rd September, returning on Monday 6th September. If you have any urgent queries, please contact your account manager. Regards Justin Menga CCIE #6640 (R/S + Security) CISSP CCSE MCSE+I Design

Re: [FW-1] Out of Office

2004-09-02 Thread Previtera, Sal
Thank you for letting all of us knows about it!!! -Original Message- From: Justin Menga [mailto:[EMAIL PROTECTED] Sent: Thursday, September 02, 2004 7:08 AM To: [EMAIL PROTECTED] Subject: [FW-1] Out of Office I will be Out of the Office Start Date: 3/09/2004. End Date: 6/09/2004.

[FW-1] CP as a reverse proxy

2004-09-02 Thread O'Flynn, Derek
Can CheckPoint be configured to act as a reverse proxy for internal servers? If not any suggestions? I have the following config currently. Server not in DMZ, but needing Internet connectivity. It's not in the DMZ for a variety of reasons. However, this creates a security hole in the

Re: [FW-1] URI Resource

2004-09-02 Thread O'Flynn, Derek
You could try the URI resource to do that, but I think that will be limited in its effectiveness. If you want something like that you may look a URI filtering company that specializes in blocking sites and spyware related websites. My experience with URI resources is as soon as you put these on

[FW-1] Passive FTP

2004-09-02 Thread John Ruff
My fw1-ng is reject ftp-pasv packet with this error: message_info: Active command received while working in Passive mode. Any ideas how to resolve this. Thanks -- ___ John Ruff [EMAIL PROTECTED] No one can see past a choice they don't understand. --Oracle

Re: [FW-1] CP as a reverse proxy

2004-09-02 Thread Covington, Chris
I don't believe FW-1 can do that, but why don't you just get an Apache box in the DMZ and use mod_proxy? Chris ps - can't wait to receive the 50 'out of office' messages for having written this -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED]

[FW-1] Best reporting software for NG AI?

2004-09-02 Thread Ray
We need to purchase a reporting package that will automatically generate reports and distribute them I've just started testing an eval of SmartView Reporter but I was wondering what other programs people are using. It particularly would be nice to be able to create a report of things trying to