Re: [FW-1] Retransmitted data does not match original data error??

2004-10-05 Thread Tyink R.H.G. Ronny
Hello Jacob, 2 Things i found out about Retransmitted data does not match original data. First is a problem with http keep-alives mostly from proxy servers, checkpoint does not support this kind of keep-alives (SolutionID sk15619). Second was my problem, i had a router which calculated the TCP

Re: [FW-1] Cannot scp to SPLAT R55

2004-10-05 Thread Brockhoven, Werner
Hi, I guess this happened after installing HFA04. You need to create a file /etc/scpusers which holds the users you want to allow to scp. It's also a KB on CP if you search for it. Werner -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On

[FW-1] No logging after import

2004-10-05 Thread David CALLEBAUT
Hi, This morning we had to export and re-import the configuration on our Management station in order to solve an problem. The problem was indeed solved but ever since the export/import the loggin of the firewall modules stopped. We checked the SIC communication but no problem there. We did

Re: [FW-1] Cannot scp to SPLAT R55

2004-10-05 Thread Kim Longenbaugh
I can see the fnords! [EMAIL PROTECTED] 10/05/04 05:43AM Check SecureKnowledge! Solution ID: sk26258 In HFA 04 the SSH package was hardened to prevent users with regular permissions from copying files to SecurePlatform from the outside Procedure: In expert mode on SecurePlatform: 1) create

Re: [FW-1] No logging after import

2004-10-05 Thread Mónica Salvia
yes. a cpstop/cpstart fixed it. regards, mónica David CALLEBAUT [EMAIL PROTECTED] Sent by: Mailing list for discussion of Firewall-1 [EMAIL PROTECTED] 05/10/2004 09:04 Please respond to Mailing list for discussion of Firewall-1 To: [EMAIL PROTECTED] cc:

Re: [FW-1] Cannot scp to SPLAT R55

2004-10-05 Thread Chris 'Chipper' Chiapusio
Check SecureKnowledge! Solution ID: sk26258 In HFA 04 the SSH package was hardened to prevent users with regular permissions from copying files to SecurePlatform from the outside Procedure: In expert mode on SecurePlatform: 1) create /etc/scpusers file [EMAIL PROTECTED] touch /etc/scpusers 2)

Re: [FW-1] Checpoint 4.1 SP4

2004-10-05 Thread Hal Dorsman
Exchange 5.5 to 2000. . . h, let's see, it's 2004, right? Checkpoint 4.1 SP4. . . hmmm, let's see. . . suggestions? Upgrade sooner. In the meantime, in addition to the static nat you will need a static host route mapping your legal IP to your internal. You will also need an arp getting out

Re: [FW-1] No logging after import

2004-10-05 Thread Kalpesh Patel
Hello Can anyone help me with this error message please??? I'm trying to push out a policy to my France Firewall from the management station in the UK and it's failing. I also can't do a fetch from the module. I've tried to unload the localhost and push out a new policy and that fails too.

[FW-1] Configuring ClientLess VPN makes access to HTTPs sites fail

2004-10-05 Thread Antonio Costa
Hi all, I'm implementing Clientless VPN in a SPLAT R55 envioment with one management and two inspection modules with ClusterXL. The procedure i did followed all instructions mentioned at the following SKs: Configuring User Authentication, Clientless VPN, and Outlook Web Access

Re: [FW-1] SecureRemote not Assigning an IP to client

2004-10-05 Thread Joe Pope
You need to use SecureClient. What you want to do is use Office Mode, which will issue the client an IP address, along with internal DNS and WINS servers info (if desired). -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Brian

[FW-1] SecureRemote not Assigning an IP to client

2004-10-05 Thread Brian Hope
I'm trying to set up SecureRemote. Currently the client will connect, but it will not get an IP address. On the connection status, the Assigned ip will either say N/A or Failed. I've tried setting the firewall up to assign the IP from a pool, and I've also tried assigning from a dhcp server. I'm

[FW-1] Nokia errors

2004-10-05 Thread Gary Scott
Has anyone ran into these errors on the Nokia platform? [LOG_CRIT] kernel: FW-1: fwconn_get_bits: failed to get bit value of bit category 6 = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of

Re: [FW-1] SecureRemote not Assigning an IP to client

2004-10-05 Thread Thorsten Behrens
You are talking about Office Mode here? Office Mode is only supported with SecureClient (needs a license), not with SecuRemote. -Original Message- From: Brian Hope [mailto:[EMAIL PROTECTED] Sent: Tuesday, October 05, 2004 2:34 PM To: [EMAIL PROTECTED] Subject: [FW-1] SecureRemote

[FW-1] VPN-1 and high availability

2004-10-05 Thread Ana Asuaje
Does VPN-1 on Solaris 8 supports high availability scheme? Thanks a lot = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail

Re: [FW-1] SecureRemote not Assigning an IP to client

2004-10-05 Thread Matt Arntsen
Seems people think you are trying to give out address via DHCP which requires OfficeMode in SecureClient. Did you just mean that SR users never receive a translated IP for use within the network? matt -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL

Re: [FW-1] SecureRemote not Assigning an IP to client

2004-10-05 Thread William Iselin
You need SecureClient, not SecuRemote. Also you need to use Office Mode to actually assign the client itself an IP address. IP pool nat only translates the clients IP at the gateway. Regards, Bill -Original Message- From: Brian Hope [mailto:[EMAIL PROTECTED] Sent: Tuesday, October 05,

Re: [FW-1] Configuring ClientLess VPN makes access to HTTPs sites fail

2004-10-05 Thread Steve Butterfield
Antonio I had the same problem - I logged a case with checkpoint - It appears to be a mistake in the documentation though by the time I set it back and got it working I couldn't find the original document i had followed so maybe the docs have now been fixed ?. Anyway you do not change the

[FW-1] Site to site vpn between FP3 firewall module and VPN-1 Edge X-series

2004-10-05 Thread Kingsley Chu
Dear All, Background: - we had setup a vpn tunnel between FP3 firewall module(windows platform) and VPN-1 Edge X-Series(firmware: 4.0.73x) - One windows 2000 AD server behind VPN-1 Edge X-Series - One windows 2000 standalone server behind FP3 firewall module (windows