Re: [FW-1] Upgrading Server OS on Firewall NG FP3

2005-02-09 Thread Thorsten Behrens
Does anyone know of any issues/problems with upgrading a Windows 2000 Server to WIndows Server 2003 Standard edition that runs Checkpoint Firewall NG FP3? That's not a supported combination of FW-1 and OS. If you do get it to work, you'll be without support options. The first FW-1 version

Re: [FW-1] VPN Access through home broadband router

2005-02-09 Thread Steffen
Well, you write SecuClient - do you use SecuRemote or SecureClient? If you installed the first, uninstall it and install the latter even if you have no license (it then behaves like SecuRemote). Configure it the same way as you do it now. This solved the same prob in my case. HTH Steffen ---

[FW-1] upgrade_export error on R55

2005-02-09 Thread Steffen
Hello, I am trying to backup my config on Win 2003 Smartcenter with upgrade_export and get the following error: D:\Checkpoint\FW1\R55W\confd:\upgtools\upgrade_export.exe test.tgz You are required to close all Check Point clients before the Export operation be gins. If the export fails, stop

Re: [FW-1] What is OfficeMode exactly

2005-02-09 Thread Thorsten Behrens
IP Pools works with SecuRemote to assign an internal address, too Yes and no. You do not assign an IP address as such, you NAT on the VPN-1 gateway. With OfficeMode, the IP address is used on a shim interface on the client, and thus as the source for all packets to be encrypted. It's

[FW-1] FW-1 Secure Server

2005-02-09 Thread Salomé Reillo
Do you know what is FW-1 Secure Server? Where could I find documentation about this product (installation documentation)? Thanks in advance. = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the

Re: [FW-1] upgrade_export error on R55

2005-02-09 Thread Steffen
Okay one thing more to say: When running in debug mode I get [ 2452 [EMAIL PROTECTED] Feb 10:06:39] GetVersion: Error Invalid local fw version [ 2452 [EMAIL PROTECTED] Feb 10:06:39] BuildConfigurationFile: Error Failed to get CP version Error: Failed to read local configuration info

[FW-1] PPTP with hide NAT

2005-02-09 Thread Bertrand KLOTZ
Hi all does anybody try the the patch that came with HFA10 to acces external pptp server from hide NAT behind FW1 If yes did you succeed to make it work and how ? for me it's not OK on splat and HFA12 Thanks by advance for answers Bertrand = To

[FW-1] how backup rules and network objects

2005-02-09 Thread Yasin Yasin
Hi list, I have a used R55W How Backup rules,network objects and how restore rules,network objects Best Regards --- kktc.net webmail servisi. http://webmail.kktc.net = To set vacation, Out-Of-Office, or away messages,

Re: [FW-1] PPTP with hide NAT

2005-02-09 Thread Tomas Lundner
We got this solution from CP. -- RE: Problem with the fix for PPTP behind nat Here is the answers to the queries raised regarding steps 21 and 26 in the release notes: 1. In case you do not manage to use the dbedit tool, you can perform the following on the

Re: [FW-1] VPN Access through home broadband router

2005-02-09 Thread Previtera, Sal
DRTCP is another good utility to adjust MTU sizeI used and it work great, here is a link below. http://www.dslreports.com/drtcp -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Ray Sent: Tuesday, February 08, 2005 7:55 PM To:

Re: [FW-1] how backup rules and network objects

2005-02-09 Thread Keshav Anand
Hi Yasin, You can use upgrade_export tool as it backs up the entire database, configuration , security policy ,network objects. You can write a script to transfer to SCP server in your LAN. For importing you can use this file and use upgrade_import. If you are running checkpoint on

Re: [FW-1] VPN Access through home broadband router

2005-02-09 Thread Keshav Anand
Check in your server that you are trying to access... go to command prompt and type this netstat -an check the state of tcp session. If you can see SYN_Received , it means firewall is forwarding the traffic to server and the return traffic is being dropped . You need to check out the

Re: [FW-1] how backup rules and network objects

2005-02-09 Thread Yasin Yasin
Thank you very much - Original Message - From: Keshav Anand [EMAIL PROTECTED] To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Sent: Wednesday, February 09, 2005 4:15 PM Subject: Re: [FW-1] how backup rules and network objects Hi Yasin, You can use upgrade_export tool as it backs up the

[FW-1] Having problems to connect Smartdashboard - Solved

2005-02-09 Thread Eduardo Notari
Hi all, I got to connect to the SmartCenter, by the SmartDashboard. I read in the /CPfw1-R55/opt/log/fwm.elg, that the fwm that is the SmartCenter PID, didn´t find the classes.C archive. I changed the corrupted archive by a copy and it worked. Thanks, Eduardo

Re: [FW-1] upgrade_export error on R55

2005-02-09 Thread Gary Scott
r55, r55w and r55p all have their own upgrade_export utility. The one for download on CP's site is for r55. You should be able to use the one that gets installed in the $FWDIR/bin/upgrade_tools. -GS -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL

Re: [FW-1] VPN Access through home broadband router

2005-02-09 Thread Nick Rawlins
Is your machine a member of the domain? Thats most likely the issue if its not. Many Thanks, Nick On Wed, 9 Feb 2005 20:08:05 +0530, Keshav Anand [EMAIL PROTECTED] wrote: Check in your server that you are trying to access... go to command prompt and type this netstat -an check the

[FW-1] Réf. : Re: [FW-1] PPTP with hide NAT

2005-02-09 Thread Bertrand KLOTZ
Thanks for your answer that was very useful, I didn't have the info about $FWDIR/modules/fwkern.conf however when I reboot with this file, the FX doesn't start Bertrand Tomas Lundner [EMAIL PROTECTED]@AMADEUS.US.CHECKPOINT.COM le 09-02-2005 13:34:45 Veuillez répondre à Mailing list for

[FW-1] protocol types in services

2005-02-09 Thread Sascha Picchiantano
Hi there, is there a list or documentation about the different protocol types that you can set when you defince advanced options of a service? Thanks, Sascha = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in

[FW-1] Pass DHCP Requests

2005-02-09 Thread Goran Jovanovic
Hi, Can I pass DHCP requests from the DMZ to the private network? If so what do I need to enable? I am running NG Feature Release 1. Or where should I go and look? Thanx Goran Jovanovic = To set vacation, Out-Of-Office, or away messages,

[FW-1] Platform Recommendation?

2005-02-09 Thread Shane Presley
Hello, We run CheckPoint FW-1 on Solaris with ClusterXL for our primary firewalls. That handles all our production traffic. Currently our backup network is 100MB to the backup clients, and 1000MB to the backup server. That backup network is not firewalled (there are multiple segments). It

Re: [FW-1] Platform Recommendation?

2005-02-09 Thread Alan Choyna
We use DL380's, as you have room for two 4 port cards (http://www.intel.com/network/connectivity/products/pro1000mt_quad_server_adapter.htm) as well as the 2 gigabit ports that come with the server, as well as having redundant power supplies. We use DL360's for our other location, with one four

Re: [FW-1] Platform Recommendation?

2005-02-09 Thread Stala
Crossbeam has some nice equipment - Original Message - From: Shane Presley [EMAIL PROTECTED] To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Sent: Wednesday, February 09, 2005 9:06 PM Subject: [FW-1] Platform Recommendation? Hello, We run CheckPoint FW-1 on Solaris with ClusterXL for

Re: [FW-1] Platform Recommendation?

2005-02-09 Thread Shane Presley
Sounds like a DL380 would do it. So that is different than SecurePlatform? What OS does it run under the hood? Thanks, Shane On Wed, 9 Feb 2005 20:48:31 -0600, Alan Choyna [EMAIL PROTECTED] wrote: We use DL380's, as you have room for two 4 port cards

Re: [FW-1] Platform Recommendation?

2005-02-09 Thread Jameel Akari
On Wed, 9 Feb 2005, Shane Presley wrote: Sounds like a DL380 would do it. So that is different than SecurePlatform? What OS does it run under the hood? Hmm, I think you're a little confused. SPLAT (Secure Platform) is Checkpoint's bundled FW1 and OS product. It is a customized and hardened

Re: [FW-1]

2005-02-09 Thread Matthias Leu
Gkhan GLEN wrote: Hi everyone, I want to block all access ICQ,MSN Messenger and other instant messaging program in my network, how can i do it?can you help me please? Thank You. Gkhan GLEN Hi, have a look at the Tab SmartDefense (R54/R55). Under Application Intelligence - Web - HTTP Protocol

Re: [FW-1] Platform Recommendation?

2005-02-09 Thread Sascha Picchiantano
hi, SPLAT (Secure Platform) is Checkpoint's bundled FW1 and OS product. It is a customized and hardened (well, stripped anyway) version of Linux, into which FW1/VPN1 has been ported. and that hardened linux is questionable and has been tampered and hacked by at least one well known german IT

Re: [FW-1] Platform Recommendation?

2005-02-09 Thread Keshav Anand
Alteon Switch Firewall from Nortel Networks (http://www.nortelnetworks.com) also would suffice your requirement. Check out ASF 5109 that comes with 4 10/100 interfaces and 2 10/100/1000 interfaces The appliance comes pre loaded with checkpoint latest software

Re: [FW-1] Platform Recommendation?

2005-02-09 Thread Alan Choyna
The HP DL360 DL380 are the hardware recommendations l was making to you. You would install Secure Platform on them (20 minutes max, it's that simple) and then go from there. Depending on what Checkpoint version you're currently running will determine how easy it would be to migrate to SPLAT

Re: [FW-1] upgrade_export error on R55

2005-02-09 Thread Steffen
Thanks Gary that's it didn't know about that. --- Gary Scott [EMAIL PROTECTED] schrieb: r55, r55w and r55p all have their own upgrade_export utility. The one for download on CP's site is for r55. You should be able to use the one that gets installed in the $FWDIR/bin/upgrade_tools. -GS