[FW-1] Access to SecureKnowledge base

2006-01-02 Thread Delava Alain
Hello, As you probably know when you only have a software subscription and no direct support contract, you only have access to a restricted part of the CP Secure Knowledge articles. I've heard that CheckPoint would give access to all articles for those having a support contract through a CSP

Re: [FW-1] Access to SecureKnowledge base

2006-01-02 Thread Ray
I don't know about this, however if you pass the CCSA test, you receive twelve months of Advanced Access to SecureKnowledge. If you pass the CCSE test, you receive eighteen months of Advanced Access. This might be an alternative for you. Ray From: Delava Alain [EMAIL PROTECTED] Reply-To:

Re: [FW-1] Access to SecureKnowledge base

2006-01-02 Thread Delava Alain
Indeed since I already followed Management I and II (NG) courses and intend to pass the CCSA then CCSE exams when I'll have enough practical experience. Hadn't thought about that. Thanks! Alain -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL

[FW-1] Strange behaviour with IPSO Clustering running Multicast Mode

2006-01-02 Thread Philippe Blavier
Hi all, I am testing an IPSO cluster with two IP380 boxes running IPSO 3.9 build 41. The cluster is connected to 3 Cisco Switch (2950 Layer2 and 4006 Layer 3). On switches I have configured the static multicast entries for interesting ports. I can create the cluster on the first box and the

[FW-1] Block Networks by country

2006-01-02 Thread Tahir Khan
Is there a way to at least block some of the major offenders? Asia? Eastern Bloc Countries? We only have US traffic, and 90% of our spam, probes come from those countries. Does anyone have any idea how much overhead this would add? Thanks! -Original Message- From: Mailing list for

Re: [FW-1] Block Networks by country

2006-01-02 Thread Roger P Herr
Create a dynamic object (network object) and use dynamic_objects command line utility to put the cider blocks of the countries you want to block. Create a rule (like rule 1) that has this dynamic object as the source and drop as action, maybe even log them if you want to see how much traffic

Re: [FW-1] Cannot connect with SecuRemote (SR)

2006-01-02 Thread Lino Eduardo Avila Rodríguez
You can try using srfw monitor It is located in the bin directory of your securemote installation. Maybe you can debug your problem with the client. Best Regards, Lino E. Avila -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of

Re: [FW-1] Strange behaviour with IPSO Clustering running Multicast Mode

2006-01-02 Thread Delava Alain
Philippe, This is not an answer to your problem but as I read that you managed to configure Cisco 2950 switches with static multicast entries for interesting ports I'm interrested to know how you did that. Indeed, in an older post on the FW1-Gurus mailing list I mentionned that I had problems

Re: [FW-1] license warning

2006-01-02 Thread Gary Scott
To follow up on this thread. The problem below which I also had Warning: Can't find:::CPMP-SMPO-U-NGX in cp.macro. License Version might not be compatible. Was solved be Checkpoint re-doing the license string, the one I had initially contained CPVP-VEE-U-3DES-MGMT-NGX CPMP-PRO-U-NGX

Re: [FW-1] Backup rules - Fix for enter issue on 'upgrade export'

2006-01-02 Thread Steffen
Ramki, after setting FWDIR=/opt/cpfw1-r55 in your script place export FWDIR in a new line, then this should work. --- Ramki Security [EMAIL PROTECTED] schrieb: I have a related question. When doing upgrade_export in a script through cron, I get an error FWDIR env variable not set. But I