Re: [FW-1] Nokia and CLI

2006-01-09 Thread secinfo
Cool. Thank you for this. Have a nice day. Aurélien. Christian Chiaverini wrote: You can dump it to a file like so: clish -c show route all routeimport.dat I don't know about importing it. If there's a way to do it in clish then you can script something using text parsing from that

[FW-1] Secure remote Client Version

2006-01-09 Thread Robert Fowler
Quick Question that i need answers to: I have a client that is currently on NG FP1 and wishs to upgrade to NGX. The are using Secure remote for client connections. What I need advise on is what versions of secure remote will work with the firewall. For isnatance: 1. Will the

Re: [FW-1] Nokia and CLI

2006-01-09 Thread Ramdas, Venkata (GE Healthcare, consultant)
Hello, You can use iclid tool to display the static routes. Nokia[admin]# iclid Firewall sh route static Copy the output to a text file. With little modifications like importing this comma based text into XLS sheet and removing the unnecessary columns , you will have the static route table.

Re: [FW-1] Checkpoint Hotfix Listings

2006-01-09 Thread Reinhard Stich
hi, the release notes tell you about things that are fixed or changed in a hotfix. cheers reinhard At 12:19 09.01.2006, you wrote: Morning all - does anyone know where I can find information on what individual hotfixes contain ? I am after hotfix 388 amongst others. Thanks.

[FW-1] Checkpoint Hotfix Listings

2006-01-09 Thread Neil Kemp
Morning all - does anyone know where I can find information on what individual hotfixes contain ? I am after hotfix 388 amongst others. Thanks. = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of

[FW-1] Problem with packages

2006-01-09 Thread Johan Engdahl
I´m running SecurePlatform NG AI R55 HFA-08 Whenever I try to add a package to my SmartUpdate software repository i get the message Error: the input file is not a valid package. I wonder what the problem might depend on or why this error occurs. It´s the same if I try to add an HFA package

[FW-1] ipso 3.8 vrrp monitor circuit problem

2006-01-09 Thread Fiorenzi Alessandro
Hi, we had a particular porblem, the cisco switch connected to one interface of our Ipso has had a particolar problem: it took link with firewall up, but all other link were down. The information arriving from the switch were uncorrect with BAD vrrp checksum under this condition our cluster

Re: [FW-1] Problem with packages

2006-01-09 Thread cisco4ng
Hi, I have not used SmartUpdate for a while because of so many problem that comes with it. But I suspect the package that you downlaed is not the one that is used for SmartUpdate. To be sure, download the package again and run: tar -xzpf .tgz if you see a SU

Re: [FW-1] SMTP Forwarding

2006-01-09 Thread John Lindblom
That's perfect, now why didn't I think of that. John Schrack, Robert [EMAIL PROTECTED] wrote on 01/09/2006 07:50:23 AM: John, I had tried to reply to the list, but I don't think the message made it... If you have another public IP address you could use to statically NAT the anti-spam

Re: [FW-1] SMTP Forwarding

2006-01-09 Thread Rob Schrack
[FW-1] SMTP ForwardingIf you have another public IP address you could use to statically NAT the spam filter, you could always add a 2nd MX record with a higher weight. If the spam server is down, mail servers will automatically try the other server. Rob - Original Message -

[FW-1] Error Licence

2006-01-09 Thread Edouard Zorrilla
Hi Gurus., I am getting the next error licence: Jan 9 11:39:09 fwpluspetrol [LOG_CRIT] kernel: Informatory: the current VPN-1 FireWall-1 license allows only 256 internal hosts. Jan 9 11:39:09 fwpluspetrol [LOG_CRIT] kernel: If this is different from the license you intended to purchase,

Re: [FW-1] Error Licence

2006-01-09 Thread Ahti Akel
Hi Edouard, CPVP-VIG-250-3DES-NG -- VPN-1 Internet Gateway for 250 users. You don't have the unlimited license. -- BR! Ahti On Mon, Jan 09, 2006 at 01:27:59PM -0500, Edouard Zorrilla wrote: Hi Gurus., I am getting the next error licence: Jan 9 11:39:09 fwpluspetrol [LOG_CRIT] kernel:

Re: [FW-1] Upgrading Firewall Module

2006-01-09 Thread Lindsay Hill
Just update the firewall object, reset SIC, and you're good to go. Once you've got SIC working, you can push out licenses and policy. No need to export anything from the module. Only other things to consider are interfaces and routes, plus any SecurID or client auth stuff you might have on

Re: [FW-1] Error Licence

2006-01-09 Thread Thorsten Behrens
Jan 9 11:39:09 fwpluspetrol [LOG_CRIT] kernel: Informatory: the current VPN-1 FireWall-1 license allows only 256 internal hosts. [] Sign {LICENSE 200.y.x.z never CPVP-VIG-250-3DES-NG ^^^ That's not an unlimited license. Please note that: 1. This

Re: [FW-1] Error Licence

2006-01-09 Thread Edouard Manuel Zorrilla Calancha
Thanks a lot for your time Gurus, However I have a question, What does CPVP-VPS-1-NG FW1:5.0:DBVR_UNLIMIT mean ? Isn't UNLIMIT ? Besides the message says: the current VPN-1 FireWall-1 license allows only 256 internal hosts., so it is talking about 256 users, why not 250 as the license say.

Re: [FW-1] Error Licence

2006-01-09 Thread Thorsten Behrens
You really should take your licensing questions to CP advocacy or your reseller. That said -- one more --- What does CPVP-VPS-1-NG FW1:5.0:DBVR_UNLIMIT mean ? CPVP-VPS-1-NG is unlimited SecuRemote. FW1:5.0:DBVR_UNLIMIT I don't recognize - might be unlimited data base versions, judging by the

[FW-1] eventia reporter error

2006-01-09 Thread Lino Eduardo Avila Rodríguez
Hi! I have the following error in the eventia reporter. I installed the reporter on ngx in a distributed configuration. I installed the policy and everything worked fine. I log into the GUI it connects to the reporter fine but in the management section the consolidation session status is N/A or

Re: [FW-1] Problem with packages

2006-01-09 Thread Lindsay Hill
If you've downloaded an HFA, you'll need to unpack the *HFA*.tgz file, and then separately import the cpshared* and fw1* packages contained within. You can't just import the HFA as one chunk, it needs to be separate. I understand what cisco4ng means about issues with SmartUpdate. I used

Re: [FW-1] Error License

2006-01-09 Thread Thorsten Behrens
The reason you are seeing this is because, It is currently seeing 256 hosts and it knows that this in violation of the current license. the current VPN-1 FireWall-1 license allows only 256 internal hosts. Umm, no, that's an informatory message during initial startup and policy install

Re: [FW-1] Upgrading Firewall Module

2006-01-09 Thread Shane Presley
Sounds perfect. I've already converted my routes and interface configs. So I should be all set. Thanks for the reply! Shane On 1/9/06, Lindsay Hill [EMAIL PROTECTED] wrote: Just update the firewall object, reset SIC, and you're good to go. Once you've got SIC working, you can push out

Re: [FW-1] Error License

2006-01-09 Thread Edouard Zorrilla
Thanks for your help, Regards - Original Message - From: Thorsten Behrens [EMAIL PROTECTED] To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Sent: Monday, January 09, 2006 4:48 PM Subject: Re: [FW-1] Error License The reason you are seeing this is because, It is currently seeing 256