Re: [FW-1] Site to site VPN between CP NGX R60 and Fortigate

2006-03-09 Thread SIBEL MEREY
Hi Sagiv, We have tried to change user.def file in our NGX but i has not worked. We can not use VYI because our CP is express. You have mentioned There is one quick work around for this issue but I am not sure you will like it... Could you send us this solution, maybe it will help us. Thanks

Re: [FW-1] CLUSTER XL

2006-03-09 Thread Fabrice Barutel
Hi Annette, it make me think about a Spanning Tree symptom between your two Cisco switches. Have you connected each VLAN with a cross-over cable, or did you do VLAN tagging with a Cisco Trunk (only one cross-over cable) ? If you put multiple cross-over cable over each VLAN, Spanning Tree will

[FW-1] fwx_auth_expiration in Windows environment.

2006-03-09 Thread Syed Abdul Hameed
I am running checkpoint firewall on windows environment, Can anyone of you advise me how can i add line fwx_auth_expiration=120 to increase the expiration time from 30 to 120 using Microsoft windows platform. Would appreciate an urgent response. Regards, Syed Abdul Hameed Engro Chemical

Re: [FW-1] NGX Secureplatform problem.

2006-03-09 Thread fico gid
Hi , You can check on /var/log/boot.log file for some clues or if there is any core files dumped. Fico On 3/8/06, Bhavin Gandhi [EMAIL PROTECTED] wrote: 'messages' file under /var/log Regds -Original Message- From: Mailing list for discussion of Firewall-1

Re: [FW-1] NGX Secureplatform problem.

2006-03-09 Thread fico gid
Or you can try memtest (different from memtest86) from http://pyropus.ca/software/memtester/ You can give it a real stress test on your memory to see if that is your problem. Fico On 3/9/06, fico gid [EMAIL PROTECTED] wrote: Hi , You can check on /var/log/boot.log file for some clues or if

Re: [FW-1] CLUSTER XL

2006-03-09 Thread Warrington Bruce - bwarri
You might be seeing a problem with the same multicast mac address showing up in the cam table on both switches. Yes, you can statically code that on the switch to work, but I think that's not intuitive to someone else when they go in for troubleshooting, among other reasons that I'd say to try

Re: [FW-1] Connections not removed from connection table

2006-03-09 Thread Doyle, Craig
Alex, We experienced this as well and worked with CheckPoint support for several hours on it just the other day. Support stated that they believe it is a bug in the kernel that handles NAT resources. There may be a fix for it in the next HFA. In the meantime they had us implement a

[FW-1] Clustering Question on NGX with 2 routers, 2 T1's

2006-03-09 Thread Tahir Khan
Hello, We currently are testing a configuration with NGXR60 running on two IPSO350's connected to 2 Cisco Routers each with a T1 in it providing load balancing. The cisco routers are set up on two /25 blocks that encompasses our /24 block, and each router listens in each block with HSRP.

Re: [FW-1] Site to site VPN between CP NGX R60 and Fortigate

2006-03-09 Thread Sagiv Filler
Hi, As for the user.def, as I said it has been modified so. What about changing the $FWDIR/conf/objects_5_0.C : ike_use_largest_possible_subnet to false ? The fast work around for this issue: Basically, the problem occurs when each gateway tell the other gateway what is its

Re: [FW-1] Least used rules

2006-03-09 Thread Mark Senior
Well, it's not at all unreasonable that there might be a counting mechanism independent of the logging mechanism. For example, the FreeBSD (and Mac OS X) ipfw firewall, the Linux iptables firewall, the Cisco PIX firewall, as well as Cisco router ACLs, all have some counters associated with rules

Re: [FW-1] dynamic interface resolving

2006-03-09 Thread Gary Scott
With this enabled it still would not work. On a hunch I started digging through the firewall properties with gui dbedit a found the entry for apply_resolving_mechanism_to_SR and it was set to false. Which based on the correct gui settings it should have been true. Changing this to true with a