Re: [FW-1] NGX Upgrade issue

2006-03-24 Thread Ramki Security
Hi Adam, I am copying the output of the debugger below. I am not sure if the debugger ran properly as I seem some error like message, no debugging symbols found. I have copied the whole capture here. Let me know if you could decipher any information from this. Thanks for your help. # gdb

Re: [FW-1] RES: [FW-1] RES: [FW-1] Provider-1 CMA Migration

2006-03-24 Thread Adam BE
Hi all, I think the following procedure is easier and would solve your problem: Starting SMS of migrated CMA results in error "can't resolve DB schema key - SWSERVER_NATADDRESS" = Try this procedure: 1. mdsenv ; cd $FWDIR/conf/sofaware/ 2. mv cpmi-schema.p

Re: [FW-1] Hot Fix level

2006-03-24 Thread Ray
http://www.checkpoint.com/downloads/latest/hfa/vpn1pro_express.html - HFA 02 is current and 03 is imminent. Ray From: Hal Huntley <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] Hot Fix level

[FW-1] Hot Fix level

2006-03-24 Thread Hal Huntley
We have have just installed an NGX 6.0 system on a Solaris 9 box. What hot fix level should we be have? Right now we have no hot fixes applied to the machine. Thanks, Hal Huntley SRI International = To set vacation, Out-Of-Office, or away message

Re: [FW-1] NGx Provider-1 deployment question

2006-03-24 Thread Adam BE
Have a look at nat-traverse it might solve your NAT problem: http://linide.sourceforge.net/nat-traverse/ Best regards, Adam. Gary Scott <[EMAIL PROTECTED]> wrote: In most P-1 deployments I deal with there is no NAT for the CMA's. I would have to say don't NAT if possible. No SIC, fetch, push

Re: [FW-1] Provider-1 database revision control and Citrix

2006-03-24 Thread Adam BE
Hi, 1) I recommend running Checkpoint GUIs only on pure Windows or good Windows emulators (VMware). Yes Motif is also an option but Windows will work best. 2) I don't know if this exists in FP3 but in NGX you can got to File > Database Revisions > "View Version" and safely view the version.

Re: [FW-1] Need SP for FW-1 (4.1 sparc)

2006-03-24 Thread Reinhard Stich
hi, please contact me offline - I have SP5 for solaris ... cheers reinhard At 18:27 24.03.2006, you wrote: I am currently in the process of UGing an old FW running 4.1 on a Sun Solaris box so that I can UG it (again) to NGAI. Acccording to the install docs for NGAI, I need SP5 for 4.1 as a m

[FW-1] Need SP for FW-1 (4.1 sparc)

2006-03-24 Thread Wilson Mohr
I am currently in the process of UGing an old FW running 4.1 on a Sun Solaris box so that I can UG it (again) to NGAI. Acccording to the install docs for NGAI, I need SP5 for 4.1 as a minimum. Unfortunately, I only have SP4. Can I UG from SP4? If not, does anyone have SP5 or SP6 (strong)? I ca

[FW-1] NG R55 HFA17 - LDAP Branches

2006-03-24 Thread Desaulniers Marc
HI, Where I can find the file that it contains all LDAP branches defined in the Account Unit Properties in SmartDashBoard Thanks - Marc Desaulniers Gestion des réseaux Service informatique Ville de Trois-Rivières Tél. 819-372-4641 Ext.: 1347 Courr

Re: [FW-1] RES: [FW-1] Provider-1 NGX Upgrade issue

2006-03-24 Thread chkp tech
It sounds like you might have one of a couple of problems. Either another P-1 or MLM with a different date/time or you're having Certificate Authority problems. First I would check that all of your Provider machines are updating properly via NTP. After that I would wait for one of the boxes to l

Re: [FW-1] Mask problem

2006-03-24 Thread Lyle Dove
Typo, 172.50.52.0 - 172.50.53.255 is the range. -Original Message- From: Lyle Dove [mailto:[EMAIL PROTECTED] Sent: Friday, March 24, 2006 7:35 AM To: 'Mailing list for discussion of Firewall-1' Subject: RE: [FW-1] Mask problem I would assume you know, but 172.50.52.0/23 is the subnet for

Re: [FW-1] Mask problem

2006-03-24 Thread Lyle Dove
I would assume you know, but 172.50.52.0/23 is the subnet for that IP, so the range would be 172.50.52.0 - 172.50.53.254 for all the IP's based on that mask. Based on basic subnetting, that should work as long as your using the IP's withing the range. I've never had to use anything over a /24, so

[FW-1] RES: [FW-1] Provider-1 NGX Upgrade issue

2006-03-24 Thread Octavio do Vale Rocha
It is not possible to install any policies. When check the sic status from smartdashboard, it gives the error: "SIC status fo X: not communicating Authentication Error [error 147] Check that peer SIC is configured properly and that system date and time on the Smartcenter and peer are synchron

[FW-1] Mask problem

2006-03-24 Thread Alvaro Gastambide
Hi, i have a question: In check point Secure Platform r55, i enter a ip on one interface. The ip is 172.50.53.253 mask 255.255.254.0 but the problem is that the network route don't appear. If i use the mask 255.255.255.0 it's ok, someone knows how i have this problem with the mask 255.255.254.0

Re: [FW-1] Provider-1 NGX Upgrade issue

2006-03-24 Thread Adam BE
Hi Octavio, Please provide more specific details... How do you know you've lost SIC, what is the symptom: does intall policy or some other operation fail? Once you've reset SIC... how long does it take until you lose it again? Can you reconstruct the specific operations you made which keep ca

[FW-1] Provider-1 NGX Upgrade issue

2006-03-24 Thread Octavio do Vale Rocha
Hi all, After upgrading Provider-1 to NGX (only the management part), we are having problems with r54 gateways. They loose SIC to the their CMAs, and even if we close SIC again it looses after some time. The error showed is error 147. The most strange is that in smartview monitor, we can se

Re: [FW-1] Technical specification of Firewall-1 GX

2006-03-24 Thread Ramki Security
It all depends on which hardware platform you want to choose. Fw1-gx is a software. Hardware requirement will be based on your requirement of performance and features. Regards, Ramki Sanisca, Dewa wrote: Hi All I make a document for my office project, and I need information about technical

Re: [FW-1] Technical specification of Firewall-1 GX

2006-03-24 Thread Lars Troen
Sanisca, FW-1 comes in all available sizes, both as small and big appliances. It also comes as software that you install on a server, an existing OS (windows, linux, solaris) or with Checkpoint's own OS. Please review Checkpoint's Platform Selection Guide for more info: http://www.checkpoint.com/p

Re: [FW-1] Technical specification of Firewall-1 GX

2006-03-24 Thread sin
Sanisca, Dewa wrote: > Hi All > I make a document for my office project, and I need information about > technical specification about Firewall-1 GX (power consumption, widht, > height, etc) ? > Maybe some one have the soft document or information ? Thank you all! GX is software. What you're intere