[FW-1] Matthias Hoppe ist außer Haus / is not in office

2006-04-20 Thread Matthias Hoppe
Ich werde ab 20.04.2006 nicht im Büro sein. Ich kehre zurück am 28.04.2006. Ich werde Ihre Nachricht nach meiner Rückkehr beantworten. In dringenden Fällen wenden Sie sich bitte an Herrn Heinrich Poetz. I will reply to your message after my return. In urgent cases please contact Mr. Heinrich Po

Re: [FW-1] ipassignment.conf

2006-04-20 Thread Lino Eduardo Avila Rodríguez
I'm using a different subnet for office mode and Ip pool. the file was already in the modules, I just edited with vi. I've installed the policy but I'm making tests and it's not receiving the ip from the file but from the office mode pool. Regards, lino -Original Message- From: Mailin

Re: [FW-1] ipassignment.conf

2006-04-20 Thread Ray
If that is the very last line, it's probably OK. I believe you did say you put the file on the enforcement module manually, didn't you? This is one of the rare files that does not get pushed from the management server; it must be placed manually on the firewall itself. What IP address is it as

[FW-1] CIFS nbsession

2006-04-20 Thread Sam Ghannadi
Hi guys, my firewall(R55) not always but sometimes reject (in smartDefebse) CIFS nbsession here is the complete info from the log Product: Smart Defense Attack: Name CIFS worm Action: Reject Service: nbsession Source: 192.168.1.2 (only this secure_remote user) Destination: email server Protocol: T

Re: [FW-1] FTP (put or get)

2006-04-20 Thread Sam Ghannadi
thanks, it did help. --- Matthias Leu <[EMAIL PROTECTED]> wrote: > Sam Ghannadi wrote: > > hi guys, > > Can I create a rule on R55 checkpoint firewall > with > > some restriction on FTPing to some server either > PUT > > or GET? > > I looked on FTP services, none of them has that > > option. I ju

Re: [FW-1] ipassignment.conf

2006-04-20 Thread Lino Eduardo Avila Rodríguez
When I do a vpn ipafile_check ipassignment.conf detail Everything looks ok and then at the end It gives me an error of End of File. Could not read line x in conf file - maybe EOF Is this correct? Or it should I do something? Best Regards, Lino Avila -Original Message- From: Ma

Re: [FW-1] FTP (put or get)

2006-04-20 Thread Bean, Frank
Haven't done that before but it seems like crating a resource is the way to go. It looks like it's designed for that. -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Sam Ghannadi Sent: Thursday, April 20, 2006 12:11 PM To: FW-1-M

Re: [FW-1] FTP (put or get)

2006-04-20 Thread Christian Chiaverini
Check your SmartDefense features. Under "Application Intelligence" ---> "FTP" > "FTP Security Server" from there you can restrict commands via "Allowed FTP Commands". Christian Chiaverini CCSE -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PR

Re: [FW-1] Radius Authentication

2006-04-20 Thread Mark Elsen
> Afternoon all, I just wanted to confirm a setup for authenticating > SecureClient Users by a Radius server. > > >- Created Host Object where the Radius Server resides >- Created Server Object using Radius as the authentication method and >set the hostname as per the previous step >

Re: [FW-1] FTP (put or get)

2006-04-20 Thread Matthias Leu
Sam Ghannadi wrote: > hi guys, > Can I create a rule on R55 checkpoint firewall with > some restriction on FTPing to some server either PUT > or GET? > I looked on FTP services, none of them has that > option. I just like to give users permission to GET > not to PUT on a SUNserver (FTP). > Thanks,

[FW-1] FTP (put or get)

2006-04-20 Thread Sam Ghannadi
hi guys, Can I create a rule on R55 checkpoint firewall with some restriction on FTPing to some server either PUT or GET? I looked on FTP services, none of them has that option. I just like to give users permission to GET not to PUT on a SUNserver (FTP). Thanks, Sam ___

Re: [FW-1] FW1/ESP

2006-04-20 Thread Mark Senior
I think you may also have to make sure ESP is labelled as a "bidirectional" or "stateful" protocol (I also forget the wording). Otherwise, the firewall won't recognize responses, and you'd need two rules for every host that's supposed to talk ESP. Mark -Original Message- From: Mailing lis

[FW-1] Radius Authentication

2006-04-20 Thread Neil Kemp
Afternoon all, I just wanted to confirm a setup for authenticating SecureClient Users by a Radius server. - Created Host Object where the Radius Server resides - Created Server Object using Radius as the authentication method and set the hostname as per the previous step - Created an

Re: [FW-1] ipassignment.conf

2006-04-20 Thread Ramki Security
Also note that you cannot give an IP which is part of your encryption domain. You should use a totally different subnet (different from your officemode pool) for the ipassignment.conf to work. Regards, Ramki Lino Eduardo Avila Rodríguez wrote: I have configured office mode and It works ok,

Re: [FW-1] Cisco VPN/CheckPoint FW

2006-04-20 Thread Ramki Security
Try using TCP mode instead of UDP (default). That may help. Regards, Ramki fwguru wrote: Hide-NAT works fine with Cisco VPN clients behind a CP. I have had to static-NAT some Cisco VPN clients to get it to work -- that was some time ago, not recently. If you have the proper ports open then ch

Re: [FW-1] State Sync does not supports VLAN ?

2006-04-20 Thread Alex S.
Hi, Thanks for your quite thorough explanations. If that so, beside not to use VLAN tagging (but only in Cisco switches), is there any important settings that I should take note? I just knew that I have to disable IGMP snooping on Cisco switches. Thanks very much. Regards, Alex Fabrice BA

Re: [FW-1] State Sync does not supports VLAN ?

2006-04-20 Thread Fabrice BARUTEL
Hi, as you talk about "First, VLANs cannot be used in the synchronization network in any version", I understand you have only one physical link to each Cisco 6500 per each Checkpoint server. So, I deduce you wanted to enable VLAN tagging on this physical interface, which would support all your net