Re: [FW-1] VPN without implied rules

2006-05-03 Thread [EMAIL PROTECTED]
that was the trick like sk18936 thx Andre Ulli Ulrich wrote: Hi, when using simplified vpn setup (communities) and disaling implied rules (vpn-1 control connections) zou have to exlude ike and esp from the community (excluded services). regards Ulrich I would like to disable all implied

[FW-1] What about LYNX in IPSO 4.0.1 ?

2006-05-03 Thread Bona Gianluca
Anybody knows why the lynx command doesn't work under IPSO 4.0.1 ? With which new command we can configure by CLI, emulating Voyager? Thanks!! Gianluca Bona Le informazioni contenute in questo messaggio di posta elettronica sono destinate esclusivamente agli individui e agli enti ai quali

Re: [FW-1] Radius Authentication

2006-05-03 Thread Lars Troen
Hello, Any pointers to documentation on how to set this up? Maybe in the combination FW1 NG AI and RSA Secure? GRTNX, RobJE For RSA SecurID you should not use RADUIS, but native SecurID authentication. Try looking at the following guide:

Re: [FW-1] What about LYNX in IPSO 4.0.1 ?

2006-05-03 Thread Reinhard Stich
hi, lynx has been removed from ipso, just read the release notes. cheers reinhard At 08:44 03.05.2006, you wrote: Anybody knows why the lynx command doesn't work under IPSO 4.0.1 ? With which new command we can configure by CLI, emulating Voyager? Thanks!! Gianluca Bona Le informazioni

Re: [FW-1] Office Mode in SecuRemote mode?

2006-05-03 Thread Robby Cauwerts
Is this trick still working in NGX? According to what I've read Check Point removed this feature in Secure Remote after R55 because having office mode is one the main reasons why one would by a Secure Client license. Thorsten Behrens [EMAIL PROTECTED] Sent by: Mailing list for discussion

Re: [FW-1] What about LYNX in IPSO 4.0.1 ?

2006-05-03 Thread cisco4ng
Those idiots from Nokia never seem to amaze me. Why the hell do they take away a perfectly working app. (lynx) from IPSO 4.0 and higher? Then again, it's Nokia, what do you expect? Reinhard Stich [EMAIL PROTECTED] wrote: hi, lynx has been removed from ipso, just read the release notes.

[FW-1] R: [FW-1] What about LYNX in IPSO 4.0.1 ?

2006-05-03 Thread Lorenzo
Clish is (as the name) Command LIne SHell. While it replaces lynx for ipso confs purposes it doesn't actually emulate a browser. Lynx is useful for many other needs (e.g. when you have to re-establish a blown environment and need to google around). Anyway I hope people understand that, despite

Re: [FW-1] What about LYNX in IPSO 4.0.1 ?

2006-05-03 Thread Jean-Paul Baillon
You can perform all lynx's functions with clish - works better too as there is no need to 'apply' and 'save' Quoting cisco4ng [EMAIL PROTECTED]: Those idiots from Nokia never seem to amaze me. Why the hell do they take away a perfectly working app. (lynx) from IPSO 4.0 and higher? Then

Re: [FW-1] What about LYNX in IPSO 4.0.1 ?

2006-05-03 Thread Reinhard Stich
hi, I guess that the new webinterface (frames etc) does not work with lynx ... and as Jean-Paul said: you can also do everything with clish ... cheers reinhard Quoting cisco4ng [EMAIL PROTECTED]: Those idiots from Nokia never seem to amaze me. Why the hell do they take away a

Re: [FW-1] R: [FW-1] What about LYNX in IPSO 4.0.1 ?

2006-05-03 Thread Juniman Kasman
Hi, Can somebody help me on BOOTP/DHCP relay? I use Nokia as BOOTP/DHCP Relay and windows DHCP server. I've tried to redirect the DHCP traffic to DHCP server (wait time=0), but it still not work. (when trying using cisco IP helper, it works). Please advice Thanks for the time...

Re: [FW-1] R: [FW-1] What about LYNX in IPSO 4.0.1 ?

2006-05-03 Thread Brockhoven, Werner
Hello, Last time I came across this issue we needed to change the Protocol Type: in the advanced settings for the dhcp service from CP-DHCP-... to none. Regards, Werner -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Juniman

[FW-1] R61 for VPN1/Pro Express

2006-05-03 Thread Jeremy Lieb
Has anyone heard a firm date on when R61 will be released? I know that some people have been able to get it from their firewall vendors etc. I had thought it was to be out a few weeks back. I'm interested in the new Edge management functionality that is supposed to be included with this release.

Re: [FW-1] What about LYNX in IPSO 4.0.1 ?

2006-05-03 Thread Mark Senior
It's true, the 'lynx' browser doesn't do frames. The 'links' browser does handle frames, javascript, SSL, and a number of other somewhat modern web features that lynx doesn't. I don't know if links is included in IPSO, but an OpenBSD build might work if you're feeling particularly

Re: [FW-1] R61 for VPN1/Pro Express

2006-05-03 Thread Reinhard Stich
hi, yes - edge-mgmt is enhanced in R61, I guess checkpoint is waiting for nokia to test and release the ipso-version. then R61 will be released. should be within the next 1-2 weeks as I see it. cheers reinhard At 18:09 03.05.2006, you wrote: Has anyone heard a firm date on when R61 will be

Re: [FW-1] R61 for VPN1/Pro Express

2006-05-03 Thread Jeremy Lieb
Thanks for the reply. -- Jeremy Lieb Firewall Administrator Open Text Corporation - Original Message - From: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM

Re: [FW-1] R61 for VPN1/Pro Express

2006-05-03 Thread Covington, Chris
Is R61 the next FW-1 after R60? So those who haven't gone to R60 yet could upgrade say from R55 SPlat - R61 SPlat and skip R60? Chris -Original Message- From: Reinhard Stich [mailto:[EMAIL PROTECTED] Sent: Wed May 03 13:08:48 2006 To:

Re: [FW-1] R61 for VPN1/Pro Express

2006-05-03 Thread Jeremy Lieb
I haven't read the release notes yet but I would say most likely. Jeremy Lieb CCSE-NG CCSE+NG Firewall Administrator Open Text Corporation 100 Tri-State Int'l Pkwy Third Floor Lincolnshire, IL 60069 18472679330 ext 4395 -Original Message- From: Mailing list for discussion of

Re: [FW-1] R61 for VPN1/Pro Express

2006-05-03 Thread Reinhard Stich
hi, well: R61 not released yet, so the best idea is ... ... to upgrade to R60 if you need to upgrade now. ... to upgrade to R60 if you need to upgrade in 1 or 2 months ... to think about upgrading to R61 later. but: this also depends on your needs (features etc) ... cheers reinhard At 22:53

Re: [FW-1] R61 for VPN1/Pro Express

2006-05-03 Thread Marc Rinderer
noch nicht müde? ;-) kann dir das iso morgen geben ! - Original Message - From: Reinhard Stich [EMAIL PROTECTED] To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Sent: Wednesday, May 03, 2006 11:25 PM Subject: Re: [FW-1] R61 for VPN1/Pro Express hi, well: R61 not released yet, so

Re: [FW-1] R61 for VPN1/Pro Express

2006-05-03 Thread Crist Clark
On 5/3/2006 at 2:25 PM, Reinhard Stich [EMAIL PROTECTED] wrote: hi, well: R61 not released yet, so the best idea is ... So this set of R61 CDs that Check Point sent me a few weeks ago are a product of my deranged mind? Or is there some other definition of released? -- Crist J. Clark

[FW-1] Checkpoint logging questions/comments?

2006-05-03 Thread cisco4ng
Hi Everyone, I think I know the answer to this but I would like to confirm with everyone in this group. Scenario: Nokia Enforcement Module NG AI R55w with with HFA_04 and Provider-1 NG with AI R55w on SPLAT The Nokia enforcement module is sending log to the CMA just fine. However,

Re: [FW-1] Checkpoint logging questions/comments?

2006-05-03 Thread Concepcion, Juan
If I remember correctly, once the firewall establishes connectivity to the CMA it should forward whatever logs it has stored. The other option is to perform a manual log switch and transfer the file over to the CMA. Jaun -Original Message- From: Mailing list for discussion of Firewall-1

[FW-1] hotfix question

2006-05-03 Thread Clive Luk
Hi all, One more silly question. http://www.checkpoint.com/downloads/latest/hfa/vpn1pro_express.html#r60 is this the latest hotfix for NGX60? Thanks! Cheers, Clive = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL

[FW-1] export configuration

2006-05-03 Thread Clive Luk
Dear FW-1 list members, Hope someone can help me here. Let me explain my situation. I am currently running single NGX55 on Solaris 8 and SmartCenter on a different box (Solaris 9). I have been assigned to a project to setup a cluster(load balance/fail-over) firewall. I have just setup a test

Re: [FW-1] hotfix question

2006-05-03 Thread Ramki Security
Yes. HFA-03 is the latest hotfix for R60. Regards, Ramki Clive Luk wrote: Hi all, One more silly question. http://www.checkpoint.com/downloads/latest/hfa/vpn1pro_express.html#r60 is this the latest hotfix for NGX60? Thanks! Cheers, Clive =

Re: [FW-1] export configuration

2006-05-03 Thread Ramki Security
Hi Clive, Are you planning to use ClusterXL for clustering? About cluster, you cannot setup cluster and management on the same box. You need to have a separate management and two other boxes to setup cluster. Once you have this infrastructure, you can follow these steps. 1. Use the

Re: [FW-1] R61 for VPN1/Pro Express

2006-05-03 Thread Ramki Security
Hi Reinhard, Can you explain what is the change in edge management in R61. Thanks, Ramki Reinhard Stich wrote: hi, yes - edge-mgmt is enhanced in R61, I guess checkpoint is waiting for nokia to test and release the ipso-version. then R61 will be released. should be within the next 1-2

Re: [FW-1] hotfix question

2006-05-03 Thread Clive Luk
Thanks Ramki! I have just installed the hotfix. Thanks again for you quick reply. -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Ramki Security Sent: Thursday, 4 May 2006 12:32 PM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM

Re: [FW-1] export configuration

2006-05-03 Thread Clive Luk
Hi Ramki, Thanks for your quick reply. At the moment, I have only have 2 play boxes. I thought I can do some playing around. So I need an extra play box for the management server. Regarding the upgrade_export. Should I run the upgrade_export on my current NGX55 box? Yeah! We have the l license

Re: [FW-1] R61 for VPN1/Pro Express

2006-05-03 Thread Reinhard Stich
hi, biggest changes: - simple QoS-mgmt for edge - smart-defense mgmt for edge (not all SD-rules!) cheers reinhard At 04:54 04.05.2006, you wrote: Hi Reinhard, Can you explain what is the change in edge management in R61. Thanks, Ramki Reinhard Stich wrote: hi, yes - edge-mgmt is enhanced