[FW-1] General NAT question (binding IP addresses)

2006-07-11 Thread Sascha Picchiantano
Hi there, quick question here. We just received a new subnet from our ISP and want to use this for static NAT mappings only. Do we need to bind these addresses (or one of them) to any of the firewalls interfaces to tell the OS it's part of this subnet, or can we simply use the addresses in NAT

Re: [FW-1] General NAT question (binding IP addresses)

2006-07-11 Thread Robby Cauwerts
Hi, If this subnet is only used for natting then you don't need to configure proxy arp. You'll only need to do this if you're using addresses on the direct connected subnet for natting. Just verify that you upstream router has a route for this subnet to your firewall. And if the traffic is

Re: [FW-1] NGX Hotfix Confusion !

2006-07-11 Thread Ramki Security
1. The release note may have been modified in June 2006. 3. Smartconsole HFA numbers are different from product HFAs and can be followed independently. Hence going by what you have mentioned, the VOIP hotfix may be the latest. Ramki CCNA, CCSE Mark Pace Balzan wrote: Hello All, Im

[FW-1] Policy Push

2006-07-11 Thread Peter Addy
Hi Does anyone know why vpn connections would break each time a policy was pushed to a piar of firewalls running NGAI R55 ipso 3.9 running vrrp nokia IP740 Vpn connectrions are only restored after another policy push, not seen this one before ?? We have rematch connections set

Re: [FW-1] Policy Push

2006-07-11 Thread Zubair Jalal
For VPN Connectivity issues, please do the following 1) Logon to SmartDashboard 2) Select and edit the FireWall object 3) In Advanced settings Connection persistence, select keep all connections Note: This will keep existing VPN connections during a policy installation 4) Install policy to

Re: [FW-1] Policy Push

2006-07-11 Thread cisco4ng
You should stick with keep all connections. that way your vpn will not go down after a policy is pushed. Peter Addy [EMAIL PROTECTED] wrote: Hi Does anyone know why vpn connections would break each time a policy was pushed to a piar of firewalls running NGAI R55 ipso 3.9 running

Re: [FW-1] NGX upgrade and high cpu usage

2006-07-11 Thread Cihan Subasi (Garanti Teknoloji)
When I do reinstall...things get worse...and after the installation come back to usual (as below no change whatsoever) *** Cihan SUBASI Garanti Technology Internet ve Yazilim Hizmetleri Tel:(90)(212)4783426 GSM:(90)(533)(2750353)

Re: [FW-1] Routing between two EXTERNAL interfaces

2006-07-11 Thread cisco4ng
Hi Simon/Kevin, 1) I can not do terminate IPSec on my 129.174.1.8 External interface with this customer because this customer is coming to me from a private Frame-relay cloud. Therefore, I had to terminate the IPSec on the DMZ External interface. 2) VPN domain is the same as you

[FW-1] Nokia IP350 License problem

2006-07-11 Thread Jean-Christophe Valiere
Hello, I'm trying to add the license for a new firewall (Nokia IP350) using SmartUpdate (R55 Build 62). Nokia Firewall Software Version is: Software Release: 4.1-BUILD016 and Software Version: releng 1515 05.19.2006-052320. I got the following eroor when adding

[FW-1] SMTP

2006-07-11 Thread Alvaro Gastambide
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, i have a question.. In my object Firewall (R55) Properties -- Advanced -- SMTP It have a lot of settings to configure, like don't accept mail larger than than XXKb I would like to know if it works with all smtp thar pass throw the firewall

[FW-1] Secureclient MAC

2006-07-11 Thread Lino Eduardo Avila Rodríguez
Hello all! Has anybody was able to function Secureclient for MAC?? I find out that there's a bug with Office Mode in this client, but when I try to connect I got this message: COnnection Canceled This machine's IP can only be used with Office Mode Can somebody give me some

Re: [FW-1] Nokia IP350 License problem

2006-07-11 Thread Ramki Security
You have got a NGX license here which is in your license database. The error is because you have R55 loaded. Check this license and remove it if not intended to be there. Ramki CCNA, CCSE-NGAI Jean-Christophe Valiere wrote: Hello, I'm trying to add the license for a new

Re: [FW-1] Policy Push

2006-07-11 Thread Peter Addy
Many thanks Zubair Jalal [EMAIL PROTECTED] wrote: For VPN Connectivity issues, please do the following 1) Logon to SmartDashboard 2) Select and edit the FireWall object 3) In Advanced settings Connection persistence, select keep all connections Note: This will keep existing VPN connections

Re: [FW-1] Policy Push

2006-07-11 Thread Peter Addy
Excellent sorted, many thanks cisco4ng [EMAIL PROTECTED] wrote:You should stick with keep all connections. that way your vpn will not go down after a policy is pushed. Peter Addy [EMAIL PROTECTED] wrote: Hi Does anyone know why vpn connections would break each time a policy

Re: [FW-1] Policy Push

2006-07-11 Thread Ray
Odd. I use rematch and do not have this issue, running R55 HFA17 on IPSO 3.9, no VRRP. Bear in mind that keep will keep all existing connections even if the new security policy does not allow them. They will persist until they end themselves. Ray From: Peter Addy [EMAIL PROTECTED]

[FW-1] Solaris 9 BGE card and NGX60

2006-07-11 Thread Clive Luk
Dear List, I am trying to do a new installation on my newly bought two SUN FIRE V240. Actually I want to setup as a cluster. However, When I installed NGX60 to a freshly built box, it seems that CP doesn't recognise the bge card. Does anyone has the same problem? Is there anyway I can solve it.