Re: [FW-1] Work assigment static vs dynamic in IPSO cluster ; means what ?

2006-07-26 Thread Robby Cauwerts
For the archives: Static assignement should be chosen if you use at least one of the following features: .. Floodgate-1. .. Sequence Verifier. .. Worm Catcher .. Delayed notification of connections .. Security servers .. IP pools (with non-Check Point gateways or clients). See Supporting

Re: [FW-1] 2 Router to Extrern on 1 Gateway

2006-07-26 Thread Robby Cauwerts
Hi, As far as I remember you don't need an additional license to setup isp redundancy. And it doens' matter on which public ip you put your license. Kind Regards Robby On 7/20/06, Verweyen, Dirk [EMAIL PROTECTED] wrote: Hey, we got a second leased line to the internet and plan to connect it

Re: [FW-1] Solaris 9 BGE card and NGX60

2006-07-26 Thread Ramki Security
Hi Clive, Broadcast/Multicast: This differentiates how the cluster members communicate with each other. Multicast would required special configuration in some switches connecting the cluster members and hence may create issues. Broadcast would eliminate this issue. Ramki CCNA, CCSE-NGAI

Re: [FW-1] Upgrade from NGX R60 to NGX R61

2006-07-26 Thread Ramki Security
First upgrade the management station. Before that take an upgrade_export of your current configuration. Once the management station is upgraded, then upgrade the modules. Refer the checkpoint upgrade guide for detailed instructions. I have heard that NGX R61 is older than NGX R60 with

Re: [FW-1] Upgrade from NGX R60 to NGX R61

2006-07-26 Thread Thorsten Behrens
I have heard that NGX R61 is older than NGX R60 with HFA03. It is. It's based on NGX R60 HFA02, or around that timeframe. Regards Thorsten Behrens SMC Supervisor / Senior Security Engineer CCMSE CCSE+ CCNA INTEGRALIS Your Trusted Security Partner 111 Founders Plaza 13th Floor East Hartford,

Re: [FW-1] stop SmartDefence on remotely managed Edge

2006-07-26 Thread Motta Corrado
Ray wrote: This questrion might be answered faster over on the Discussion Groups of http://www.sofaware.com (lower left part of the home page). Their tech support people monitor the forums and post replies as well as it being used to user-to-user support. Ray Hi Ray, I did what you

Re: [FW-1] Work assigment static vs dynamic in IPSO cluster ; means what ?

2006-07-26 Thread Andrej Skamen
Static assignment means that all traffic will be inspected by the same node during session activity. Dynamic assignment means, that packets within particular session could be / will be inspected by different modul. AndrejS -Original Message- From: Mailing list for discussion of

Re: [FW-1] stop SmartDefence on remotely managed Edge

2006-07-26 Thread Joe Matusiewicz
At 09:54 AM 7/26/2006, you wrote: Ray wrote: This questrion might be answered faster over on the Discussion Groups of http://www.sofaware.com (lower left part of the home page). Their tech support people monitor the forums and post replies as well as it being used to user-to-user support.

[FW-1] FW-1 NGx 60 QOS doesn´t work

2006-07-26 Thread Caballero Carlos
Hello, I have an FW-1 NGX60 infrastructure with two enforcement modules in a cluster configuration and a SmartCenter Console equipment, the thing is that I need to activate the QoS feature. I have been looking for the way to activate the services and have the the QoS Pane in the

[FW-1] Help needed with Checkpoint Firewall and Proxy Server

2006-07-26 Thread cisco4ng
Guys, I did not come up with this design but I have to support this so here we go. Keep in mind that the customer wants to keep everything as is and wanted me to make this work. Scenario: OS: Nokia IPSO 3.7.1 build 024 Checkpoint: NG with AI R55w and HFA_04 Internal network:

Re: [FW-1] NGX R61 supported on IPSO (4.0.1)

2006-07-26 Thread Lino Eduardo Avila Rodríguez
NGX R61 is supported from IPSO 3.9 and above. Check The Release Notes of R61 Regards, Lino -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Mark Elsen Sent: Lunes, 24 de Julio de 2006 04:01 a.m. To:

Re: [FW-1] Help needed with Checkpoint Firewall and Proxy Server

2006-07-26 Thread Reinhard Stich
hi, this is possible with the predefined http_mapped service - in the advanced part of the service-definition you can enter the proxy-ip. cheers reinhard At 22:05 26.07.2006, you wrote: Guys, I did not come up with this design but I have to support this so here we go. Keep in mind that

Re: [FW-1] Upgrade from NGX R60 to NGX R61

2006-07-26 Thread Lino Eduardo Avila Rodríguez
Does anyone know any know issues for R61? The one I know is the 'http_activate_ss_protections' must be active in order to download large attachments. Anything else? Best Regards, lino -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On

Re: [FW-1] NGX R61 supported on IPSO (4.0.1)

2006-07-26 Thread Reinhard Stich
hi, r61 and ipso41 have been release about at the same time. so nokia could not test r61 and checkpoint not ipso41. but: it works and: there is no info anywhere that it's not supported there will be an information (tac-newsletter) from nokia soon that r61 is supported on ipso41 cheers

Re: [FW-1] NGX R61 supported on IPSO (4.0.1)

2006-07-26 Thread Mark Elsen
hi, r61 and ipso41 have been release about at the same time. so nokia could not test r61 and checkpoint not ipso41. but: it works Define 'works' ... ? and: there is no info anywhere that it's not supported there will be an information (tac-newsletter) from nokia soon that r61 is

Re: [FW-1] NGX R61 supported on IPSO (4.0.1)

2006-07-26 Thread Reinhard Stich
At 22:50 26.07.2006, you wrote: hi, r61 and ipso41 have been release about at the same time. so nokia could not test r61 and checkpoint not ipso41. but: it works Define 'works' ... ? no problems here ... running for several days now. cheers reinhard -- Reinhard Stich [EMAIL

[FW-1] Error at policy install

2006-07-26 Thread Gaston Serralta
Check new added rules. I had a similar problem when i typed spanish characters. Maybe you are using (not english) characters in rule names or descriptions. Hope it works! GS = To set vacation, Out-Of-Office, or away messages, send an email to

Re: [FW-1] stop SmartDefence on remotely managed Edge

2006-07-26 Thread Ray
Well, you must be feeling good that you have such a unique problem no one else has eer had it. :-) I did notice such a post and it is odd that no one ever answered. Ray From: Motta Corrado [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1

Re: [FW-1] stop SmartDefence on remotely managed Edge

2006-07-26 Thread Ray
They just started requiring that because spam was making it on to the boards. After you go into Discussion Groups, upper right just above the date and time you'll see a Login/Join link. Those things do have implied rules but I've never seen them documented. Ray From: Joe Matusiewicz [EMAIL

[FW-1] Cluster failover logs

2006-07-26 Thread fico gid
Hi There, I am running NG AI R55 and have cluster setup as High Availability Legacy Mode. Yesterday my primary firewall A failed and was taken over by firewall B. I'm puzzled as to what happened. Where can I see the logs for this kind of problems ? Best Regards, Fico

Re: [FW-1] Help needed with Checkpoint Firewall and Proxy Server

2006-07-26 Thread cisco4ng
Hi Reinhard, Assuming that it is working for http_mapped (I will test it later), what about https and ftp? My proxy server is microsoft proxy server so it supports http/https and ftp. Any comments? TIA cisco4ng Reinhard Stich [EMAIL PROTECTED] wrote: hi, this is possible

Re: [FW-1] Help needed with Checkpoint Firewall and Proxy Server

2006-07-26 Thread Reinhard Stich
hi, just have a look at the http_mapped service and you will know what to do ;-) cheers reinhard At 03:11 27.07.2006, you wrote: Hi Reinhard, Assuming that it is working for http_mapped (I will test it later), what about https and ftp? My proxy server is microsoft proxy server so it

Re: [FW-1] Cluster failover logs

2006-07-26 Thread Reinhard Stich
hi, check the syslogs, you will see something there (interface down, firewall-problem, etc) cheers reinhard At 02:55 27.07.2006, you wrote: Hi There, I am running NG AI R55 and have cluster setup as High Availability Legacy Mode. Yesterday my primary firewall A failed and was taken over