Re: [FW-1] Linux Client

2007-06-29 Thread David CALLEBAUT [AEMS Be]
Bernd, You could give it a try by using Wine (http://www.winehq.org/) and then follow the instructions at this location according to the version in use: http://appdb.winehq.org/appview.php?iAppId=1067 Of course this is not supported by Checkpoint and it does not do a full-fledged linux client,

Re: [FW-1] Problem pushing policy to gateway

2007-05-11 Thread David CALLEBAUT [AEMS Be]
Not that I'm aware of. As always with CP you need a license (or in this case a subscription) to be able to use/update a component. I have not seen a case where the signatures could be updated offline. David Callebaut Security Engineer Tel. +32 (0) 2 702 55 49 Mobile. +32 (0) 478 98 08

Re: [FW-1] TX and RX - VSX

2007-03-30 Thread David CALLEBAUT [AEMS Be]
Hi Satyam, We don't have VSX but we use standard SNMP to monitor the bytes data on FW interfaces. I suppose that you can use this concept as well. For this you can use any SNMP enabled monitoring tool. Simply allow SNMP-read in your security policy to your VSX and enable it on the device itself.

Re: [FW-1] Internal_sendmail

2007-03-22 Thread David CALLEBAUT [AEMS Be]
them and pushing the policy again. Not sure this is really helpful, but in theory, with the file being there this should be working for you. Please let me know how you get on. Christopher McGill On 3/6/07, David CALLEBAUT [AEMS Be] [EMAIL PROTECTED] wrote: Hi all, Did anyone try to use

[FW-1] VLAN change = no longer reachable

2007-03-20 Thread David CALLEBAUT [AEMS Be]
Dear listmembers, Did anybody ever encountered this: Gateway is a CP NG w. AI R55 with latest HFA on a Nokia IP 530 with 3.8.1-BUILD033. A physical interface is configured to have 2 logical IP's using VLAN tagging. Both interfaces were re-distributed in OSPF to our backbone routers (through

Re: [FW-1] scp to secureplatform : lost connection

2007-03-14 Thread David CALLEBAUT [AEMS Be]
There is another *fine detail* that needs to be done: In /etc on SPLAT you also need to create a file with the name scpusers that holds a list of all SCP allowed users. Otherwise no connection is allowed. David Callebaut Security Engineer Tel. +32 (0) 2 702 55 49 Mobile. +32 (0) 478 98

Re: [FW-1] FW-1 list is moving

2007-03-13 Thread David CALLEBAUT [AEMS Be]
] FW-1 list is moving What is the email to subscribe to it ? -Message d'origine- De : Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] De la part de David CALLEBAUT [AEMS Be] Envoyé : mardi 13 mars 2007 07:00 À : FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Objet : Re: [FW

Re: [FW-1] FW-1 list is moving

2007-03-12 Thread David CALLEBAUT [AEMS Be]
The only thing I see is a Page cannot be displayed... And the new checkpoint website is still -as always- vry slow when viewed from europe Things look bright :-S David -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Gil

Re: [FW-1] FW-1 list is moving

2007-03-12 Thread David CALLEBAUT [AEMS Be]
I would strongly suggest you all to subscribe to the Phoneboy list if not done so yet. Don't put your effort in convincing Checkpoint to keep the list. Don't think for a second that Checkpoint even cares if we would like the list to be continued otherwise they would have asked before announcing

[FW-1] Internal_sendmail

2007-03-05 Thread David CALLEBAUT [AEMS Be]
Hi all, Did anyone try to use internal_sendmail on a R61 (on splat)? We used to run R55 and we configured to send out email alerts with internal_sendmail without any problems. Recently we upgraded to R61 and it suddenly stopped working even since. The command is no longer known to SPLAT in R61

[FW-1] Fwm load output

2007-01-04 Thread David CALLEBAUT [AEMS Be]
Dear list users, Is there a way to capture the output of the fwm load command into a file? I've tried putting the standard output.txt suffix but that didn't work. And to my knowledge there any no arguments of the command that can be used to redirect the output to a file. Any suggestions would

Re: [FW-1] Fwm load output

2007-01-04 Thread David CALLEBAUT [AEMS Be]
:41 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Fwm load output On Fri, 5 Jan 2007, David CALLEBAUT [AEMS Be] wrote: Is there a way to capture the output of the fwm load command into a file? I've tried putting the standard output.txt suffix but that didn't work

Re: [FW-1] trad. VPN settings in simp. mode

2006-11-23 Thread David CALLEBAUT [AEMS Be]
2006 9:39 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] trad. VPN settings in simp. mode David CALLEBAUT [AEMS Be] a écrit : Dear List members, I have a customer who wants to establish a site-to-site VPN between a FP2 cluster and a Cisco 2621 router. I know there are some

[FW-1] trad. VPN settings in simp. mode

2006-11-22 Thread David CALLEBAUT [AEMS Be]
Dear List members, I have a customer who wants to establish a site-to-site VPN between a FP2 cluster and a Cisco 2621 router. I know there are some pitfalls in setting something like this up. Anybody has some good info or documents related to setting up this kind of VPN? Note: the customer does

Re: [FW-1] assistance needed ASAP.

2006-10-18 Thread David CALLEBAUT [AEMS Be]
As far as I can remember the R55w version did not support floodgate. Only R55 or R55p does. It had something to do with technical incompatibility with the web services build in the w version. I have no R55w gateways to manage but I vaguely remember posts in this mailing list about the lack of

Re: [FW-1] block file transfer in Instant Messaging like AOL, Yahoo and MSN while still allowing chat

2006-08-15 Thread David CALLEBAUT [AEMS Be]
Cisco4ng, If you want to block these IM's completely you'll need to use that pain in the *ss of a SmartDefense. But to stop only the file transfers you can simply use a rule: Source: Internal LAN's Dest.: Internet Protocol groups: P2P_File_Sharing_Appications Messenger_Applications Action:

[FW-1] Securemote on FP2

2006-05-04 Thread David CALLEBAUT [AEMS Be]
Hi all, Does anybody have some good information/manuals on setting up securemote on a checkpoint FW-1 NG FP2? I have a client with a old FP2 setup (on Nokia ipso 3.5). The client does not want to upgrade since the licenses are no longer under support and they are not eager to pay. I have the

Re: [FW-1] weirdness chpaprob state output

2006-05-04 Thread David CALLEBAUT [AEMS Be]
Cisco4ng, Are there other devices on this sync LAN? Perhaps even other FW's? We didn't have the same issue, but something a bit similar where there were 2 FW clusters sharing the same Sync LAN. We were able to solve it by modzap'ing the magic numbers of the sync multicast traffic and assigned a

[FW-1] AD logon ports

2006-02-16 Thread David CALLEBAUT [AEMS Be]
Hi all, Does someone know what RPC or DCE-RCP (or yet another) service I need to allow for a MS machine in a DMZ to logon to the Active Directory through a FW-1 R55HFA07 on IPSO3.8? I've already opened LDAP, kerberos, DNS. But I know that there is also an RPC connection. However I am unable

Re: [FW-1] Need help with configuring OSPF on the Nokia to work w ith Cisco device

2006-02-09 Thread David CALLEBAUT [AEMS Be]
HI Janis/Cisc4ng, To be precise you can force Nokia NOT to be DR or BDR by setting the election priority to 0 in the OSPF configuration page of voyager. 0 means: never be elected in this case. David Callebaut -Original Message- From: Mailing list for discussion of Firewall-1

[FW-1] Common knowledge question

2006-02-09 Thread David CALLEBAUT [AEMS Be]
of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of David CALLEBAUT [AEMS Be] Sent: vrijdag 10 februari 2006 7:48 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Need help with configuring OSPF on the Nokia to work w ith Cisco device HI Janis/Cisc4ng, To be precise you can force

[FW-1] Secureclient SCV implementation

2005-11-13 Thread David CALLEBAUT [AEMS Be]
Hi All, Does anybody has experience in implementing a SCV setup through the use of the local.scv file? I'm trying to setup SCV but for some reason I get no result: I created (actually adapted) local.scv and put in on the management server in the $FWDIR/conf directory. I turn on the Apply rule

Re: [FW-1] SPLAT - R55 - Secure Remote User Issue

2005-10-20 Thread David CALLEBAUT [AEMS Be]
David/Tom, I the past I have had the same issues. I did get rid of them by doing a upgrade_export and upgrade_import on the Smartcenter. After the import I was able to delete the users I wanted to get rid off. However: since today I have a similar issue, not with a user but a group (which is