Re: [FW-1] recommended operating system for smartcenter server

2011-03-08 Thread Shiroma Dassanayake
and are comfortable with using/managing. -Pierre On 3/7/2011 1:33 PM, Sergio Alvarez wrote: IMHO... SPLAT On Mon, Mar 7, 2011 at 4:31 AM, carlopmartcarlopm...@gmail.com  wrote: On 03/07/2011 11:03 AM, Shiroma Dassanayake wrote: Dear Checkpoint admin I would like opinions/feedback

[FW-1] recommended operating system for smartcenter server

2011-03-07 Thread Shiroma Dassanayake
Dear Checkpoint admin I would like opinions/feedback on the best operating system to use for a smartcenter server. It will be used to manage version R65 and above gateways. Thanks and regards Shiroma = To set vacation, Out-Of-Office, or away

Re: [FW-1] site to site VPN failing with Cisco Pix 515 and 505

2009-07-08 Thread Shiroma Dassanayake
list for discussion of Firewall-1 [mailto:fw-1-mailingl...@amadeus.us.checkpoint.com] On Behalf Of Shiroma Dassanayake Sent: Thursday, 2 July 2009 12:49 AM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] site to site VPN failing with Cisco Pix 515 and 505 Hi   Thanks Czar/Sergio

Re: [FW-1] site to site VPN failing with Cisco Pix 515 and 505

2009-06-29 Thread Shiroma Dassanayake
] On Behalf Of Shiroma Dassanayake Sent: Monday, 29 June 2009 1:41 PM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] site to site VPN failing with Cisco Pix 515 and 505 Hi admins   I have 3 site-site VPNs with three different Cisco models. The site-site with the ASA 5510 works. However

[FW-1] site to site VPN failing with Cisco Pix 515 and 505

2009-06-28 Thread Shiroma Dassanayake
Hi admins   I have 3 site-site VPNs with three different Cisco models. The site-site with the ASA 5510 works. However the VPNs with the 515 and the 505 don't work. To exclude the subnets issue, I have selected one VPN tunnel per each pair of hosts under tunnel management.   The keys are

Re: [FW-1] Malformed ssl packet

2009-03-12 Thread Shiroma Dassanayake
from Block SSL null-pointer assignment and install policy. Moreover, how is your current rule setting now ? The service field is Any or new design SSL protocol ? Thanks ! Regards, Little Lun --- 2009年3月11日 星期三,Shiroma Dassanayake nilshiro2...@yahoo.com 寫道﹕ 寄件人: Shiroma Dassanayake nilshiro2

[FW-1] Malformed ssl packet

2009-03-04 Thread Shiroma Dassanayake
Dear Checkpoint gurus   When attempting to access skype (non-voip acces has been allowed for a selected group of individuals), we are unable to connect. On checking the tracker logs, https packets to one of the Skype IPs are being dropped with this message:   attack name: invalid ssl packet SSL

[FW-1] changing the Ip address of the Smartcenter server and the external interface IP of the module

2007-09-18 Thread Shiroma Dassanayake
Dear Checkpoint admins I have a smartcenter server (NGX R62) and a gateway (NGAI R55) in distributed configuration. I have to change the IP addresses assigned to the Smartcenter and the gateway (the host address and the Ip assigned to the external interface) as our ISP is changing our

Re: [FW-1] Problem to establish VPN connection (NAT pb...?)

2007-06-06 Thread Shiroma Dassanayake
Hi What is the IP that the secureclient enters when creating the site (when connecting from the internet)? Is it the statically NAT'd IP of the cluster or is it the statically NAT'd IP of the firewall interface that connects to your ISP??? Regards Shiroma Joel Guillerm [EMAIL

Re: [FW-1] Problem to establish VPN connection (NAT pb...?)

2007-06-06 Thread Shiroma Dassanayake
: [EMAIL PROTECTED] TEL : +33.2.4041.4638 (int. : 874638) Mobile : +33.6.8503.3184 FAX : +33.2.4041.4638 Shiroma Dassanayake Sent by: Mailing list for discussion of Firewall-1 06/06/2007 12:20 Please respond to Mailing list for discussion of Firewall-1 To FW-1-MAILINGLIST

[FW-1] Smartview monitor after NGX upgrade

2006-08-31 Thread Shiroma Dassanayake
Dear all I recently upgraded my Smartcenter server from R55 to NGX. However my enforcement module is still running R55. The enforcement module takes part in both site-site and remote access VPN communities. On opening Smartview monitor on the smartcenter server I am unable to view

[FW-1] upgrading from R55 to NGX

2006-06-07 Thread Shiroma Dassanayake
Dear all I currently have a distributed env. My smartcenter server is running R55 HFA 14 and my gateway is running R55 HFA09. I am going to upgrade to NGX R60. However, this is what I got from the R61 release notes under clarifications and limitations: VPN 1. After

Re: [FW-1] Fwd: Re: [FW-1] secure remote users cannot access targ et servers in VPN domain

2006-06-07 Thread Shiroma Dassanayake
enabled VPN ports outbound to your network. Their firewall must be dropping IKE packets. Anand Addepalli. -Original Message- From: Shiroma Dassanayake [mailto:[EMAIL PROTECTED] Sent: Friday, June 02, 2006 2:30 AM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] Fwd: Re: [FW-1

[FW-1] Fwd: Re: [FW-1] secure remote users cannot access target servers in VPN domain

2006-06-02 Thread Shiroma Dassanayake
Note: forwarded message attached. Dear all Thanks to all of you that replied. The Secure remote clients are not connecting though ADSL, so PPOE is not used. A few additional tests were conducted that is why theres been a delay in the reply. The secureremote client is

[FW-1] secure remote users cannot access target servers in VPN domain

2006-05-22 Thread Shiroma Dassanayake
Dear all We have secure remote users connecting to servers in our VPN domain. However some of our secure remote users are experiencing problems connecting to the target servers in the VPN domain. These particular secure remote users are able to download the site and are authenticated as

[FW-1] Time change in a distributed env

2006-04-09 Thread Shiroma Dassanayake
Dear all I have a firewall and management server in a distributed environment. I need to set the time on both the firewall and management server back by half an hour. I will be changing the management server time first, then the firewall time. Is there anything that needs to be

Re: [FW-1] AW: [FW-1] Site to Site VPN woes

2005-10-10 Thread Shiroma Dassanayake
Auftrag von Shiroma Dassanayake Gesendet: Dienstag, 04. Oktober 2005 12:29 An: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Betreff: [FW-1] Site to Site VPN woes Wichtigkeit: Niedrig Dear mailing list members I have created a site to site VPN between our local Checkpoint NG AI R55 firewall and a Cisco

[FW-1] Site to Site VPN woes

2005-10-04 Thread Shiroma Dassanayake
Dear mailing list members I have created a site to site VPN between our local Checkpoint NG AI R55 firewall and a Cisco VPN server. The VPN domain defined on our end is: two seperate subnets of 255 hosts each and three host objects a.b.c.0/24 f.d.e.0/24 a.b.c.2 a.b.c.3 a.b.c.4 (this host

Re: [FW-1] smtp security server error

2005-08-24 Thread Shiroma Dassanayake
Dear all This list is great. Thanks to Reinhard and Jorn Dahl-Stamnes. The reboot worked. Hopefully it won't suddenly stop working again. Regards Shiroma Reinhard Stich [EMAIL PROTECTED] wrote: hi, just try a cprestart or reboot... cheers reinhard At 07:35 24.08.2005, you wrote: Dear all

[FW-1] smtp security server error

2005-08-23 Thread Shiroma Dassanayake
Dear all I have enabled an smtp resource on all incoming smtp to the mailserver. Up till yesterday this resource was working fine. Yesterday smtp got dropped with the following error string TCP packet out of state: First packet isnt SYN tcp flags: RST. The flags change between RST and

[FW-1] Changing license

2005-02-15 Thread Shiroma Dassanayake
Dear all We are currently using a Checkpoint Express license (CPXP-SC3-250-NG) . This is for 250 users. We are using central licensing. The license is installed on the management server which has Checkpoint NG AI R55 HFA-09 and from the management server a license is attached to our gateway

[FW-1] HFA-09 for R55

2004-10-08 Thread Shiroma Dassanayake
Dear Mailing list members I am about to apply HFA-09 on my management server which is running R55 HFA-04 Has anyone tried HFA-09 ? Any comments on HFA-09? Thanks Shiroma __ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection

[FW-1] GUI client

2004-06-22 Thread Shiroma Dassanayake
Dear all I have installed a firewall in a distributed configuration. The SmartCenter server runs NG AI R54 and the module is running NG FP3. The firewall module has 4 ports. One port has been reserved for the management network (network comprising firewall host Ip, Smartcenter Server). Another

[FW-1] Fwd: Too many VPN-1/FW-1 modules in network objects

2004-05-04 Thread Shiroma Dassanayake
Dear members Hi I am new to this list and have just installed Checkpoint in a distributed application. The Smart Center Server is on a Windows 2000 SP3 machine (Checkpoint version : NG with AI R54), my enforcement module is a Nortel Alteon 5105 running Checkpoint NG FP3. I obtained a central