Re: [FW-1] SPLAT - R55 - Secure Remote User Issue

2005-10-17 Thread Ray
I've seen a similar error message on earlier revs of R55 where removing a network object that was still in a rule would cause that error. Any chance it's used somewhere else, if in fact you can still see it? Ray From: Tom Brown [EMAIL PROTECTED] Reply-To: Mailing list for discussion

Re: [FW-1] openion on Sybex-CCSE book...

2005-10-20 Thread Ray
. I did pass the CCSA CCSE on the first attempt using a combination of the Sybex books and Boson tests, for whatever that's worth. Ray From: Christian Chiaverini [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW

Re: [FW-1] Problems installing SecureClient R56/R60

2005-10-21 Thread Ray
hotfixes that you will need to apply first to avoid BSOD problems. I know this isn't what you're seeing ,though. If this laptop has the Cisco VPN client on it, it will have to be un-checked. That Deterministic Networks thingy is usually the problem. Ray From: [EMAIL PROTECTED] [EMAIL PROTECTED

[FW-1] R55 Clientless VPN questions

2005-10-22 Thread Ray
of installing any client software at all, like SNX. I don't need those kinds of headaches. Thanks for any help, Ray = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1

[FW-1] For those of you having worm catcher problems with HFA16

2005-10-23 Thread Ray
Check Point has released sk31267 with a hotfix to be applied on top of HFA16. The hotfix can be downloaded from the article and requires a reboot of the enforcement module. Ray = To set vacation, Out-Of-Office, or away messages, send an email

Re: [FW-1] R55 Clientless VPN questions

2005-10-24 Thread Ray
Thanks, Chris. We're trying to stick to just one authentication scheme that doesn't involve user names and passwords. Ray From: Covington, Chris [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1

Re: [FW-1] suggestions on mid-size firewall

2005-10-25 Thread Ray
and it's rock solid. What's your throughput and how many IPs will be behind it? Is it doing anything fancy like remote access or publishng web servers? Ray From: Covington, Chris [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST

Re: [FW-1] Problems with ICMP and VPN.

2005-10-25 Thread Ray
Can you ping the internal interace of the opposite firewall? If so, it might be a downstream router that's blocking it. Ray From: Luiz H. Guimarães Filho [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1

Re: [FW-1] suggestions on mid-size firewall

2005-10-27 Thread Ray
. There are basically 2 Class C VLANs behind the router, 1 is for phones and doesn't traverse. The 130 should be fine. My 120 is an internal firewall on a 100 M/bps LAN and the throughput is OK. Ray = To set vacation, Out-Of-Office, or away messages, send

Re: [FW-1] Wireless Card

2005-11-01 Thread Ray
in, the card is off. The PC Card can stay plugged in all the time. Ray From: Stephen W. Stewart [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] Wireless

Re: [FW-1] External Interface automatic in Encryption Domain???

2005-11-02 Thread Ray
Why does the client at HQ need to connect to the external interface of the remote firewall? In a simplified security policy, all enforcement modules are automatically part of th encryption domain. Ray From: FITZ MAILING [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1

Re: [FW-1] Problems with R55_HFA_16 hot fix?

2005-11-09 Thread Ray
VPN-1/FireWall-1 rejects HTTP traffic following Gateway's upgrade to HFA_16 of NG with AI R55 Solution ID: #sk31267 The hotfix is attached to this article. Ray From: Reinhard Stich [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST

Re: [FW-1] Enable Hot Spot\Hotel registration

2005-11-09 Thread Ray
) :max_trials (0) ) This is mine with hotspot disabled. Note that you must first stop the Check Point services before editing userc.C and start them after you save the edited file. AsI recall, the :enabled( false) needs to be made true Ray From: Mark

Re: [FW-1] Allow SecureClient users to access resources in a site to site VPN

2005-11-10 Thread Ray
SmartView Tracker for drops to and from the Office Mode network to make sure your rules are OK. Good luck, Ray From: Kalpesh Patel [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST

Re: [FW-1] VPN / Site-to-Site issue

2005-11-11 Thread Ray
default settings Check Point has. Ray From: Kalpesh Patel [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] VPN / Site-to-Site issue Date: Thu, 10 Nov 2005 23

Re: [FW-1] Migrating certificates from R55 NG to a new NGX firewall

2005-11-11 Thread Ray
Define migrate please. Do you mean merge an existing certificate authority into an existing one or do you really mean migrate as in the NGX box is replacing the R55 box? Ray From: Meyers, Duncan [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1

[FW-1] Revised NGX HFA01 available

2005-11-13 Thread Ray
, though. Ray = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail = To unsubscribe from this mailing list, please

Re: [FW-1] Secureclient sends unencrypted

2005-11-14 Thread Ray
split tunneling and denies access to local LAN resources unless they can be reached by the gateway, but it should do what you want. Note that there were some issues with Hub Mode that got fixed in SecureClient NGX. Ray From: Marcus Hess [EMAIL PROTECTED] Reply-To: Mailing list for discussion

Re: [FW-1] Migrating certificates from R55 NG to a new NGX firewall

2005-11-14 Thread Ray
/techsupport/downloadsng/utilities.html#upgrade_verify for R55 http://www.checkpoint.com/techsupport/ngx/utilities.html for NGX. Ray From: Meyers, Duncan [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1

Re: [FW-1] Certification Tests

2005-11-16 Thread Ray
without doing the CCSA.. Ray From: Shane Presley [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Certification Tests Date: Tue, 15 Nov 2005 21:43:41

Re: [FW-1] VPN Edge SMART management setup

2005-11-23 Thread Ray
Maybe NGX is different, but I know earlier versions required the server version of Windows on the SmartCenter. Ray From: Andriy Malyuk [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST

Re: [FW-1] Cisco VPN Client behind a Check Point Fw

2005-11-26 Thread Ray
Do you have a VPN between the Check Point gateway and the Cisco gateway? That's the only way you should see that error in the Check Point logs. We have several Cisco clients behind a CP box with no issues. Ray From: Oliver [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1

Re: [FW-1] AW: [FW-1] SecureClient DNS registration

2005-11-26 Thread Ray
Odd. That article sk23196 was updated on Nov. 21st and says no fix is available but it will be included in NGX HFA01 due in Sept. 05. I wonder if this is going to take a SecureClient fix. The one available for download is still the original one. Ray From: Scholz Wolfgang [EMAIL PROTECTED

[FW-1] Two things I really like about SecureKnowledge 2.0

2005-11-26 Thread Ray
for it and you get feedback on what you wrote. I've used it a few times and it works nice. Sometimes it takes a few weeks but each time I've submitted something, I've gotten feedback and clarified wording in the article or whatever it pertained to. Ray

[FW-1] Full Disclosure list message on bypasing SecureClient SCV

2005-12-07 Thread Ray
. Ray -- From : Viktor Steinmann [EMAIL PROTECTED] Sent : Wednesday, December 7, 2005 11:54 AM To :full-disclosure@lists.grok.org.uk Subject : [Full-disclosure] Checkpoint SecureClient NGX Security Policy caneasily be disabled

[FW-1] SecureClient NGX Dynamic DNS registration

2005-12-07 Thread Ray
This was supposed to be available in SecureClient NGX NGX HFA01 on the gateway. It seems it was but there's an additional configuration step needed. It's detailed in sk23196 Ray = To set vacation, Out-Of-Office, or away messages, send an email

Re: [FW-1] EDGE 6.0 with SmartCenter NGX

2005-12-12 Thread Ray
On Dec. 6th, CP posted new libsw files to the Edge 6.0 firmware download page. I suspect they also apply to NGX due to their date. Ray From: Du¹ko Tubin [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1

[FW-1] HFA17 for R55 posted

2005-12-12 Thread Ray
Doesn't seem to have anything earth-shattering, at least for me. Ray = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail

[FW-1] Another SecureClient SCV bypass?

2005-12-15 Thread Ray
From the Full Disclosure list - seems to be a popular topic nowadays. sog Ray From : Avner Peled [EMAIL PROTECTED] Sent : Thursday, December 15, 2005 8:35 AM To :full-disclosure@lists.grok.org.uk Subject : [Full

Re: [FW-1] Firewall dropping packets

2005-12-22 Thread Ray
It's a SmartDefense drop. You have to change SmartDefense to allow connections to all ports, Network Security Dynamic Ports Select the top radio button Ray From: Tauseef Khan [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST

Re: [FW-1] Checkpoint vpn performance on SPLAT

2005-12-24 Thread Ray
require a crypto card for good performance. You might want to try kicking Phase 2 down to AES-128 while leaving Phase 1 at AES-256. That's what I run but I don't have the bandwidth requirements you do. Ray From: cisco4ng [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1

Re: [FW-1] Firewall dropping packets

2005-12-24 Thread Ray
on the firewall. I suspect Lindsay is correct; this is a protection that got moved into SmartDefense when it originally wasn't there. Ray From: Lindsay Hill [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW

Re: [FW-1] Urgent: Please help with another Connectra NGx question

2005-12-27 Thread Ray
I've seen this as well and also had it happen with user names. I've had to delete the object and recreate it with identical parameters to clear the error. Ray From: cisco4ng [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST

Re: [FW-1] Please help: Connectra Security Gateway on Secureplatform

2005-12-27 Thread Ray
, Ray From: cisco4ng [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] Please help: Connectra Security Gateway on Secureplatform Date: Mon, 26 Dec 2005 17:22

Re: [FW-1] Please help: Connectra Security Gateway on Secureplatform

2005-12-28 Thread Ray
been an issue. I don't know how you're enforcing that restriction on your employees, but if it's a personal firewall, you could add a rule to allow TCP 444 to the Connectra public IP only. Ray From: Reinhard Stich [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1

Re: [FW-1] Please help: Connectra Security Gateway on Secureplatform

2005-12-28 Thread Ray
certificate. Ray From: Ray [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Please help: Connectra Security Gateway on Secureplatform Date: Wed, 28 Dec

Re: [FW-1] Please help: Connectra Security Gateway on Secureplatform

2005-12-28 Thread Ray
through fine. It does not pass them automatically like IE does, Ray From: Covington, Chris [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Please help

Re: [FW-1] Please help: Connectra Security Gateway on Secureplatform

2005-12-28 Thread Ray
on user. RAy From: Michael J. Semaniuk [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Please help: Connectra Security Gateway on Secureplatform Date

Re: [FW-1] Please help: Connectra Security Gateway on Secureplatform

2005-12-28 Thread Ray
and it works fine. We had some US citizens over there recently and they were able to compare Connectra versus SecureClient in the US and they said there wasn't any noticeable difference. Ray From: Reinhard Stich [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1

Re: [FW-1] Firewall dropping packets

2005-12-29 Thread Ray
Are you thinking of the FTP Bounce attack? That protection is one of the ones in SmartDefense that cannot be disabled (as I recall). Seems t0 ne it's a defect in the FTP protocol, so if you have something that follows the protocol, then you are susceptible. Ray From: Charalambos

Re: [FW-1] Firewall dropping packets

2005-12-29 Thread Ray
Thanks for the detailed reply. That's pretty much what was happening to us with Outlook and Exchange. Ray From: Charalambos Klitiropoulos [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST

Re: [FW-1] Another Connectra on SecurePlatform Question Part III... Please help

2005-12-30 Thread Ray
://java.sun.com Ray From: cisco4ng [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] Another Connectra on SecurePlatform Question Part III... Please help

Re: [FW-1] Cannot connect with SecuRemote (SR)

2005-12-30 Thread Ray
to the Internet. Ray = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail = To unsubscribe from this mailing list, please

Re: [FW-1] Access to SecureKnowledge base

2006-01-02 Thread Ray
I don't know about this, however if you pass the CCSA test, you receive twelve months of Advanced Access to SecureKnowledge. If you pass the CCSE test, you receive eighteen months of Advanced Access. This might be an alternative for you. Ray From: Delava Alain [EMAIL PROTECTED] Reply

Re: [FW-1] VPN Edge Policy Install Failed

2006-01-06 Thread Ray
You probably need to download the libsw updates for that level of the firmware and install it on the SmartCenter. They'e on the same page as the firmware download. Seems to me that NGX requires the libsw updates applied in two folders, unlike R55. Ray From: Michel Lapointe [EMAIL

Re: [FW-1] PLEASE READ: CHECKPOINT TECHNICAL SUPPORT SUCKS

2006-01-07 Thread Ray
as they are to you and we're adding more Check Point products to our systems because of their performance and reliability. Or maybe that statement just says something about our other vendors. :-) Ray From: cisco4ng [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1

Re: [FW-1] Secure remote Client Version

2006-01-10 Thread Ray
or are you getting into modifying site-to-site VPNs and such? RAy From: Robert Fowler [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] Secure remote Client

Re: [FW-1] Edge firmware v6.0.42x

2006-01-11 Thread Ray
There have been several complaints about 6.0.42 on the www.sofaware.com discussion groups, for whatever that's worth. Ray From: Russell Aspinwall [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1

Re: [FW-1] SmartCenter's IP address change

2006-01-12 Thread Ray
disk space or reduce what you're logging temporarily). The certificate authority CRL will be cached on the gateways, so that's not an issue either. I routinely take mine down for two hours or so to create a disaster recovery disk image with Symantec Ghost. Ray From: mymailinglistsonly [EMAIL

Re: [FW-1] Change of IP for remote VPN

2006-01-12 Thread Ray
and you can specify just the old destination IP address. Sometimes it's fast, sometimes it takes a few minutes to complete its thing. Ray From: Tom Brown [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1

Re: [FW-1] preventing SSH tunnels

2006-01-16 Thread Ray
the proxy server IP address. E. B, C, D. Ray From: Tom Brown [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] preventing SSH tunnels Date: Mon, 16 Jan

Re: [FW-1] Gurus in this list. Please help

2006-01-16 Thread Ray
. Ray In Windows the default is to first check the host file, then DNS or WINS (from Win2k and on DNS is used before WINS). = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw

Re: [FW-1] QOS on NG AI R55 HFA16

2006-01-17 Thread Ray
will they be using to stream the audio? Is it really streaming or just HTTP downloads? Ray From: Alan Choyna [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] QOS

[FW-1] Posting on VulnWatch about privilege escalation potential with SecureClient/SR

2006-01-17 Thread Ray
of other stuff they (or malware) can do as well. The first reference link is interesting, though. Posted as an item of possible interest, Ray Date: Tuesday, January 17, 2006 4:48 PM From: Thierry Zoller [EMAIL PROTECTED

[FW-1] NGX HFA 02 released

2006-01-18 Thread Ray
http://www.checkpoint.com/downloads/latest/hfa.html Ray = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail

Re: [FW-1] managing an enforcement server externally

2006-01-21 Thread Ray
will have to re-license the SmartCenter using the User Center. If that's the only change, I don't think you'll have to change anything with SIC. Ray From: Alexander Simbun [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST

Re: [FW-1] Urgent please help. VPN issue

2006-01-21 Thread Ray
Agreed on this, and I once found an SK article that confirmed it. Ray Personally I've had to play with the exportable for securemote/secureclient setting and it DOES have an impact. = To set vacation, Out-Of-Office, or away messages, send

Re: [FW-1] managing an enforcement server externally

2006-01-22 Thread Ray
VPN traffic. Are you using central licensing? What versions are the SmartCenter and enforcement modules on? Ray From: Alexander Simbun [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST

Re: [FW-1] managing an enforcement server externally

2006-01-22 Thread Ray
SmartCenter is on our internal network and I manage the main firewall from behind it. We have WAN connections to other locations. In one of those other locatons I have an internal firewall. I can only reach it from its external interface and I can manage it just fine. Good luck! Ray From

Re: [FW-1] Same SecuRemote IP (behind a NAT device) detected.

2006-01-29 Thread Ray
you clone a computer with Symantec AntiVirus Corporate Edition). It's a GUID that is supposed to be unique to each computer but the clone image put the same key on all of them. Ray From: Sommerfeld, Frank [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1

Re: [FW-1] Same SecuRemote IP (behind a NAT device) detected.

2006-01-30 Thread Ray
Seems to me you can just delete the key and reboot. Ray From: Sommerfeld, Frank [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Same SecuRemote IP

Re: [FW-1] SecureClient questions

2006-01-31 Thread Ray
and userc.C, I use WinZip to zip it up and then use the companion self-extractor creator to make it a single .EXE install file. userc.C is modified to preset the gateway IP address, etc., so it's easier to configure when installed. Ray = To set

Re: [FW-1] Deliver Hostname with SecureClient in Office Mode and DHCP

2006-01-31 Thread Ray
Yes. Apply at least HFA-01 to the gateway, use the NGX R60 version of SecureClient and follow the directions in this article: Hosts cannot use DNS name to access SecureClient Solution ID: #sk23196 Ray From: Bernhard Weiser [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1

Re: [FW-1] SecureClient questions

2006-02-01 Thread Ray
Yes, it is. It installs as part of SmartCenter. It does have some limitations, though. For instance it un-modifies PRODUCT.INI. If you try to create a Compact View deployment, it backs out all of your changes without asking. That's why I now do it manually. Ray From: Robbie Elliott [EMAIL

Re: [FW-1] VPN Extranet Question

2006-02-03 Thread Ray
to translate the other side into a different address range and then use some sort of static name resolution. Ray From: Chris McGill [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST

Re: [FW-1] SecuRemote over D-Link DI-514 and DI-624 routers

2006-02-04 Thread Ray
. Ray From: Ronny Nussbaum [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] SecuRemote over D-Link DI-514 and DI-624 routers Date: Sat, 4 Feb 2006 22:16

Re: [FW-1] SecuRemote over D-Link DI-514 and DI-624 routers

2006-02-05 Thread Ray
of a sudden everyone in the meeting could connect simultaneously via Visitor Mode. Ray From: Ronny Nussbaum [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1

Re: [FW-1] Smartview reporter clarification!!

2006-02-06 Thread Ray
on the SmartCenter. It actually looks like it's going to install the whole thing, copying files an everything, on the SmartCenter then all of a sudden it stops and gives you the choice to install just the add-on, which is what ships the logs to the database. Ray From: john maverick [EMAIL

Re: [FW-1] Smartview reporter clarification!!

2006-02-07 Thread Ray
No, no changes are made to the rules at all. You still have to enable it manually. Ray From: john maverick [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re

Re: [FW-1] ISA Firewall Question

2006-02-10 Thread Ray
Your best bet would be http://www.isaserver.org. How are they planning on connecting ISA in? Off a DMZ interface, in series with CP or what? I've got ISA 2000 behind CP and we're using it to control outbound web browsing traffic as well as to virus-scan incoming. Ray From: Robbie Elliott

Re: [FW-1] Error: PS: less than 10 percent license free

2006-02-17 Thread Ray
. The difference is probably that the SecureClient firewall protects the laptop whether it is connected or not. Ray From: Mark Williams [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST

Re: [FW-1] Problem SecureClient access to SDS Server

2006-02-17 Thread Ray
Hi Fabrice, The solution is to forget about SDS. It's no longer a part of the system starting with NGX, probably because Check Point now supplies .MSI files. You're trying to make something work that you cannot use in the future. Ray From: Fabrice BARUTEL [EMAIL PROTECTED] Reply

Re: [FW-1] URGENT: IP350 NGX

2006-02-18 Thread Ray
Seems to me there has been a revision or two to IPSO 3.9. Which variant are you using? Ray From: Jignesh Joshi [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject

Re: [FW-1] ISA Firewall Question

2006-02-19 Thread Ray
the firewall. Another really neat feature is that the ISA inbound listener ignores connections coming in by IP address and not the DNS name. It makes port scanning virtually useless because ISA just ignores the traffic since the connection is by IP address. Ray From: Hawkins, Michael

Re: [FW-1] Error: PS: less than 10 percent license free

2006-02-20 Thread Ray
Don't know. What version and HFA level are you on? Ray From: Mark Williams [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Error: PS: less than 10

Re: [FW-1] ISA Firewall Question

2006-02-21 Thread Ray
anything else. Ray From: Hawkins, Michael [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] ISA Firewall Question Date: Tue, 21 Feb 2006 20:25:19 -0500 Yes

Re: [FW-1] Error: PS: less than 10 percent license free

2006-02-21 Thread Ray
What does SmartView Status show for the enforcement module under Policy Server? You're somewhat behind on HFA's, however I would think you're current enough that it should be enforcing the license limit. Ray From: Mark Williams [EMAIL PROTECTED] Reply-To: Mailing list for discussion

Re: [FW-1] Error: PS: less than 10 percent license free

2006-02-22 Thread Ray
years ago, anyway). Remember that you can buy licenses from any CP dealer, so if they won't offer you relief from their mistake, go elsewhere. Good luck, Ray From: Mark Williams [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST

Re: [FW-1] Web Radio - AI R55 with Smart Defence

2006-03-01 Thread Ray
There is a SmartDefense block for iTunes somewhere but I don't know how much of iTunes it does block. Look in that big long list of HTTP headers that it can examine. Ray From: Tom Brown [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST

Re: [FW-1] Secure Remote problem

2006-03-06 Thread Ray
gateway, bu that certainly does not explain why the Office Mode IP is not being seen behind the Nokia. Maybe it's a clue, though. Ray From: [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST

Re: [FW-1] Secure Remote problem

2006-03-07 Thread Ray
is the Nokia box (doesn't go via the SPLAT). It is going via the SPLAT box; it just doesn't show up in the traceroute. If it wasn't, the Nokia would not show up as the first hop. Does this help? Ray From: [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW

Re: [FW-1] Microsoft-ds Traffic

2006-03-13 Thread Ray
SmartDefense settings apply to all interfaces. If you had a second interface that went over to a DMZ and you needed to copy files across it, you wouldn't be able to do so if SmartDefense blocked it. Ray From: Claudia Cordova [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall

Re: [FW-1] WSE0020008

2006-03-14 Thread Ray
files. Do those emails have zip file attachments? Ray From: Verweyen, Dirk [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] WSE0020008 Date: Tue, 14 Mar 2006

Re: [FW-1] WSE0020008

2006-03-14 Thread Ray
there that violate this part of RFC-2616 and so we have had to rethink our answer to this problem. FWIW, Ray From: Ray [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re

Re: [FW-1] SmartReporter Distribute Installation license

2006-03-21 Thread Ray
If you're asking whether you can set up a separate box for consolidating the logs and generating reports without buying another license, yes. That box becomes a Check Point host. The recommended method is to keep the Reporter database separate from the SmartCenter. Ray From: Alexander

Re: [FW-1] Hot Fix level

2006-03-24 Thread Ray
http://www.checkpoint.com/downloads/latest/hfa/vpn1pro_express.html - HFA 02 is current and 03 is imminent. Ray From: Hal Huntley [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST

Re: [FW-1] SecureClient error - tunnel test (NGX R60)

2006-03-28 Thread Ray
Are you using Office Mode? The error message says you should be because someone else with the same local IP adress is connected at the same time. Is that possible? Ray From: G³owacki S³awomir [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW

Re: [FW-1] SecureClient error - tunnel test (NGX R60)

2006-03-30 Thread Ray
It's possible if you deploy new computers with SecureClient pre-installed and you also use a disk imaging program like Symantec Ghost. There's a unique virtual MAC address created as part of the installation in the registry. Any chance you're deploying computers like this? Ray From

[FW-1] Question on default route to a new ISP while retaining original IP

2006-03-30 Thread Ray
object? Or do I just have to keep the old router in place? Thanks for any education you can lend, Ray = To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail

Re: [FW-1] Question on default route to a new ISP while retaining original IP

2006-03-31 Thread Ray
to be a real pain ongoing. Ray From: Lyons, Jon [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Question on default route to a new ISP while retaining

Re: [FW-1] Question on default route to a new ISP while retaining original IP

2006-03-31 Thread Ray
Thanks Jason and Lino. Unfortunately I now have ask you to answer a new question. :-) What the heck is a sub-interface? I have ever heard that term before. Yes, they are our IP addresses and the new ISP will announce them for us. No, they are not NATting anything from us. Thanks, Ray

Re: [FW-1] Question on default route to a new ISP while retaining original IP

2006-04-01 Thread Ray
via SmartUpdate, it learns that IP address. When I detach it via SmartUpdate, the license is available for re-use. My UserCenter account license list does not show any IP addresses other than my SmartCenter. Thanks for all of your time, Ray From: chkp tech [EMAIL PROTECTED] Reply

Re: [FW-1] Question on default route to a new ISP while retaining original IP

2006-04-03 Thread Ray
Yeah, that's what I wanted to do, but they said they can't do it because it's a switch and because it's not their IP space. I don't think they're being difficult, probably a company policy or something. Thanks for all of your help, Ray From: Lyons, Jon [EMAIL PROTECTED] Reply-To: Mailing

Re: [FW-1] Connectra - File Share

2006-04-06 Thread Ray
. The only one we cannot open is Access files, and it appears to be a Microsoft thing. If there's a . in the file path, as there is in the URL, Access refuses to open because it thinks its coming from an unsafe environment (or some other silly thing like that). Ray From: Peter Gavagan, Jr. [EMAIL

Re: [FW-1] Connectra - File Share

2006-04-07 Thread Ray
Is your call for the Access issue? Unfortunately fhat won't work for us because they're shared databases. Ray From: Khan, Irfan [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM To: FW-1-MAILINGLIST

[FW-1] Connectra NGX R61 available for download

2006-04-09 Thread Ray
At the Check Point site. Cluster XL Secure Workspace Embedded applications, where the app is on the Connectra gateway File Shares no longer use Web Folders An SNX client for the Mac and a bunch more. Ray = To set vacation, Out-Of-Office, or away

Re: [FW-1] Connectra NGX R61 available for download

2006-04-10 Thread Ray
Go into the Software Subscriptions, Download Selector, select Connectra, etc. I grabbed it this morning but am still going through the docs. Ray From: Jeremy Lieb [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM

Re: [FW-1] Connectra NGX R61 available for download

2006-04-10 Thread Ray
Nope. The number of R61 articles is slowly increasing in SecureKnowledge, so I figure it'll be soon. I might actually have to move off of R55 this year before I get too far behind. :-) Ray From: Jeremy Lieb [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1

Re: [FW-1] Connectra NGX R61 available for download

2006-04-11 Thread Ray
and executes it locally without having to install ti locally, seems nice. I'm a bit disappointed that only SSH v1 is supported, not SSH v2, though. Time will tell, Ray From: Jeremy Lieb [EMAIL PROTECTED] Reply-To: Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST

[FW-1] NGX HFA 03 available for download

2006-04-11 Thread Ray
thing that seems to be missing is Connectra R60 HFA 02, which was supposed to be out a few months ago. It was supposed to allow the SSL Network Extender to auto-minimize, which is a nice feature. Ray = To set vacation, Out-Of-Office, or away

<    1   2   3   4   5   6   7   8   9   10   >