[FW-1] Urgent need for hardening Windows 2003 Server for NGX R65 installation

2008-08-08 Thread a bv
Hi, Im in an urgent need to have a checklist for hardening windows 2003 server which NGX R65 firewall will be installed . So we need to harden the OS for security but also let the firewall run normally. I found that that there is Checkpoint article which is called sk26458 but i cant access it.

[FW-1] Firewall administrator user database creation privilege problem

2008-09-03 Thread a bv
Hi all, On a windows NGX R65 system i would like to add a new firewall admin and have the ability to create change objects. But on the permissions profile Objects Database is read-only . And also from the cpconfig only one admin can be set. Regards Scanned by Check Point Total Security

Re: [FW-1] Firewall administrator user database creation privilege problem

2008-09-03 Thread a bv
Hi, Yes i try form the Smartdashboard and get the problem Regards 2008/9/3 pkc_mls [EMAIL PROTECTED] a bv a écrit : Hi all, On a windows NGX R65 system i would like to add a new firewall admin and have the ability to create change objects. But on the permissions profile Objects

Re: [FW-1] Firewall administrator user database creation privilege problem

2008-09-03 Thread a bv
Yes i have connected with it and try to create the new admin 2008/9/3 pkc_mls [EMAIL PROTECTED] a bv a écrit : Hi, Yes i try form the Smartdashboard and get the problem Did you connect with the admin created via the cpconfig ? Regards 2008/9/3 pkc_mls [EMAIL PROTECTED] Scanned

Re: [FW-1] Firewall administrator user database creation privilege problem

2008-09-04 Thread a bv
, then sign in with a user that has that profile set? Did they not have the ability to create nodes? Christopher Hoff | Systems Engineer | FishNet Security -Original Message- From: Mailing list for discussion of Firewall-1 [mailto: [EMAIL PROTECTED] On Behalf Of a bv Sent: Wednesday

Re: [FW-1] Checkpoint Gateway Antivirus

2008-09-09 Thread a bv
Hi Markus, Not about the av side i wondered if all the processes, the whole firewall went well after enabling the addons like messaging security. regards 2008/9/9 Markus Schmidt [EMAIL PROTECTED] Hi there, I recently set up a NGX R65 w Messenging Security Gateway, and configured it for

[FW-1] VPN/UTM Edge X -connecting to and managing from smartcenter

2008-11-12 Thread a bv
Hi, I have a demo UTMEdge X box which i would like to connect and manage from NGX R65 on Windows. I created a vpnedge gateway object and a new policy package on smartdashboard but couldnt communicate with it. And i dont know what to do on the edge appliance itself to let itself to be managed.

Re: [FW-1] VPN/UTM Edge X -connecting to and managing from smartcenter

2008-11-12 Thread a bv
. This is also well documented. -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of a bv Sent: November-12-08 9:02 AM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] VPN/UTM Edge X -connecting to and managing

Re: [FW-1] VPN/UTM Edge X -connecting to and managing from smartcenter

2008-11-12 Thread a bv
but it gave error connection refused. So what to fix? Regards 2008/11/12 a bv [EMAIL PROTECTED]: I have tried this (gave IP addresses of 2 interface of NGX R65) but i get the error the service center did not respond. I guess for now the device is unable to access the interface of the firewall

Re: [FW-1] VPN/UTM Edge X -connecting to and managing from smartcenter

2008-11-13 Thread a bv
And lastly i entered the gateway name i created for the edge itself and made the connection . But i got the errors from smartview tracker about the policy installation and etc. Ill examine the logs for what are they and try to fix the issues regards 2008/11/12 a bv [EMAIL PROTECTED]: I have

Re: [FW-1] VPN/UTM Edge X -connecting to and managing from smartcenter

2008-11-13 Thread a bv
:22:52 Failed to install updated security policy 00015 13Nov2008 11:22:52 Wrong update version in policy (got 511 instead of 600) Regards 2008/11/13 a bv [EMAIL PROTECTED]: And lastly i entered the gateway name i created for the edge itself and made the connection . But i got the errors

[FW-1] Understanding and configuring QOS on an exiting R65 gateway

2009-03-25 Thread a bv
Hi all, Having forgetten the Checkpoint QOS im need in a crash understanding it , which then im in need of adding a rule for a destination on a current R65 gateway which has a QOS policy configured and enabled before. Are there any cool simple tutorials about that? Regards Scanned by Check

[FW-1] Daily log transfer of R65 on Windows 2003

2009-05-05 Thread a bv
Hi, I have an R65 on Windows 2003 installed long time ago. Im in need of transfering the daily log files to an other ftp server. I tried to use a script for this purposes written by someone else , which is aiming to zip (zip exe is taken form oracle or something else) the files and then transfer

[FW-1] R70: to upgrade or not?

2009-05-15 Thread a bv
Hi list, For the ones who upgraded their fw to R70 , or the ones who learned about the R70 what do you see improvements and advantages upgrading from R65 Regards Scanned by Check Point Total Security Gateway. = To set vacation, Out-Of-Office, or

Re: [FW-1] R70: to upgrade or not?

2009-05-15 Thread a bv
Thank you Reinhard, waiting for the others answers , i would also ask what you have found different at the IPS side (Smartdefense to IPS-1). Regards 2009/5/15, Hammond, Chris (CONT) chris.hamm...@capitalone.com: For the ones that had issues, what were they? Did they seem to revolved around

[FW-1] Windows 2003/R65 OS patch management

2009-06-02 Thread a bv
Hi, I have 2 hardware which on both Windows 2003 Server and R65 is installed. Also DNS server on both systems are working on to host the companies domains. For a long time the main firewall is working online. But this weekend i need to make the backup fw the same as the main one. I have exported

Re: [FW-1] Windows 2003/R65 OS patch management

2009-06-04 Thread a bv
are there any comments? 2009/6/3 a bv vbavbal...@gmail.com:  Hi, I have 2 hardware which on both Windows 2003 Server and R65 is installed. Also DNS server on both systems are working on to host the companies domains. For a long time the main firewall is working online. But this weekend i

Re: [FW-1] Windows 2003/R65 OS patch management

2009-06-04 Thread a bv
with the current patches etc. 2009/6/4 pkc_mls pkc_...@yahoo.fr: a bv a écrit : are there any comments? 2009/6/3 a bv vbavbal...@gmail.com:  Hi, I have 2 hardware which on both Windows 2003 Server and R65 is installed. Also DNS server on both systems are working on to host the companies

[FW-1] Observing the rules

2009-06-08 Thread a bv
Hi list, There are many rules on our R65 and when someone needs we add temporary rules but mostly the user who needs the temp rule dont warn us when he/she no longer needs it , and also we cant follow . So how can these rules effectively be observed , how often used or not used since x time? Are

[FW-1] Getting the standby firewall live

2009-06-23 Thread a bv
Hi, I have a Windows 2003 R65 fw running and another one standing by. I have controlled the DNS records of both (also acting as an external DNS) , imported a current fw configuration to the stand by one with upgrade_import. Ran the MSBA on the standby matching and installed all the patches it

[FW-1] Standby Firewalls interesting connections

2009-07-13 Thread a bv
Hi list, I have 2 boxes which Windows 2003 Server and NGX R65 is installed. One of them was working for a long time, and a short time ago its switched with the other one. For the aiming of installing the patches of the Windows (cause it was online so long and couldnt do it) , i have gave a local

[FW-1] Following the protections on Smartdefense by update/installation date

2009-08-11 Thread a bv
Hi, when we update smartdefense , either we use them or not the new downloaded protections are highlighted . But after we install the policy to save the updates the highlights or gone so its hard to find the new downloaded ones in many protections and overview them. Is there a pratical way to

[FW-1] Loggrabber and OPSEC information

2009-08-12 Thread a bv
Hi, I want to transfer a windows NGX R65 log files to a linux system which syslog-ng is installed. At the fw-1loggrabber configuration file there are some OPSEC information needed. I manage Checkpoint but till now couldnt understand what pratically OPSEC is and how to find OPSEC releated

[FW-1] License (adding) problem Upgrade from R65Windows 2003 to R70 SPLAT and edge

2009-09-09 Thread a bv
Hi, I have exported a CP NGX R65 onWindows 2003 configuration with upgrade_export and formated the backup fw with Secureplatfrom R70. I saw somewhere on the firewall also says that the trial period has gone (though i installed it before 15 days ). I opened the smartupdate on the current R65

Re: [FW-1] Basic rule question

2009-09-10 Thread a bv
The question is what must be the rule? is Source Any Destination MyDNSserversLocalIP(10.x.x.x) (which is given a real IP as static NAT) service dns and a second reverse rule will work? Regards 2009/9/10, Eugeniu Patrascu eu...@imacandi.net: a bv wrote: Hi, My question will be an easy one

[FW-1] When and how does the Site to Site VPN tunnel begins?

2009-09-14 Thread a bv
Hi, I have forgotten much about the VPN thing. I have site-to site VPNs configured with external CPs but when i look at the smart monitor for the vpn tunnels i see 0 . I want to test this vpn connection and how and when this tunnel will be active (ill see 1 or 2 tunnels) ? Regards Scanned by

[FW-1] Encryption fail reason :Packet is dropped because there is no valid SA sk 19423 error

2009-09-15 Thread a bv
Hi i got the above error on a site sto Site VPN which was used for a near time but the peer had problems and reported to reinstall the firewall and came back from config backup. The peer is not helpfulll we have both checked the community etc setting , created again teh communities etc. But still

[FW-1] Client encryption error thorough Site to Site

2009-09-17 Thread a bv
Hi, I have a Site to site VPN between an external firm. I have their ftp server in the vpndomain and a rule which 2 of our PCs have access to any service to destination of their ftp server through site to site vpn. I saw encrypted ftp logs from the real users PC , but when i try to ftp that

[FW-1] Exporting policy from NGX R65 to VPNedge

2009-09-25 Thread a bv
Hi, Is there a way to export policy from NGX R65 to use in VPNEdge? Regards Scanned by Check Point Total Security Gateway. = To set vacation, Out-Of-Office, or away messages, send an email to lists...@amadeus.us.checkpoint.com in the BODY of

Re: [FW-1] Exporting policy from NGX R65 to VPNedge

2009-09-28 Thread a bv
Then How? 2009/9/25 Reinhard Stich r.st...@internet-security.at: At 14:25 25.09.2009, you wrote: Hi, Is there a way to export policy from NGX R65  to use in VPNEdge? if the edge is managed from the same smartcenter as the R65 is: yes br reinhard -- Reinhard Stich          

[FW-1] Mailing the information about rules installed

2009-10-11 Thread a bv
Hi, I can get a mail alert when an policy is installed (somewhere at global policies we had configured before). But how can i make the information about the rules get mailed ? Regards Scanned by Check Point Total Security Gateway. = To set

Re: [FW-1] Mailing the information about rules installed

2009-10-11 Thread a bv
What about R65? and also at R70 iğs that free to use upgrading form R65? 2009/10/12 Eugeniu Patrascu eu...@imacandi.net: a bv wrote: Hi, I can get a mail alert when an policy is installed (somewhere at global policies we had configured before). But how can i make the information about

[FW-1] differences between r65 smartdefense and r70 IPS-1

2009-10-19 Thread a bv
Hi, what are the differences between r65 smartdefense and r70 IPS-1? Not only as a products (here smartdefense) new version, but if its more serious enterprise ips now. Regards Scanned by Check Point Total Security Gateway. = To set vacation,

[FW-1] vpn edge (managed by R65) lost password

2009-11-09 Thread a bv
Hi, I have a vpn edge which is connected (managed) to an R65 smartcenter , i have lost the vpnedges web interface usernam password . So how can i recover it while not giving harm to its production and configuration? Regards Scanned by Check Point Total Security Gateway.

Re: [FW-1] vpn edge (managed by R65) lost password

2009-11-09 Thread a bv
, Nov 9, 2009 at 2:21 AM, a bv vbavbal...@gmail.com wrote: Hi, I have a vpn edge which is connected (managed)  to an R65 smartcenter , i have lost the vpnedges web interface usernam password . So how can i recover it while not giving harm to its production and configuration? Regards

[FW-1] How do you review rulebase and objects on CP

2009-11-23 Thread a bv
Hi, I wanna ask to the list for best practices. How do you (and often) review /clean your rulebase and objects on Checkpoint firewalls? Or for not doing some kind of thing, do you have some tricks while creating these ? (time limited rules and objects?) Regards Scanned by Check Point Total

[FW-1] Resources for installing deploying cluster , high available- clustered Checkpoint Firewalls

2009-11-23 Thread a bv
Hi list, I wanna go on further than a stand alone firewall. Wanna learn how to create a high available, clustered CP firewalls ( especially regarding using R70 and R65 versions) . WAnd hat are the good points to start , and what are the documentation good to read ? And also ask how can an CP

Re: [FW-1] differences between r65 smartdefense and r70 IPS-1

2009-11-23 Thread a bv
NFR is finally making a difference... On Tue, Oct 20, 2009 at 1:40 AM, Hugo van der Kooij hvdko...@vanderkooij.org wrote: On 10/19/09 16:43, a bv wrote: Hi, what are the differences between  r65 smartdefense and r70 IPS-1?  Not only as a products (here smartdefense) new version

[FW-1] Network Knowledge requirements for CP

2009-11-23 Thread a bv
Hi while talking about basics these days, what are the minimum networking /tcp-ip knowledge to have (and never forget) to get cp firewall up runnning, deploying, monitoring and if when there is a problem finding that its not from it (maybe the switch router etc). Regards Scanned by Check Point

Re: [FW-1] Resources for installing deploying cluster , high available- clustered Checkpoint Firewalls

2009-11-23 Thread a bv
Many thanks forn the video links. More video and document,article , blog entry , how-tolink will be great. 2009/11/23 a bv vbavbal...@gmail.com: Hi list, I wanna go on further than a stand alone firewall. Wanna learn how to create a high available, clustered CP firewalls ( especially

[FW-1] Secureclient/Securemote compatibility with Windows 7

2009-11-23 Thread a bv
Hi, Which versions of Secureclient/Securemote compatibe, works fine with Window 7? Regards Scanned by Check Point Total Security Gateway. = To set vacation, Out-Of-Office, or away messages, send an email to lists...@amadeus.us.checkpoint.com in

Re: [FW-1] Secureclient/Securemote compatibility with Windows 7

2009-11-24 Thread a bv
, a bv vbavbal...@gmail.com wrote: Hi, Which versions of Secureclient/Securemote  compatibe, works fine  with Window 7? There is an EA release on Check Point site that is for Windows 7 32bit. They said that in Q1 2010 there should be one for Windows 7 64bit. Eugeniu Scanned by Check

[FW-1] How do you manage your Smartdefense/IPS policy ?

2009-11-24 Thread a bv
Hi, I wanna ask to the list members how do they manage /create their IPS1/smartdefense policy. How often do they update the signatures? How /and how often do they review the rules.? How do they test them, how do they monitor them and etc. Regards Scanned by Check Point Total Security Gateway.

[FW-1] Deploying IPSEC between DMZ network and a (some) LAN hosts

2009-11-24 Thread a bv
Hi, What i need to know about deploying IPSEC between DMZ network and a host (o a little more) which reside on LAN? Putting the security rule with some related ports will be enough to work it out or i need to know and monitor more? Regards Scanned by Check Point Total Security Gateway.

Re: [FW-1] vpn edge (managed by R65) lost password

2009-11-24 Thread a bv
don't understand your question. In case it is of any help to clarify, according with those instructions, you are supposed to open a browser and point to your SmartCenter IP on port 9283. Regards On Mon, Nov 9, 2009 at 9:37 AM, a bv vbavbal...@gmail.com wrote: Thanks  can i get the URL again

Re: [FW-1] vpn edge (managed by R65) lost password

2009-11-27 Thread a bv
: Mailing list for discussion of Firewall-1 [mailto:fw-1-mailingl...@amadeus.us.checkpoint.com] On Behalf Of a bv Sent: Tuesday, November 24, 2009 11:30 PM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] vpn edge (managed by R65) lost password Hi Sergio , http

Re: [FW-1] vpn edge (managed by R65) lost password

2009-11-27 Thread a bv
the traffic match the rule. Alexey -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:fw-1-mailingl...@amadeus.us.checkpoint.com] On Behalf Of a bv Sent: Friday, November 27, 2009 2:13 PM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] vpn edge

[FW-1] Taking responsiblity of a legacy CP firewall

2009-11-27 Thread a bv
Hi, Think of you were a stand alone CP firewalls administrator which its downtime was not critical to firm and no high availabiliy is expected. Then youll have an other job offer /job apply and which there youll find that things are taken more seriously and there is a more complicated checkpoint

Re: [FW-1] Deploying IPSEC between DMZ network and a (some) LAN hosts

2009-12-02 Thread a bv
What is wanted is to encrypt the traffic between DMZ segment and a machine at LAN. the trafiicc will be about database processes i guess . I controll the fw but dont know what the people are trying to do much. Regards 2009/12/1 pkc_mls pkc_...@yahoo.fr: a bv a écrit : Hi, What i need to know

Re: [FW-1] Deploying IPSEC between DMZ network and a (some) LAN hosts

2009-12-03 Thread a bv
They wanted me to add a access rule for both ways between that host at LAN and whole DMZ subnet for ESP protocol group. At the host sides the owners ( other people from mycompany ) applied ipsec on the hosts as i know. Can you explain in detail for statement inwriting ? Regards 2009/12/2

Re: [FW-1] vpn edge (managed by R65) lost password

2009-12-03 Thread a bv
:This Gateway:Any Service Allow Source This GatewayANY:Any Service Allow 2009/11/28 a bv vbavbal...@gmail.com: I was able to install the policy at the age but havent done for a long time (it has its own policy) .Yes its an standalone R65

Re: [FW-1] Deploying IPSEC between DMZ network and a (some) LAN hosts

2009-12-03 Thread a bv
for the hosts at LAN can be given outside the world and DMZ? Regards 2009/12/3 pkc_mls pkc_...@yahoo.fr: a bv a écrit : They wanted me to add a access rule for both ways between that host at LAN and whole DMZ subnet  for  ESP protocol group. At the host sides the owners ( other people from mycompany

[FW-1] Vpnedge managed by R65 log and policy install problem

2009-12-04 Thread a bv
Hi, I have a vpnedge box which is managed by R65 smartcenter and configured to send the logs to the smarcenter. I couldnt look at the smartview tracker for sometime for these logs and didnt tried to install policy on edge box. I looked at yesterday at the webui of the box for event logs but all

[FW-1] Firewall policy management and audit

2009-12-14 Thread a bv
Hi list I wanna ask for the list members for their procedures, rules , how-tos and best practices for firewall (CP) rule/policy change management and audit. For example how do you accept rule change/new rule requests , how and (who ) approves that, how do you audit these changes etc. Regards

[FW-1] http https port address translation for a web portal

2009-12-14 Thread a bv
Hi , There is an web portal application which works in the enterprise as http. But the team wants to open this application to outside world to serve as https . They want all the traffic, access from outside to be encrypted or secure. They have their SSL certificate installed. We have a rule which

[FW-1] Best practices for bandwith statistics and bandwith management

2009-12-21 Thread a bv
Hi , Having a R65 CP with only QOS and Smartdefense i would like to ask what are the best practices for observing and reporting the bandwith usage (for both short and long times) and analyzing if there are any bottlenecks (for example the cause of mail slow processing problem is releated with

Re: [FW-1] Best practices for bandwith statistics and bandwith management

2009-12-22 Thread a bv
I didnt know if the Smartview Monitor is licensed additionally ( i knew that it was free), i have it . I can use it but looking for best practices. Where the smartview monitor get these data? from the log files? For example for long term fro teh need of disk space we remove some logs to an

[FW-1] Exceptions on Smartdefense

2009-12-23 Thread a bv
Hi, Is there any way to define exceptions for the source for the protections on R65's smartdefense? For example getting a protection for a client IP to be monitor-only or only logging? Regards Scanned by Check Point Total Security Gateway. = To

[FW-1] Evaluating the R70 blades

2009-12-25 Thread a bv
Hi list, If there are some friends here who are using or evaluating the new R70 blades , will they share their thoughts and experiences about these blades and also how can i evaluate them? Regards Scanned by Check Point Total Security Gateway. =

[FW-1] About URI resources

2009-12-28 Thread a bv
Hi, Can somone briefly explain what a URI resource at Checkpoint means and how and whene used? Regards Scanned by Check Point Total Security Gateway. = To set vacation, Out-Of-Office, or away messages, send an email to

[FW-1] (smartcenter managed) UTM-1 Edge X conenction problem with R65 smartcenter

2009-12-29 Thread a bv
Hi, There seems to be a problem with an utm-1 edgex which is connected to a smartcenter for management for a time ago (and also send its logs to smartcenter). At the Smartview Monitor the edge seems disconnected also at the web ui of the edge there is a sentence which says Connection Refused:

Re: [FW-1] Réf. : [FW-1] (smartcenter managed) UTM- 1 Edge X conenction problem with R65 smartcenter

2009-12-29 Thread a bv
Klotz GFI Informatique 158, avenue de Verdun, 92130 Issy les Moulineaux, France Web: www.gfi.fr a bv vbavbal...@gmail.com Envoyé par : Mailing list for discussion of Firewall-1 FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM 29/12/2009 15:45 Veuillez répondre à Mailing list for discussion

[FW-1] Performance measuring and tuning

2010-01-17 Thread a bv
Hi list, What are the methods /best practices for performance measuring and tuning of a Checkpoint firewall? What are the metrics? Regards Scanned by Check Point Total Security Gateway. = To set vacation, Out-Of-Office, or away messages, send an

[FW-1] R65 to R70 upgrade license issues

2010-01-17 Thread a bv
Hi, Sellers partners distributors of Checkpoint mixes mind about the upgrade from a R65 firewall to R70 firewall. Its hard to understand what has to be done which steps are exiting, which steps are free, which steps require payment and how much. Is there anyone on the list who is clear or had

[FW-1] Smartdefense / IPS1 and networks

2010-01-19 Thread a bv
Hi, Which networks do the Smartdefense and IPS1 protect from attacks which it has the signatures? From internet ok,, but does it also protect scans from LAN to DMZ network also? And if so is it possible to give exceptions from a source (for example someone is trying to pentest from LAN ?)

[FW-1] Blocking instant messaging traffic with Smartdefense

2010-03-09 Thread a bv
Hi, I would like to block instant messaging with smartdefense under R65 and applied the patterns which is date is 15 Feb 2010. And also foumd and Checkpoint article and added some values at the hedaer rejection. For testing some i was able to login some were blocked really for login. How can i

Re: [FW-1] Blocking instant messaging traffic with Smartdefense

2010-03-18 Thread a bv
Is there anyone , who has an idea about that? any custom header to put on rejection? Regards 2010/3/15, a bv vbavbal...@gmail.com: Hi Paolo, It seems that i have all the patterns activated (both at the IM part and Header Rejection side) and gave no exception to any client , but i still can

[FW-1] Preventing SQL injection with Smartdefense

2010-03-20 Thread a bv
Hi, I would like to block and monitor sql injection attacks with Smartdefense (R65) , and im not a web/programming/sql expert. Enableing all the patterns under sql injection (on monitoring mode) gives many logs inbound and outbond . So what is the best practices for this? Regards Scanned by

[FW-1] How to reset some connections on firewall

2010-03-23 Thread a bv
Hi how can i reset desired connections with source and destination ip when wanted on R65 winodws and secureplatform? Regards Scanned by Check Point Total Security Gateway. = To set vacation, Out-Of-Office, or away messages, send an email to

Re: [FW-1] Blocking instant messaging traffic with Smartdefense

2010-03-24 Thread a bv
receive this message by error, please immediately send it back and delete the message received. -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:fw-1-mailingl...@amadeus.us.checkpoint.com] On Behalf Of a bv Sent: Jueves, 18 de Marzo de 2010 08:50 a.m. To: FW-1

[FW-1] Importing R65 windows config to SP R70 (interface question)

2010-03-24 Thread a bv
Hi, Im trying to import current configuration R65 on windows to R70 secureplatform. I did this before on this firewall and tried and it worked but take it offline again. now im again trying to export the current config from windows r65 to SP r70 . I did this , take my laptop , connected it

[FW-1] Calculating the hardware needs

2010-03-26 Thread a bv
Hi, How can we find out the hardware requirements of an SPLAT or Windows R65/R70 installations that will meet our enterprise? If we have a current installation/hardware how can we find out if we will need an hardware upgrade/change by the time somethings change (number of users, bandwith

Re: [FW-1] Calculating the hardware needs

2010-03-26 Thread a bv
of Firewall-1 [mailto:fw-1-mailingl...@amadeus.us.checkpoint.com] On Behalf Of a bv Sent: Friday, March 26, 2010 8:33 AM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: [FW-1] Calculating the hardware needs Hi, How can we find out the hardware requirements of an  SPLAT or Windows R65

Re: [FW-1] Calculating the hardware needs

2010-03-26 Thread a bv
Of a bv Sent: Friday, March 26, 2010 9:20 AM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] Calculating the hardware needs Hi, What about a current running one? What  difrrences will bring the need of an any upgrade? (memory cpu or even the whle hardware? Regards 2010/3

[FW-1] Real and virtual memory status from Smartview Monitor

2010-03-29 Thread a bv
Hi, Looking at the Smartview Monitor of an Windows 2003 Server/R65, i get the total virtual memory same as the maximum paging file size enabled at the windows , good. And i see a current used value for that. But at the total real memory part , i get the 2048 MB , which i (right click the my

[FW-1] Importing R65 windows config to SP R70 (interface question)

2010-03-30 Thread a bv
Hi, Im trying to import current configuration R65 on windows to R70 secureplatform. I did this before on this firewall and tried and it worked but take it offline again. now im again trying to export the current config from windows r65 to SP r70 . I did this , take my laptop , connected it with a

Re: [FW-1] How to reset some connections on firewall

2010-03-31 Thread a bv
intruder, and picking what options you intended for killing the connection? -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:fw-1-mailingl...@amadeus.us.checkpoint.com] On Behalf Of a bv Sent: Tuesday, March 23, 2010 04:44 To: FW-1-MAILINGLIST

Re: [FW-1] How to reset some connections on firewall

2010-03-31 Thread a bv
that connections only? Cause the connections i wanna drop is a production releated connection and need them after killing the current connections. 2010/3/31, Dameon Welch-Abernathy dwe...@checkpoint.com: On Mar 31, 2010, at 1:01 AM, a bv wrote: I found that fw tab -t connections -x clear all the connectsion

Re: [FW-1] How to reset some connections on firewall

2010-03-31 Thread a bv
many thanks im looking for the right examples for fw sam . 2010/3/31 pkc_mls pkc_...@yahoo.fr: a bv a écrit : I found that fw tab -t connections -x clear all the connectsion but i what i need is drop spesicif connections by source and destinations like source hosta  destination hostb port

Re: [FW-1] Importing R65 windows config to SP R70 (interface question)

2010-04-01 Thread a bv
Any ideas about the problem ans solution ? Regards 2010/3/30, a bv vbavbal...@gmail.com: Hi, Im trying to import current configuration R65 on windows to R70 secureplatform. I did this before on this firewall and tried and it worked but take it offline again. now im again trying to export

[FW-1] Policy (QOS) install error after a R65 Windows /R70 migration

2010-04-02 Thread a bv
Hi, After setting up a fresh R70 SPLAT and then importing the current configuration file of a production Windows 2003 /R65 i was able to login to the smartdashboard with my laptop only after giving the command fw unload local at the R70 SPLAT. After that i logined saw the rules i have expected

Re: [FW-1] Policy (QOS) install error after a R65 Windows /R70 migration

2010-04-02 Thread a bv
pkc_...@yahoo.fr: a bv a écrit : Hi, After setting up a fresh R70 SPLAT and then importing the current configuration file of a production Windows 2003 /R65 i was able to login to the smartdashboard with my laptop only after giving the command fw unload local at the R70 SPLAT. After that i

[FW-1] ipsec between database (LAN) and aplication server (DMZ) through CP

2010-04-05 Thread a bv
Hi, There is an database server at LAN and an application server at DMZ which needs to communicate all the time. The system admins implemented ipsec on their end to make this communication through ipsec. Of course the firewall is R65 and a security rule are given for allowing the communication

[FW-1] Audit logs, finding rule/object delete information

2010-04-12 Thread a bv
Hi all, How can we find a specific rule or objects delete time and other details like deleted by who etc on audit logs?It seems that a rule is deleted and i wanna find the details , releated access cannot be occured Regards Scanned by Check Point Total Security Gateway.

[FW-1] Preparing a Smartdefense /IPS1 policy

2010-04-12 Thread a bv
Hi all, How do you determine a Smartdefense/IPS1 policy ? What are the steps you take to make or change this policy? Regards Scanned by Check Point Total Security Gateway. = To set vacation, Out-Of-Office, or away messages, send an email to

[FW-1] Policy installation/does it have side effects?

2010-04-12 Thread a bv
Hi, Does making a policy installation on CP firewall (SP,Windows r60,62i65,70 whatever version) have side affects? Does it effect the current connections or effect anything else? Regards Scanned by Check Point Total Security Gateway. = To set

[FW-1] User password change

2010-05-11 Thread a bv
Hi after a user password change at users and administrators from Smartdashboard is it necessary to installa database or install policy to save the new password Regards Scanned by Check Point Total Security Gateway. = To set vacation,

[FW-1] After disk space full

2010-05-11 Thread a bv
Hi, as the log files grow up what does the CP do on both windows and SP after the disk is full. Scanned by Check Point Total Security Gateway. = To set vacation, Out-Of-Office, or away messages, send an email to lists...@amadeus.us.checkpoint.com

[FW-1] Tracking Smartdefense updates made at R65

2010-05-14 Thread a bv
Hi, When you update smartdefense at R65 the new signatures seem bold when first downloaded, so you have that time to see and review the new signatures. But if you escape it they will seem as regular not bold and its hard to find out whats newly came Is there ant trich you use for tracking these?

[FW-1] Utmedge connected to R70 SPLAT logging problem

2010-06-09 Thread a bv
Hi , On an R70 Splat gateway there is an utmedge object (which has an different internet gateway ) and at its properties at the logging part forward logs to Security Management Server is selected. But when when i look at the smarttracker i cant see any log ? There is an proxy behind this utm and

Re: [FW-1] Utmedge connected to R70 SPLAT logging problem

2010-06-10 Thread a bv
but still cant resolve it. Connected to the edges console by ssh but couldnt find a way to add an static host entry. Regards 2010/6/9, a bv vbavbal...@gmail.com: Hi , On an R70 Splat gateway there is an utmedge object (which has an different internet gateway ) and at its properties

[FW-1] auditing security through CPto CP site to site VPN

2010-07-13 Thread a bv
Hi, After configuring a site to site vpn between 2 enterprises (both Checkpoint gateway) and 2 application servers making traffic , how to audit the security of this connection and the traffic and data? Regards Scanned by Check Point Total Security Gateway.

Re: [FW-1] auditing security through CPto CP site to site VPN

2010-07-13 Thread a bv
Hi, i want to show and improve that this communication is secure. Regards 2010/7/13, pkc_mls pkc_...@yahoo.fr: Le 7/13/2010 9:33 AM, a bv a écrit : Hi, After configuring a site to site vpn between 2 enterprises (both Checkpoint gateway) and 2 application servers making traffic , how

[FW-1] upgrade_import error

2010-07-22 Thread a bv
Hi I have installed a R70 SPLAT on an open server, made nearly none configuration and then tried to use the configuration file from an production R70 SPLAT with upgrade_import. upgrade_import started , but it ended with an error saying Error: 'Failed to read the configuration info of the

[FW-1] technical specs and paramaters of FW-1

2010-07-27 Thread a bv
Hi, How can i find, or someone share (deep) technical specs of a FW-1 R65 and R70 , and also releated paramaters (tcp/ip related paramaters and so) , and how can i found out or test on a production one? Regards Scanned by Check Point Total Security Gateway.

[FW-1] static arp entry at 2 diffent SPLAT boxes

2010-08-11 Thread a bv
Hi, Having a 2 FW-1 SPLAT R70 box and sometimes switching from one to the makes an extra offline time cause of the arp. Cause the internet gateway device (router, modem etc) has the first fws arp entry, not the others one and also the new online taken box doesnt know its gateway devices mac

Re: [FW-1] static arp entry at 2 diffent SPLAT boxes

2010-08-12 Thread a bv
11, 2010 at 1:32 AM, a bv vbavbal...@gmail.com wrote: Hi, Having a 2 FW-1 SPLAT R70 box and sometimes switching from one to the makes an extra offline time cause of the arp. Cause the internet gateway device (router, modem etc) has the first fws arp entry, not the others one and also the new

[FW-1] Setting/testing the Smartdefense /IPS policy

2010-09-02 Thread a bv
Hi list, I wanna ask how do you set/configure your IPS settings on Checkpoint gateway, and how do you test , see and and improve IPS /the configuration success. Regards Scanned by Check Point Total Security Gateway. = To set vacation,

[FW-1] Log analyzes

2010-09-06 Thread a bv
Hi, You have set a policy on your CP gateway , adding rules etc. Whether you have a dedicated ips/Smartdefense module/IPS blade or not , what do you do how do you do with the firewalls logs addition to connectivity troubleshooting , in the mean of security , intrusion dedection, incident response

[FW-1] your opinions about the software blades

2010-09-27 Thread a bv
Hi list, I would like to ask to the list members what do they think about the R70/R71 software blades, which they find usefull (maybe useless) , which features do they like ,which blades they bought and found use in their enterprise . And also what are these blades negative effect on performance

  1   2   3   >