[FW1] Loveletter virus was here, but fw-1 mailing list stopped it

2000-10-20 Thread THELLIER, Francis (Kedros)
We received the virus loveletter by mail several days ago, but hopefully, the checkpoint server removed it from the mail, see below ... http://www.tlanews.com/TLA/NEWS/2000sec/20001020LoveLetter.htm Francis THELLIER

[FW1] test

2000-10-19 Thread THELLIER, Francis (Kedros)
please ignore this message.sorry. To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html

RE: [FW1] Web Hosting

2000-09-26 Thread THELLIER, Francis (Kedros)
www.hotyellow98.com easy, simple, fast. Francis THELLIER -Message d'origine- De: Mike Glassman - Admin [SMTP:[EMAIL PROTECTED]] Date: mardi 26 septembre 2000 10:23 À:'fw-1 listserv' Objet:RE: [FW1] Web Hosting There is also ATT, Internet Gold to name a few

RE: [FW1] Email Content Filtering/URL Filtering

2000-09-20 Thread THELLIER, Francis (Kedros)
Hello, about the bandwith control, use PacketShaper rather than Floodgate. I'm not impressed at all by Floodgate, and I've already been heard by people who tried both than PacketShaped is better Francis THELLIER -Message d'origine- De: [EMAIL PROTECTED] [SMTP:[EMAIL

RE: [FW1] Adding a new license

2000-09-11 Thread THELLIER, Francis (Kedros)
Hello yes, you can add the license without removing the old one. There is no problem to have multiple license on the Firewall ! If you want you can delete the old one later, or maybe keep it forever ! Francis THELLIER 9 TELECOM - DSI.P.SS Administrateur sécurité Tél. +33

RE: [FW1] Best Practices for managing a firewalls

2000-08-18 Thread THELLIER, Francis (Kedros)
What a mistake ! :o) No, I'm serious, the two best search engines are www.altavista.com and www.google.com try again ! Francis THELLIER -Message d'origine- De: Ivan Fox [SMTP:[EMAIL PROTECTED]] Date: vendredi 18 août 2000 16:04 À:fw1-wizards; Firewall-1 Objet:

RE: [FW1] Ip forwarding On Firewall

2000-08-17 Thread THELLIER, Francis (Kedros)
Leave IP forwarding off, int his configuration, all the trafic will be blocked during the reboot of the Firewall. Francis THELLIER -Message d'origine- De: benjamin.c [SMTP:[EMAIL PROTECTED]] Date: mercredi 16 août 2000 17:03 À:[EMAIL PROTECTED] Objet:[FW1] Ip

RE: [FW1] fw logswitch

2000-08-10 Thread THELLIER, Francis (Kedros)
Hello, you can put a cron to do something like that : at 23:59 /every:m,t,w,th,f,s,su c:\winnt\fw\bin\fw logswitch to switch the logs every day I hope this help Francis THELLIER -Message d'origine- De: Johnson, Dave [SMTP:[EMAIL PROTECTED]] Date: mercredi 9 août 2000 21:17

RE: [FW1] Removing several field with a SMTP ressource

2000-08-10 Thread THELLIER, Francis (Kedros)
Hello, you can specify, in the action Tab1 of your smtp resource, all the fields that you want to filter, In fact, you can put in the field : "field" {Received,From} "Contents" {*,*} --- {whatyouwant,[EMAIL PROTECTED]} Obviously, it is just an example I hope this help ! Francis THELLIER

RE: [FW1] problems again with installing policys

2000-08-04 Thread THELLIER, Francis (Kedros)
Hello Just a suggestion : Did you define your Firewall as an object ? You must set it to a "Firewall Gateway" The security Policies need at least one Firewall gateway to install the rules Francis THELLIER -Message d'origine- De: Ben Cuthbert [SMTP:[EMAIL PROTECTED]] Date:

RE: [FW1] SMTP - Mail size filter

2000-08-02 Thread THELLIER, Francis (Kedros)
Hello, try to put zero, otherwise I found this on Phoneboy site : You should be able to type a number into this field. "99" seems to work for some people. Blank works for others. In older versions of FireWall-1, you could set this to zero and it would have the same effect. Another way to

[FW1] FW1 Vulnerabilities

2000-07-31 Thread THELLIER, Francis (Kedros)
Hello, did you know this ? http://www.TLAnews.com/TLA/NEWS/2000sec/2731CheckpointTUV.htm Go to check if you want Francis THELLIER To unsubscribe from this mailing list, please see the instructions

RE: [FW1] ICQ

2000-07-12 Thread THELLIER, Francis (Kedros)
Hello I think you can block ports 6667 to 6669 But why don't you use the policy : "All is blocked by default, and I open all that I really need" ? Francis THELLIER -Message d'origine- De: Dwayne Mowers [SMTP:[EMAIL PROTECTED]] Date: mercredi 12 juillet 2000 16:24 À:

RE: [FW1] securemote

2000-07-10 Thread THELLIER, Francis (Kedros)
Yes, me It worked very well, Francis THELLIER -Message d'origine- De: Michael Tench [SMTP:[EMAIL PROTECTED]] Date: lundi 10 juillet 2000 13:46 À:[EMAIL PROTECTED] Objet:[FW1] securemote Has anyone on this list successfully used certificates for their

[FW1] RE:

2000-07-07 Thread THELLIER, Francis (Kedros)
Hello I think you have to specify all the header fields in action tab in your smtp resource There are received, from, Message-ID, what else ?? euh, maybe : (From: To: Date: Mime-Version: Content-Type: Sender: ) ? I don't really know, Those I'm sure are : received, from, Message-ID You can

[FW1] InterScan problem

2000-07-07 Thread THELLIER, Francis (Kedros)
Hello, I've tried to contact the Trendmicro support, I'm waiting for a respons Could you help me ? My problem is : When I try to update pattern virus I have the error message : ERROR: Other process is updating pattern file. What can I do ? I've already tried to stop and restart the service,

TR: [FW1] FW has disconnected GUI-Client !!! HELP !!

2000-07-07 Thread THELLIER, Francis (Kedros)
Francis THELLIER 9 TELECOM - DSI.P.SS Administrateur sécurité Tél. +33 1.55.20.13.84 E-mail [EMAIL PROTECTED] -Message d'origine- De: THELLIER, Francis (Kedros) Date: vendredi 7 juillet 2000 12:16 À:'Ralf Stracke' Objet:RE: [FW1] FW

RE: [FW1] primary IP-address

2000-07-06 Thread THELLIER, Francis (Kedros)
I'm not an expert, but I already had some troubles because I had chosen the internal interface, I've changed this to the external, and all was going better ! Francis THELLIER -Message d'origine- De: Uy, Alex [SMTP:[EMAIL PROTECTED]] Date: jeudi 6 juillet 2000 14:52 À:

RE: [FW1] groups

2000-06-30 Thread THELLIER, Francis (Kedros)
One another solution is to use an authentification on the Firewall. You can create an account on the Firewall (one user and the corresponding password), then you give to the authorized users the login/pass they connect to http://internal_or_external_Firewall_Interface:900 or telnet to

RE: [FW1] Stateful inspection of icmp

2000-06-29 Thread THELLIER, Francis (Kedros)
Yes, it should work with (2) and (3), but why enable ICMP from properties if you use rules ? Francis THELLIER -Message d'origine- De: D H [SMTP:[EMAIL PROTECTED]] Date: mercredi 28 juin 2000 19:01 À:[EMAIL PROTECTED] Objet:[FW1] Stateful inspection of icmp I

RE: [FW1] Studying for Checkpoint Exams

2000-06-29 Thread THELLIER, Francis (Kedros)
Eh eh, What about trying to anwsers to questions in this mailing-list ??? I really think this is the best training, don't you think ? Otherwise I don't know if there are some training exams on Internet. Read every FAQ on the Net Francis THELLIER 9 TELECOM - DSI.P.SS Administrateur

RE: [FW1] Stateful inspection of icmp

2000-06-29 Thread THELLIER, Francis (Kedros)
One of the problem to accept ICMP from properties (and not in rules) is that you won't log it ! I prefere to log all my traffic, so I've put rules (echo-request/echo-reply) for allowing ICMP Francis THELLIER -Message d'origine- De: [EMAIL PROTECTED] [SMTP:[EMAIL PROTECTED]]

[FW1] InterScan serial number

2000-06-27 Thread THELLIER, Francis (Kedros)
Hello everyone ! I would like to know where I can find the serial number on the InterScan machine ? Anyone has an idea ? I've looked in the intscan.ini file, but no sucess ... Thanks in advance, Francis THELLIER

RE: [FW1] SMTP per user

2000-06-23 Thread THELLIER, Francis (Kedros)
I don't really know what you want to do, but you can limit the number of recipients when a user send a email is it your question ? So, for this you go in the $FWDIR\conf and edit the smtp.conf file the max_recipients field is at 50 per default I think Francis THELLIER -Message

RE: [FW1] Time delay's

2000-06-20 Thread THELLIER, Francis (Kedros)
Of course, use the time field in your rule base ! and the rule will be enabled only the days or hours specified Francis THELLIER Hello everyone, Is there any way of expiring a rule at a certain time for Checkpoint FW v4.0? E.g. What if I wated to disable rule 30 after 5pm today. Is

RE: [FW1] Archive of this mailing list (again) sorry

2000-06-15 Thread THELLIER, Francis (Kedros)
Check For exemple : http://search.securepoint.com/frame2.html or http://www.shmoo.com/mail/fw1/ or FAQ, docs : http://www.phoneboy.com/fw1/ http://www.enteract.com/~lspitz/pubs.html http://www.dreamwvr.com/bastions/fw1gq01.html Francis THELLIER -Message d'origine- De:

[FW1] Translation problem ...

2000-06-13 Thread THELLIER, Francis (Kedros)
Hello, This problem is an emergency A-translated1 is différent of A-translated2 A is internal, B et C are external Rules in Security Policy : source destination B ---A-translated1 A ---C C

[FW1] NAT problem ... please help !

2000-06-13 Thread THELLIER, Francis (Kedros)
Hello, This problem is an emergency A-translated1 is différent of A-translated2 A is internal, B et C are external Rules in Security Policy : sourcedestination B ---A-translated1 A ---C

RE: [FW1] read only problem on policy, please help

2000-05-30 Thread THELLIER, Francis (Kedros)
Hello, did you try to go in $CKPFW dir and find a lock file or something like that ? If this is the problem, delete this file, and you'll be able to log. Francis THELLIER 9 TELECOM - DSI.P.SS Administrateur sécurité Tél. +33 1.55.20.13.84 E-mail [EMAIL PROTECTED]

[FW1] Securemote and NAT problem

2000-05-18 Thread THELLIER, Francis (Kedros)
Hello, I have Securemote 4.1 on a private address and Fw-1 4.0 behind. I try to pass trough the Firewall but it doesn't work. I can't do VPN like this, I use static NAT, and I 've made changes in objects.C like it is explained on Phoneboy site to use HIDE NAT. But even with static NAT it