CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Certifications And Exams > CCSA (Check Point Certified Security Administrator) > CCSA NGX Exam 156-215.1
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #41 (permalink)  
Old 2006-08-30
Junior Member
 
Join Date: 2006-08-14
Posts: 7
Rep Power: 0
Karadin has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Quote:
Originally Posted by firesec View Post
Hey,

This is really a tricky question because in NGX R60 you cannot change the admin password from SmartDashboard. In NGX R61 you can do that. I also put A but the right answer is B !

I disagree with this as i have just tried to override the admin password in r60 and was able to do it so i believe the answer is B
Reply With Quote
  #42 (permalink)  
Old 2006-08-30
Member
 
Join Date: 2006-06-03
Posts: 33
Rep Power: 0
dean7711 has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Hey guys I have just remebered some of a question on the exam that I failed. It mentioned use of the "cron" or "cron utility" I dont know if any of you guys had this question. Can we define what its used for and if anyone remembers the question itself?
Reply With Quote
  #43 (permalink)  
Old 2006-08-30
Junior Member
 
Join Date: 2006-06-23
Posts: 21
Rep Power: 0
firewalz has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

"Cron or crontab is a Unix/GNU Linux task scheduler, it allows you to specify when to run certain cli commands or scripts. The system crontab is usually found in /etc/crontab, to view a particular users crontab use "crontab -u <userid> -l".

As for TK question 101, R61 does have the option as mentioned in B.
Reply With Quote
  #44 (permalink)  
Old 2006-08-30
Junior Member
 
Join Date: 2006-08-21
Posts: 8
Rep Power: 0
prasad has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

QUESTION 101

How can you reset the password of the Security Administrator, which was created during initial installation of the SmartCenter Server on SecurePlatform?

A. Launch cpconfig and select "Administrators".
B. Launch SmartDashboard, click the admin user account, and overwrite the existing
Check Point Password.
C. Type cpm -a, and provide the existing administration account name. Reset the Security
Administrator's password.
D. Export the user database into an ASCII file with fwm dbexport. Open this file with an
editor, and delete the "Password" portion of the file. The log in to the account without
password. You will be prompted to assign a new password.
E. Launch cpconfig and delete the Administrator's account. Recreate the account with the same name.

Answer according to Testking it is B

In windows version I tried to change the admin password which was created initially. We cannot change the password by Smartdashboard as there is no option to change the password the default administrator password created initally at the time of installation.

We need to type cpconfig on the Enforcement module select administrators and then change the password.

Please let me know your comments....

Thanks and Regards,

Bhaskar Prasad
Reply With Quote
  #45 (permalink)  
Old 2006-08-30
Junior Member
 
Join Date: 2006-03-24
Posts: 22
Rep Power: 0
firesec has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Hi guys,

Regarding question 101 I've played with NGX R55, R60 and R61. According to CheckPoint_NGX_R61_WhatsNew.pdf, "Administrators can change their passwords through SmartDashboard", but only Administrators created from SmartDashboard (AdminAuth window). I think this was also possible in R55 but you couldn't do that in NGX R60. You cannot modify the administrator's password created from SecurePlatform->cpconfig. I also didn't understood this question in the beginning. I think after all, the right answer is E because you don't have "Administrators" in cpconfig, you only have "Administrator", and definatelly not B because is specified that the user was created during initial installation of the SmartCenter Server on SecurePlatform.
Reply With Quote
  #46 (permalink)  
Old 2006-08-30
Junior Member
 
Join Date: 2006-08-14
Posts: 7
Rep Power: 0
Karadin has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Ok OK i should really read the question right as it states the "initally". Then prasad is right you have to go into cpconfig
Reply With Quote
  #47 (permalink)  
Old 2006-08-30
Junior Member
 
Join Date: 2006-08-29
Posts: 15
Rep Power: 0
huggins has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Quote:
Originally Posted by firesec View Post
Hi guys,

Regarding question 101 I've played with NGX R55, R60 and R61. According to CheckPoint_NGX_R61_WhatsNew.pdf, "Administrators can change their passwords through SmartDashboard", but only Administrators created from SmartDashboard (AdminAuth window). I think this was also possible in R55 but you couldn't do that in NGX R60. You cannot modify the administrator's password created from SecurePlatform->cpconfig. I also didn't understood this question in the beginning. I think after all, the right answer is E because you don't have "Administrators" in cpconfig, you only have "Administrator", and definatelly not B because is specified that the user was created during initial installation of the SmartCenter Server on SecurePlatform.

Yes, I am also agree your result. It should be E!!!
Reply With Quote
  #48 (permalink)  
Old 2006-08-31
Junior Member
 
Join Date: 2006-03-24
Posts: 22
Rep Power: 0
firesec has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Hi,

I just found the new thing in NGX R61 regarding administrator's password changing. Administrators created from SmartDashboard can change their password from Manage->Change my password.
Reply With Quote
  #49 (permalink)  
Old 2006-08-31
Junior Member
 
Join Date: 2006-03-24
Posts: 22
Rep Power: 0
firesec has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Regarding question 71: I think the right answer is B.

Original Packet Translated Packet
No Source Destination Service Source Destination Service
1 internal_net Any HTTP firewall(hide) Original Original
2 internal_net Any FTP firewall(hide) Original Original
3 internal_net Any SMTP firewall(hide) Original Original

It is specified that the network addresses are translated only when they try to access HTTP,SMTP and FTP.
Reply With Quote
  #50 (permalink)  
Old 2006-08-31
Junior Member
 
Join Date: 2006-08-21
Posts: 8
Rep Power: 0
prasad has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Hi ,

You are correct The Answer to Question No. 71. is B

Manual Hide NAT rules for HTTP, FTP, and SMTP services for network 10.10.20.0/24.

Thanks and Regards,

Bhaskar Prasad
Reply With Quote
  #51 (permalink)  
Old 2006-08-31
Junior Member
 
Join Date: 2006-08-21
Posts: 8
Rep Power: 0
prasad has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Hi FireSEC,

I THINK THE EXAM IS BASED ON R60 AND NOT on R61.

In What's New in NGX: SmartCenter

http://www.checkpoint.com/ngx/upgrad...artcenter.html

Regarding Question Number 101, It should be between A or E. Please let me know

Please let me know your comments

Regards,
Bhaskar Prasad
Reply With Quote
  #52 (permalink)  
Old 2006-08-31
Junior Member
 
Join Date: 2006-03-24
Posts: 22
Rep Power: 0
firesec has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Hey,

Like I said I think the right answer is E.
Reply With Quote
  #53 (permalink)  
Old 2006-08-31
Junior Member
 
Join Date: 2006-03-24
Posts: 22
Rep Power: 0
firesec has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Regarding question no. 77: I think TestKing answer C is is right, because it's specified that Automatic Static NAT it's used, and when you use Automatic NAT you don't have Routing/ARP issues.
Reply With Quote
  #54 (permalink)  
Old 2006-08-31
Junior Member
 
Join Date: 2006-03-24
Posts: 22
Rep Power: 0
firesec has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Hey guys,

What do you think about question 85?
How can you reset Secure Internal Communications (SIC) between SmartCenter and Security Gateway?
A. Run the command fwm sic_reset to reinitialize the Internal Certificate Authority (ICA) of the SmartCenter Server. Then retype the activation key on the Security Gateway from SmartDashboard.
B. From cpconfig on the SmartCenter Server, choose the Secure Internal Communication option and retype the activation key. Next, retpe the same key in the gateway object in SmartDashboard and reinitialize Secure Internal Communications (SIC).
C. From the SmartCenter Server's command line type fw putkey -p <shared key> <IP Address of SmartCenter Server>.
D. From the SmartCenter Server's command line type fw putkey -p <shared key> <IP Address of Security Gateway>.
E. Reinstall the Security Gateway

TestKing answer: B

The problem is that in cpconfig, we don't have any Secure Internal Communication option. This option I think is available in NG R55 version.
The right answer here I think is A.
Reply With Quote
  #55 (permalink)  
Old 2006-08-31
Member
 
Join Date: 2006-08-14
Location: Rio de Janeiro / RJ - Brazil
Posts: 43
Rep Power: 0
leogoesrj has an average reputation (10+)
Send a message via ICQ to leogoesrj Send a message via MSN to leogoesrj Send a message via Skype™ to leogoesrj
Default Re: Don't make the mistake I made with CCSA NGX

Quote:
Originally Posted by firesec View Post
Hey guys,

What do you think about question 85?
How can you reset Secure Internal Communications (SIC) between SmartCenter and Security Gateway?
A. Run the command fwm sic_reset to reinitialize the Internal Certificate Authority (ICA) of the SmartCenter Server. Then retype the activation key on the Security Gateway from SmartDashboard.
B. From cpconfig on the SmartCenter Server, choose the Secure Internal Communication option and retype the activation key. Next, retpe the same key in the gateway object in SmartDashboard and reinitialize Secure Internal Communications (SIC).
C. From the SmartCenter Server's command line type fw putkey -p <shared key> <IP Address of SmartCenter Server>.
D. From the SmartCenter Server's command line type fw putkey -p <shared key> <IP Address of Security Gateway>.
E. Reinstall the Security Gateway

TestKing answer: B

The problem is that in cpconfig, we don't have any Secure Internal Communication option. This option I think is available in NG R55 version.
The right answer here I think is A.
No, it is true that the cpconfig has the SIC option (labeled as Secure Internal Communication), in this option you can reset the SIC. I dont know if this option doesnt appear in the R55, but in R60 i tested this.
Reply With Quote
  #56 (permalink)  
Old 2006-08-31
Junior Member
 
Join Date: 2006-03-24
Posts: 22
Rep Power: 0
firesec has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Are you sure ? I don't have this option, and I've installed NGX R60 and NGX R61.
Reply With Quote
  #57 (permalink)  
Old 2006-08-31
Senior Member
 
Join Date: 2006-06-28
Posts: 140
Rep Power: 3
david has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

you wont have this option if this is a stand-alone install.
only appears in a distributed install.
Reply With Quote
  #58 (permalink)  
Old 2006-08-31
Member
 
Join Date: 2006-08-14
Location: Rio de Janeiro / RJ - Brazil
Posts: 43
Rep Power: 0
leogoesrj has an average reputation (10+)
Send a message via ICQ to leogoesrj Send a message via MSN to leogoesrj Send a message via Skype™ to leogoesrj
Default Re: Don't make the mistake I made with CCSA NGX

Quote:
Originally Posted by firesec View Post
Are you sure ? I don't have this option, and I've installed NGX R60 and NGX R61.
The above answer answered your question.
Reply With Quote
  #59 (permalink)  
Old 2006-08-31
Junior Member
 
Join Date: 2006-03-24
Posts: 22
Rep Power: 0
firesec has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Hey David,

I just saw in NGX R61 documentation that that option is included. And yeah you are right I have the SmartCenter Server and the Security Gateway installed on the same machine, so there is not need for SIC.
Thanks
Reply With Quote
  #60 (permalink)  
Old 2006-09-01
Junior Member
 
Join Date: 2006-03-24
Posts: 22
Rep Power: 0
firesec has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Hi,

If you want to reset SIC between SmartCenter Server and a specific Security Gateway you can do this in two ways:

i. from SmartDashboard: Security Gateway's General Properties->Communication->Reset
ii. from Security Gateway cpconfig: Secure Internal Communication

If you want to reset SIC on all CheckPoint Components you have to run fwm sic_reset on the SmartCenter Server and after this:
i. Re-initialize the internal Certificate Authority from cpconfig->Certificate Authority
ii. Restart CheckPoint Services (cpstart, cpridstart)
iii. Reset SIC on each specific component managed by the SmartCenter Server
iv. Re-establish Trust with each component

So, regarding that testking question, you can't run cpconfig->Secure Internal Communication on the SmartCenter Server. Also if you do like A. says, I think you also have to reset Secure Internal Communication from cpconfig. So ..I don't know which of this answers are more wrong. :)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:34.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0