CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Certifications And Exams > CCSA (Check Point Certified Security Administrator) > CCSA NGX Exam 156-215.1
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #81 (permalink)  
Old 2006-09-25
Junior Member
 
Join Date: 2006-09-22
Location: India
Posts: 4
Rep Power: 0
ratanjai has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

Hi Pulkit...
i m going to appear in the CCSA soon..did u get some dump or study material?
if you have kindly share it with me please

Thanks.
Reply With Quote
  #82 (permalink)  
Old 2006-10-08
Junior Member
 
Join Date: 2006-06-15
Posts: 15
Rep Power: 0
cqliuke has an average reputation (10+)
Default Re: Don't make the mistake I made with CCSA NGX

B. Host-based port scan is enabled, because SmartDefense settings are global.
Reply With Quote
  #83 (permalink)  
Old 2008-08-14
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 307
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: Don't Make The Mistake I Made With CCSA NGX

Another one that is a bit crappy:
QUESTION 85
How can you reset Secure Internal Communications (SIC) between a SmartCenter
and Security Gateway?
A. Run the command fwm sic_reset to reinitialize the Internal Certificate Authority
(ICA) of the SmartCenter Server. Then retype the activation key on the Security Gateway
from SmartDashboard.
B. From cpconfig on the SmartCenter Server, choose the Secure Internal Communication
option and retype the activation key. Next, retype the same key in the gateway object in
SmartDashboard and reinitialize Secure Internal Communications (SIC).
C. From the SmartCenter Server's command line type fw putkey -p <shared key> <IP
Address of SmartCenter Server>.
D. From the SmartCenter Server's command line type fw putkey -p <shared key> <IP
Address of Security Gateway>.
E. Reinstall the Security Gateway.

Answer: B
Which would be correct if it would read "From cpconfig on the Security Gateway"
Explanation:
And this:
Note: The B option (Secure Internal Communication) is available in NG R55. We don't have something like this in NGX R60 or NGX R61.

I thought only in a non distributed setup this would NOT be there.

Regards, Maarten
Reply With Quote
  #84 (permalink)  
Old 2008-10-01
Junior Member
 
Join Date: 2008-02-02
Posts: 5
Rep Power: 0
maxfactor has an average reputation (10+)
Default Re: Dont make the mistake I made with CCSA NGX

Quote:
Originally Posted by david View Post
this is just my understanding, may be wrong ;-)

if you clear/untick "Translate destination on client side" the nat will be performed on the internal interface of your firewall, rather than the external interface.

if this is the case the packet will not get to the firewalls internal interface as the routing on the firewall would send packets bound for public IP to the external interface. so you need to add a static to point the nat rules public ip to the internal interface of the firewall so that the nat can be performed.
Please, I agree... but can you give me a practical example with real ip addresses ?? PLease... I miss something to understand well...
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:35.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0