Re: on splat cpstop and ip forwarding disabled Not sure if this is such a dumb question. Executing cpstop or cpstop FW1 will always disable ip forwarding, but on SPLAT, I suppose the answer might be provided by knowing which config file to edit - i.e. a bit of linux & check point knowledge. Then you'd have to go into expert mode to execute the changes. However the easiest way I can think of achieving the same goal on SPLAT is to leave the firewall daemon running and install a simple one-rule policy where everything can access everything (the reverse of the cleanup rule). Anyone else care to comment? |