CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point VPN-1 Edge Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-11-19
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 268
Rep Power: 2
dantro has an average reputation (10+)
Default Firmware 8.0.35 released

SofaWare has just released a new major firmware version 8.0.35 to the general public.

Make sure to read the Embedded_NGX_8_GA_ReleaseNotes.pdf (General Availability Version) carefully for all the new features and resolved issues.
Check Point recommends to update to this firmware version asap.

Embedded NGX 8.0 incorporates a lot of new and improved features, including:

- VStream Antispam
- Firewall Monitor
- Enhanced Policy Editors
- Built-in 802.1x and WPA Authenticator
- Built-in RS-232 Terminal Server
- Built-in DNS Server
- BGP Dynamic Routing
- Enhanced SNMP MIB
- New Status Dashboard
Reply With Quote
  #2 (permalink)  
Old 2008-11-19
Senior Member
 
Join Date: 2007-06-05
Location: Canada
Posts: 203
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: Firmware 8.0.35 released

Dantro,
I also got this from one of my contacts...however, have you seen a download link to the GA version yet?
Reply With Quote
  #3 (permalink)  
Old 2008-11-19
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 268
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Firmware 8.0.35 released

You can grab it directly from Check Point.
Firmware Version 8.0.35x
Firmware Version 8.0.35a for ADSL
8.0.35 libsw for Linux and Solaris
8.0.35 libsw for Windows
Reply With Quote
  #4 (permalink)  
Old 2008-11-19
Senior Member
 
Join Date: 2007-06-05
Location: Canada
Posts: 203
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: Firmware 8.0.35 released

Ah, the files are filed under Safe@Office and not UTM1-Edge devices..that's why I couldn't find them...

I imagine its the same firmware?

Last edited by hotice_; 2008-11-19 at 15:03.
Reply With Quote
  #5 (permalink)  
Old 2008-11-19
Senior Member
 
Join Date: 2007-07-16
Posts: 687
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Firmware 8.0.35 released

Finally! Thanks for the update dantro!
Reply With Quote
  #6 (permalink)  
Old 2008-11-19
Senior Member
 
Join Date: 2006-01-25
Posts: 1,004
Rep Power: 4
melipla has an average reputation (10+)
Default Re: Firmware 8.0.35 released

Quote:
Originally Posted by hotice_ View Post
I imagine its the same firmware?
Yes, sofaware makes the Edge devices & releases the firmware for them.
__________________
Its all in the documentation.
Reply With Quote
  #7 (permalink)  
Old 2008-11-20
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 268
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Firmware 8.0.35 released

ATTENTIONE !!

There is a slight issue I encountered on nearly every UTM-1 Edge that was updated to 8.0.35. The DMZ port assignment was lost. This causes address spoofings in the security log as requests from the DMZ network appear on your UTM-1 Edge appliance but it doesn't expect them on its DMZ interface.

Always check the Port assignments under Network > Ports after an update to this firmware!
Reply With Quote
  #8 (permalink)  
Old 2008-11-21
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 293
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Firmware 8.0.35 released

2 more issues to report: (My best friend sells safe@office for small businesses)

Since the firmware is identical for Edge an Safe@Office, I thought these may apply equally.

1) Automatic Update = bad - he had 2 customers that got the firmware update in mid-afternoon and it rebooted. He THOUGHT he only had anti-virus updates turned on.

Why would CP do mid-afternoon automatic upgrades? You would think they would program something to do Midnight in the local time zone or something if a reboot is required...


2) Anti-SPAM. Even though this was set to disabled and the screen with the scanning rules says something along the lines of "Anti-SPAM is disabled and these rules do not apply". I had to disable the default SMTP scanning rule because it stopped SMTP connections following the firmware upgrade.

Very reminiscent of SmartDefense dropping packets when in Monitor Only mode in FW-1. When he called me to ask for help troubleshooting, this was my first thought and sure enough, as soon as I disabled the rule, I was able to telnet to port 25.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #9 (permalink)  
Old 2008-11-28
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 308
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: Firmware 8.0.35 released

One more major problem found, we run a lot of older Nokia IP40's which run fine with libsw up to version 7.5.55 however with the 8.0.35 libsw we had been locked out completely from these boxes, the only thing still allowed was the Smartcenter connection.
__________________
Regards, Maarten.
P1 R62 IPSO SPLAT IOS
Reply With Quote
  #10 (permalink)  
Old 2008-11-28
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 268
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Firmware 8.0.35 released

Just go to Services > Connect and uncheck the Service Center connection. Next > Next > Finish. Connect the IP40 to the Service Center again and everything should be fine. You should have an IP or network configured under Setup > Management for such emergency cases.

Update: The above steps can also done by a small script configured centrally on your SmartCenter Server or via remote scripting.

Last edited by dantro; 2008-11-28 at 07:41.
Reply With Quote
  #11 (permalink)  
Old 2008-11-28
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 308
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: Firmware 8.0.35 released

Dantro, I don't see this as a solution for the 50+ IP4x's we have devided over 20 CMA's.
LIBSW is not supposed to lock us out and when I go back to 7.5.55 LIBSW the problem is gone.
We HAVE the network access limited on the Management HTTPS and SSH page.
These boxes are all around the world and although I don't mind going to almost all of theses countries, however Mumbai is not on my wishlist this week
__________________
Regards, Maarten.
P1 R62 IPSO SPLAT IOS

Last edited by msjouw; 2008-11-28 at 06:28.
Reply With Quote
  #12 (permalink)  
Old 2008-11-28
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 268
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Firmware 8.0.35 released

See update posted above. This is an old issue/behaviour I encountered with older versions as well. Maybe it's by design of the product.

Get some hands-on training and blaim Nokia, not me.
Reply With Quote
  #13 (permalink)  
Old 2 Weeks Ago
Junior Member
 
Join Date: 2008-11-27
Posts: 10
Rep Power: 0
geetarman has an average reputation (10+)
Default Re: Firmware 8.0.35 released

anyone else having issues with libsw upgrade leading to odd errors?
This is SmartCenter R65 HFA30 on SPLAT.

I went from 8019 (incl in HFA30 I guess) to 8.0.35
Edge is running 8.0.35 fine.

Now when I try to push policy I get this error:

"Advanced Security VPN-1 UTM Edge/Embedded Gateway cpp: line 547, Fatal error: Cannot open include file "fwui_head.def" Advanced Security VPN-1 UTM Edge/Embedded Gateway cpp: line 547, Fatal error: Cannot open include file "fwui_head.def":

Funny thing is the file is there, looks fine too. Why is cpp choking?

I did cpstop/cpstart.. no change.

I chmoded all files to root:root to see if that would help (they came out of tar with numeric user & group ID's..) and root has read on this file as you can see:

[Expert@myfirewall]# whoami
root
[Expert@myfirewall]# head fwui_head.def
#define __WIN32
#ifndef __fwui_head__
#define __fwui_head__

//
// (c) Copyright 1993-2000 Check Point Software Technologies Ltd.
// All rights reserved.
//
// This is proprietary information of Check Point Software Technologies
// Ltd., which is provided for informational purposes only and for use
[Expert@PALCPMSRV01]#

any thoughts? Did not see any sk's which related. Checked sofaware boards too.

Thx
Reply With Quote
  #14 (permalink)  
Old 2 Weeks Ago
Junior Member
 
Join Date: 2008-03-06
Posts: 6
Rep Power: 0
cpgoof has an average reputation (10+)
Default Re: Firmware 8.0.35 released

Doesn't seem to work on an X-series Industrial...
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:26.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0