CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Internal Security > Endpoint Security (Formerly Integrity)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-04
Junior Member
 
Join Date: 2007-10-03
Posts: 2
Rep Power: 0
zoo-loo has an average reputation (10+)
Default HFA06 for 6.5?

Anyone know when HFA06 is actually going to be released? Seems like it keeps getting delayed....
Reply With Quote
  #2 (permalink)  
Old 2007-10-05
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 291
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: HFA06 for 6.5?

???

Do you mean HFA_01 for R65? If so, it will be released very soon.

If you mean HFA_06 for R60, well... HFA_05 isn't that old, so I wouldn't expect a new one anytime soon.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #3 (permalink)  
Old 2007-10-05
Junior Member
 
Join Date: 2007-05-11
Location: Bristol, UK
Posts: 19
Rep Power: 0
unclerichard has an average reputation (10+)
Default Re: HFA06 for 6.5?

We are waiting for an imminent release of (presumably) HFA-06 for Integrity Client 6.5 due to issues with release 166 and CA Antivirus. The latest date that I had from Tech Supp. was 12th October.

Unc
Reply With Quote
  #4 (permalink)  
Old 2007-10-05
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 291
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: HFA06 for 6.5?

Ahhh... Ambiguity will be the death of us all. Thanks for the clarification.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #5 (permalink)  
Old 2007-10-30
Senior Member
 
Join Date: 2007-06-22
Posts: 108
Rep Power: 2
CSING has an average reputation (10+)
Default Re: HFA06 for 6.5?

HFA06 is still more than 2 weeks away.
Reply With Quote
  #6 (permalink)  
Old 2007-11-09
Junior Member
 
Join Date: 2006-08-23
Location: Europe
Posts: 18
Rep Power: 0
dingo8mybaby has an average reputation (10+)
Send a message via ICQ to dingo8mybaby
Default Re: HFA06 for 6.5?

Was told 16th Nov - don't know if that is a general release date though.
Reply With Quote
  #7 (permalink)  
Old 2007-11-09
Senior Member
 
Join Date: 2007-06-22
Posts: 108
Rep Power: 2
CSING has an average reputation (10+)
Default Re: HFA06 for 6.5?

There is already a one-off client build 195 that is availible for special cases. It is possible that a Nov 14 date for HFA06 will be met.
Reply With Quote
  #8 (permalink)  
Old 2007-11-15
Senior Member
 
Join Date: 2007-06-22
Posts: 108
Rep Power: 2
CSING has an average reputation (10+)
Default Re: HFA06 for 6.5?

You were correct!

HFA6 is now available on the Check Point Download Center. Release notes are also on the Download Center.

Note:

The wireless feature still has the same limitation in HFA6 as in all versions before: It will NOT work on machines with a static IP address. This will be fixed in HFA7.
Reply With Quote
  #9 (permalink)  
Old 2007-12-02
Junior Member
 
Join Date: 2007-12-01
Posts: 13
Rep Power: 0
securitydude has an average reputation (10+)
Default Re: HFA06 for 6.5?

How is 6.5 HFA06 working for everyone so far? Any issues?
Reply With Quote
  #10 (permalink)  
Old 2007-12-03
Senior Member
 
Join Date: 2007-06-22
Posts: 108
Rep Power: 2
CSING has an average reputation (10+)
Default Re: HFA06 for 6.5?

Are you more concerned about the client or server? I haven't heard of any negative feedback on HFA06. There are a number of issues that this fix corrected. Here are notiable fixes from the RN.

Integrity Client Issues Fixed:

§ Added: Password persistence

Description:
Client rules database corruption could cause the installation password to be lost. In HFA-6 this problem has been resolved. User and install passwords are now backed up (hash value) and read back in automatically.


§ Added: Global Reset-to-Default Feature:
Description:
This new feature adds a tray menu item and supporting code to handle the new Global Reset-to-Default Feature. Ctrl-Shift Right Click on the tray icon enables a newly added item, "Reset" to the right click menu. Clicking “Reset” prompts the user to proceed with reset; if they do then it resets all of the policies in the client. When the client is restarted, the personal policy is re-created and the connection.xml file is read in so that the connection to the integrity server is re-established. Also the installation password is read back in and active.


§ Added the ability to detect WWAN adapters and to disable WWAN adapters the same way that we disable WLAN adapters. This means that if "Disable Wireless On LAN" property is set in the policy both types of adapters should be disabled.


§ Added support of setting dump flags (8, 10 or 14)in the Set Debug Level dialog, which is invoked by Shift+Ctrl+Right Click on the systray menu.

§ Detect VPN Adapter as virtual adapter rather than LAN connections. This fixes the issue of mistakenly disconnecting the Wireless adapters when connecting through wireless to a VPN gateway with "Disable Wireless on LAN" setting because VPN adapter would detected as LAN.


§ Fixed: VSDATANT Multiple IOCTL Privilege Escalation Vulnerabilities (iDefense reported 8/20/2007)

§ Fixed: Multiple Products Privilege Escalation Vulnerability (iDefense reported 8/20/2007)

§ Fixed: Matousec exploit: insufficient checking on ioctl parameter


Integrity Server Issues Fixed:

§ Duplicate deployed policies were not getting purged at all, and now all older versions of current deployed policies are purged.

§ Added MS-SQL Server 2005 to list of supported db

§ Endpoints were not getting deleted from EMON_{domain} table and therefore endpoints even older than 4 weeks were showing up in reports.

§ Policy data retrieved from db is now cached, greatly improving performance.


§ Made synchronization of cluster members robust by getting rid of unreliable JGroups messaging and enforcing periodic uploading of each member cache from common database. This period is configurable by the admin, and is part of the system properties which can be dynamically changed from the tech support page


§ When server gets spyware DAT and engine updates, they are also cached, improving performance and reliability.
Reply With Quote
  #11 (permalink)  
Old 2007-12-10
Junior Member
 
Join Date: 2007-05-11
Location: Bristol, UK
Posts: 19
Rep Power: 0
unclerichard has an average reputation (10+)
Default Re: HFA06 for 6.5?

Just one point relating to the patching itself. Ensure that the Apache logs are not excessive in size as a complete backup of the Integrity directory is made. We noticed that the patching was taking ages - the cause of which being an 8Gb log file !!!

No problems with either the client or server software so far and that 'Reset' facility is a peach !!

Unc
Reply With Quote
  #12 (permalink)  
Old 2007-12-26
Junior Member
 
Join Date: 2007-12-18
Posts: 15
Rep Power: 0
mrjoshua has an average reputation (10+)
Default Re: HFA06 for 6.5?

I am running Integrity Advanced Server 6.5 HFA05 and Integrity Agent 6.5 HFA05. If I update to HFA06 agent will I need to update the server as well?

I am currently having issues with things like Outlook, VPN, and Drive Mapping not working properly on random clients until the Integrity client is stopped, followed immediately by a system reboot. I want to change out the client with the new version but the server is so stable I do not want to change it out at the same time.
Reply With Quote
  #13 (permalink)  
Old 2007-12-28
Senior Member
 
Join Date: 2007-06-22
Posts: 108
Rep Power: 2
CSING has an average reputation (10+)
Default Re: HFA06 for 6.5?

You may update the client to build 199 (HFA06) without upgrading the server. If you are using cisco vpn then I would think about upgarding the server also.

I always hear about issues with Outlook and Drive Mapping (Netbios) Have you checked the zalog and fwpktlog and fwdbglog in the windows/internet logs directory of the affected endpoints to see if the block is logged? Also ensure that 127 is in the trusted zone.

HTH
Reply With Quote
  #14 (permalink)  
Old 2007-12-28
Junior Member
 
Join Date: 2007-12-18
Posts: 15
Rep Power: 0
mrjoshua has an average reputation (10+)
Default Re: HFA06 for 6.5?

Thank you for the information I will double check the machine settings and upgrade the client version and see how it goes with the server running HFA05.
Reply With Quote
  #15 (permalink)  
Old 2008-01-07
Junior Member
 
Join Date: 2007-12-01
Posts: 13
Rep Power: 0
securitydude has an average reputation (10+)
Default Re: HFA06 for 6.5?

Quote:
Originally Posted by CSING View Post
You may update the client to build 199 (HFA06) without upgrading the server. If you are using cisco vpn then I would think about upgarding the server also.

I always hear about issues with Outlook and Drive Mapping (Netbios) Have you checked the zalog and fwpktlog and fwdbglog in the windows/internet logs directory of the affected endpoints to see if the block is logged? Also ensure that 127 is in the trusted zone.

HTH
Why do you recommend upgrading the server if you are using Cisco VPN?
Reply With Quote
  #16 (permalink)  
Old 2008-01-07
Junior Member
 
Join Date: 2007-12-01
Posts: 13
Rep Power: 0
securitydude has an average reputation (10+)
Default Re: HFA06 for 6.5?

Quote:
Originally Posted by unclerichard View Post
Just one point relating to the patching itself. Ensure that the Apache logs are not excessive in size as a complete backup of the Integrity directory is made. We noticed that the patching was taking ages - the cause of which being an 8Gb log file !!!

No problems with either the client or server software so far and that 'Reset' facility is a peach !!

Unc
what is the "reset" facility?

thanks
Reply With Quote
  #17 (permalink)  
Old 2008-01-08
Senior Member
 
Join Date: 2007-06-22
Posts: 108
Rep Power: 2
CSING has an average reputation (10+)
Default Re: HFA06 for 6.5?

Checked the notes and I was incorrect. The correction for the Cisco VPN was made in the client and not the server. A bug was introduced in HFA05 whereby if you connect a second time to the Cisco concentrator, the client sends a heartbeat with a session ID from the first connection, so the Integrity server never authorizes the session to the VPN concentrator. This has been fixed in HFA6.
Reply With Quote
  #18 (permalink)  
Old 2008-01-08
Senior Member
 
Join Date: 2007-06-22
Posts: 108
Rep Power: 2
CSING has an average reputation (10+)
Default Re: HFA06 for 6.5?

Quote:
Originally Posted by securitydude View Post
what is the "reset" facility?

thanks
CNTL+Shift right click Integrity icon. Hidden menu appears with log setting and reset options
Reply With Quote
  #19 (permalink)  
Old 2008-01-19
Junior Member
 
Join Date: 2007-12-01
Posts: 13
Rep Power: 0
securitydude has an average reputation (10+)
Default Re: HFA06 for 6.5?

Quote:
Originally Posted by CSING View Post
CNTL+Shift right click Integrity icon. Hidden menu appears with log setting and reset options
What does the "reset" option actually do?

Thanks,
Reply With Quote
  #20 (permalink)  
Old 2008-01-22
Senior Member
 
Join Date: 2007-06-22
Posts: 108
Rep Power: 2
CSING has an average reputation (10+)
Default Re: HFA06 for 6.5?

This new feature adds a tray menu item and supporting code to handle the new Global Reset-to-Default Feature.

Ctrl-Shift Right Click on the tray icon enables a newly added item, "Reset" to the right click menu. Clicking “Reset” prompts the user to proceed with reset; if they do then it resets all of the policies in the client. When the client is restarted, the personal policy is re-created and the connection.xml file is read in so that the connection to the integrity server is re-established. Also the installation password is read back in and active.

-cs
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 06:46.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0