Re: WARNING - R61 HFA 1 We were really lucky here as we have a number of client firewalls on R61. Reallised taht we also were on the same so did us first. The most obvious problem was that R61 Tracker kept collapsing on the management machine. Then we found that IPSEC VPNs to Cisco kit appeared to be up, but was in classic "Half Duplex Mode". From the remote sites; behind Cisco kit, we couldn't ping or anything else to the HQ; behind Checkpoint R61.1 From the HQ site we could ping and RDP to remote kit...but not do anything back ????????????????? Also loads of connectivity permited by the rulesbase was being ignore and dropped by the general clean up rules. Repeated reinstallation of the policy changed what was ignored. B0LX..R62 is good and its easy to migrate to, so do so. Dumped the whole thing and upgrdaed to R62 from CD and evrythings fine |