CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > IPv6
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-11-02
tgbayly tgbayly is offline
Junior Member
 
Join Date: 2005-11-02
Posts: 3
Rep Power: 0
tgbayly has an average reputation (10+)
Default Enabling IPv6

We are having trouble enabling IPv6 on our firewalls. A valid IPv6 license is installed on our SmartCenter server and the correct associations are made. When we attempt to create an IPv6 object on the dashboard the option is not there. Any suggestions?
Reply With Quote
  #2 (permalink)  
Old 2005-12-09
tgbayly tgbayly is offline
Junior Member
 
Join Date: 2005-11-02
Posts: 3
Rep Power: 0
tgbayly has an average reputation (10+)
Default Re: Enabling IPv6

Ok. I got IPv6 objects configured on the SmartCenter. And have v6 traffic throughput.

But, I noticed that IPv6 traffic passes when the only rule configured on the firewall is 'source any destination any deny'. If I specify that a v6 object (host or network) cannot pass then it is blocked. What is the IPv6 'any' object?
Reply With Quote
  #3 (permalink)  
Old 2006-01-12
elblindo elblindo is offline
Junior Member
 
Join Date: 2006-01-12
Posts: 5
Rep Power: 0
elblindo has an average reputation (10+)
Default Re: Enabling IPv6

[quote=tgbayly]Ok. I got IPv6 objects configured on the SmartCenter. And have v6 traffic throughput.

Could you give a hint how you are able to configure IPv6 objects?

regards

elblindo
Reply With Quote
  #4 (permalink)  
Old 2006-01-12
tgbayly tgbayly is offline
Junior Member
 
Join Date: 2005-11-02
Posts: 3
Rep Power: 0
tgbayly has an average reputation (10+)
Default Re: Enabling IPv6

I have a pdf I found off the web that is too big to attach here. Give me your email address and I'll send it to you.

Cheers,
Tom
Reply With Quote
  #5 (permalink)  
Old 2006-03-14
inserm-dsi inserm-dsi is offline
Junior Member
 
Join Date: 2006-03-14
Posts: 2
Rep Power: 0
inserm-dsi has an average reputation (10+)
Default Re: Enabling IPv6

Hello,
I installed Checkpoint Express NGX on Sparc Solaris 9/05 and I do not manage to visualize objects IPV6 in SmartDashboard.

- the system functions perfectly in IPV4 and IPV6 before the installation of Checkpoint
- I have a licence IPV6 on SmartCenter
- Checkpoint functions correctly in IPV4.

Traffic IPV6 is thus blocked.

Y has to you it an easy way to validate IPV6 correctly.

Cordially
Reply With Quote
  #6 (permalink)  
Old 2006-08-13
gt2847c gt2847c is offline
Junior Member
 
Join Date: 2006-07-13
Location: Georgia, US
Posts: 12
Rep Power: 0
gt2847c has an average reputation (10+)
Send a message via ICQ to gt2847c Send a message via AIM to gt2847c Send a message via Yahoo to gt2847c
Default Re: Enabling IPv6

I have R61 installed and the IPv6 config done up and have the objects, etc. I've got IPSO 4.1 running on an IP440 system. The 440 had v6/v4 both running fine before installing a policy on the box, with a policy no v6 similar to the previous poster. What I've noticed, but haven't figured out yet is how to get Neighbor discovery to work properly. If I go into my Cisco 3640 router, I can't get a ND entry for the firewall when a policy is installed on it. RIPNG is running on the 440 and sends out advertisements ok, but doesn't receive anything back. I've tried a few rules in the firewall to permit things, but no luck so far. If I find the trick for it, I'll post back here.
Reply With Quote
  #7 (permalink)  
Old 2006-08-13
gt2847c gt2847c is offline
Junior Member
 
Join Date: 2006-07-13
Location: Georgia, US
Posts: 12
Rep Power: 0
gt2847c has an average reputation (10+)
Send a message via ICQ to gt2847c Send a message via AIM to gt2847c Send a message via Yahoo to gt2847c
Default Re: Enabling IPv6

Bingo!... Found the trick. Have to enable IPv6 on the gateway as well as the management server. On your enforcement point, execute:
$FWDIR/scripts/fwipv6_enable
I rebooted the system afterwards (just to be sure), but you might be able to get away with a cpstop;cpstart.

Hope that helps... Worked great for me!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:47.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0