CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Search:

Type: Posts; User: brierw

Search: Search took 0.00 seconds.

  1. Replies
    2
    Views
    6,113

    Deploying Anti-Bot Blade

    Hi,

    I am curious to know if it is possible to make the deployment of the Anti-Bot Blade silent. At this point I have used my test policy to deploy it to a machine that doesn't have it and although...
  2. Replies
    0
    Views
    2,599

    Client Settings Question

    HI,

    In the Client Settings section under Default Client User Interfaces tab the setting overwrites the images on our desktop preconfiguration. Is there a way to bypass using this and just leave...
  3. Replies
    1
    Views
    1,354

    Re-Enabling the Management Interface

    Hi,

    While in the Web UI of my gateway I selected the mgnt interface and selected "disable" and now of course I cannot get to the gateway via the Web UI or any other interfaces. I do maintain...
  4. Windows 7 VPN Clients get automatic configuration script applied

    HI,

    I have an R75.30 Management Server running on Splat.
    I have a Nokia IP390 running R65.70
    The current Remote Access community member is a Nokia IP390 running IPSO and the CheckPoint version...
  5. Replies
    3
    Views
    2,736

    Unable to push policy to IP Cluster

    Hi,

    We are unable to push a policy to our Checkpoint IP Cluster, all of a sudden. We have 10 firewalls managed by our Management Server, and only the Cluster doesn't allow policy pushes. The error...
  6. Thread: HFA70

    by brierw
    Replies
    3
    Views
    2,048

    HFA70

    Hi,

    Moving to HFA70 on an IP350, I know... I won't be on it much longer.

    Question, will an IP350 with a gig of memory allow me to put the required IPSO 4.2 106a04 on it for the move to HFA70?...
  7. Replies
    2
    Views
    2,476

    Secure-Client availability for LION

    Hi,

    Simple question...

    I am running R65 HFA70 and want to know if there is currently a Secure-Client (64bit) version available for MAC's new OS Lion? I am in the process of upgrading to R71.3,...
  8. Replies
    6
    Views
    3,179

    Re: Best available Upgrade Option

    I've heard some people say that I should export my settings on the management server and build a freshly installed R71.3 management server. Then import that exported backup. That seems laborious to...
  9. Replies
    6
    Views
    3,179

    Re: Best available Upgrade Option

    Hi,

    Thanks for your response. I see I wasn't very clear in the my question, sorry for that.

    I have a Chekpoint R65 HFA40 management server running on windows in VM, and IP390 gateways running...
  10. Replies
    6
    Views
    3,179

    Best available Upgrade Option

    I am currently running R65 HFA40 on Nokia IP390's and am looking to find the best version of R7x to move to, where the upgrade process and path have the smoothest, problem free result. I have seen...
  11. Replies
    4
    Views
    5,230

    Re: Various Malformed HTTP

    Oddly ... This didn't work for me when I created the additional service. Is there anything other then leaving the protocol type blank?
  12. Thread: FWDIR/spool

    by brierw
    Replies
    6
    Views
    2,798

    Re: FWDIR/spool

    I have looked at the processes running and the two SMTP ones seem to be the lionshare of the CPU usage. It would surprise me that an IP390 has trouble processing email when all its doing is...
  13. Thread: FWDIR/spool

    by brierw
    Replies
    6
    Views
    2,798

    Re: FWDIR/spool

    Yes it is a UTM gateway
  14. Thread: FWDIR/spool

    by brierw
    Replies
    6
    Views
    2,798

    FWDIR/spool

    Hello,

    Nokia IP390
    IPSO 4.2 build096
    Checkpoint R65 HFA30

    I have a gateway that all of a sudden appears to have a hard time processing email. The SMTP and SMTPd seem to be collectively taking...
  15. Replies
    1
    Views
    1,585

    How do I know...

    Hello,

    I want to know how I can find out on a Checkpoint R65 install with HFA30 on Nokia IPSO running 4.2 build096 what someone chose that built the gateway when they got to the "press 1" for...
  16. Re: Installing R65 HFA50 on Nokia IPSO 4.2 -- Help

    I completely agree with upgrading one, failing the cluster over, then upgrading the other. We have done this successfully when HFA's needed to be applied to our clusters.
  17. Re: Installing R65 HFA50 on Nokia IPSO 4.2 -- Help

    First thing is to ftp the HFA file to the device your upgrading into the packages directory

    Telnet to the firewall and login as admin

    When starting at - /var/ehome/admin - follow these...
  18. Replies
    1
    Views
    1,822

    VPN connectivity

    Hello,

    R65 HFA30 running on IPSO 4.2

    I don't think we can do this but I thought I would ask the experts. We are running remote access VPN on a gateway of ours and also have wireless running...
  19. Replies
    7
    Views
    2,944

    Re: Out of state issue...

    What kind of NAT entry would potentially cause this? :)
  20. Replies
    7
    Views
    2,944

    Re: Out of state issue...

    Another thing to mention is there is no routing here...

    I am talking about traffic where the firewall is the gateway and the firewall interface is connected to a switch. The switch is 24port and...
  21. Replies
    7
    Views
    2,944

    Re: Out of state issue...

    I agree it makes no sense...

    When a policy is pushed, traffic that never used the gateway before, because it's destined for another node on the same network, starts to see the gateway. The best...
  22. Replies
    7
    Views
    2,944

    Out of state issue...

    Hello,

    I have an R65 gateway running HFA30 on an IP390 with IPSO 4.2 build096. Whenever I push a policy to it one of my DMZ networks begins to have issues where it randomly blocks traffic (out of...
  23. Dropped packet between two external interfaces

    I had some port forwarding working and when I applied my 25 user license it stopped. Here is what I had setup

    FW Rule
    source destination port
    any publicIPXX 4100

    My Nat...
  24. Replies
    0
    Views
    1,589

    Creating a new policy

    Hello,

    I am creating a new security policy for a new gateway I am setting up and will have Remote Access and Site-to-Site VPN on it (Site-to-Site between two Checkpoint gateways). I want to know...
  25. Replies
    5
    Views
    2,353

    Re: Getting back to inital setup screen

    I have been told I have a bad R65 install on an IP390 and I suspect its config. I notice this command doesn't appear to reset everything as I still see host entries? Are there any other things I...
  26. Replies
    2
    Views
    1,977

    Re: Weird issue after R65 upgrade

    Senior Members... :)

    Have a look at the article and see what you think. It really seems to fit our problem...
    ...
  27. Replies
    2
    Views
    1,977

    Re: Weird issue after R65 upgrade

    Hello,

    It would appear that the "static work assignment" is no longer working after the upgrade to R65 HFA_30 from R60 HFA04. When the second member of the cluster is removed the significant...
  28. Replies
    2
    Views
    1,977

    Weird issue after R65 upgrade

    Hello,

    We recently upgraded our IPSO Cluster of two Nokia IP390's from R60 with HFA04 to R65 with HFA 30. The upgrade appeared to apply to both members simultaneously, which wasn't what appeared...
  29. Replies
    4
    Views
    2,031

    Re: Upgrading to R65 with HFA_30

    Thanks ... Better safe then sorry :)
  30. Replies
    4
    Views
    2,031

    Upgrading to R65 with HFA_30

    Hello,

    I would like it if someone could verify to me that R65's HFA_30 is a cumulative HF for the R65 version. This would mean that it includes HFA02 and the Hotfix for HFA02 inside the HFA_30...
  31. Thread: Command Line

    by brierw
    Replies
    7
    Views
    6,143

    Re: Command Line

    I was looking to see if there was a Checkpoint or IPSO way to block at the command line an individual IP. It would likely be easier to block at the command line in the event we were getting attacked...
  32. Thread: Command Line

    by brierw
    Replies
    7
    Views
    6,143

    Command Line

    Hello,

    I am looking for the syntax at the command line to block an individual IP on an R60 Checkpoint Cluster. Anyone help me out with this?

    We have Nokia's clustered running Checkpoint R60
  33. Replies
    4
    Views
    2,383

    Re: Out of state issues...

    Hi,

    I appreciate your answer. I have been in contact with Checkpoint Support on this issue and they acknowledge it is in fact a problem. They have said they hope to add a fix into a future HFA but...
  34. Replies
    4
    Views
    2,383

    Re: Out of state issues...

    Hi,

    Thought I would ask some questions and offer some more information on this issue. Is anyone else having it? This issue is also one that can be recreated quite easily, so I would expect this...
  35. Replies
    4
    Views
    2,383

    Out of state issues...

    Hello,

    I have recently upgraded our nodes to R65 HFA02 with the hotfix, from R60 HFA04. We are now seeing a very large number of out of state packets, which naturally are affecting performance and...
  36. Re: Getting lots of Out of state messages on R65

    Our proxy server has started generating an inordinate number of our of state packets being seen by our firewall. Has anyone seen this before? This seems to be a relatively new development for us. The...
  37. Getting lots of SYN attack messages from the proxy server

    Hello,

    I am getting a ton of syn attack messages from our proxy servers in Tracker while they handle web browsing requests. This just started happening a couple of weeks ago but has now made...
  38. Replies
    1
    Views
    1,720

    Upgrading from R60 to R65...

    Hello,

    I am upgrading a Nokia IP390 firewall from Checkpoint R60 with HFA04 to Checkpoint R65 with HFA02 and the hotfix for HFA02. I have successfully run this already on 4 gateways without issue,...
  39. Replies
    14
    Views
    7,626

    Re: Site-to-Site VPN Problem

    Hello,

    Same error... Still not working :(

    Any other ideas?
  40. Replies
    14
    Views
    7,626

    Re: Site-to-Site VPN Problem

    Hello,

    I really appreciate your response.

    I have a question on what you have suggested. Does a "get topology" not take care of updating things from the Nokia portion and also take care of...
  41. Replies
    14
    Views
    7,626

    Re: Site-to-Site VPN Problem

    Here is a section of the VND.ELG file... I removed the IP's and the community name...


    Sorry it's so long...


    [vpnd 16775 3056128]@FW[3 May 7:22:38] fwd_log_handler called (data == 0x0, dlen...
  42. Replies
    14
    Views
    7,626

    Re: Site-to-Site VPN Problem

    Found it... It's not plural...
  43. Replies
    14
    Views
    7,626

    Re: Site-to-Site VPN Problem

    This is going to sound funny but I cannot find the directory "logs"?? in the root there is no directory called logs?
  44. Replies
    14
    Views
    7,626

    Re: Site-to-Site VPN Problem

    Thanks for the reply...

    I will try that and post what I see.
  45. Replies
    14
    Views
    7,626

    Site-to-Site VPN Problem

    Hello,

    I am unsuccessfully trying to establish a Site-to-Site VPN between a Checkpoint R65 gateway and a Nortel CES 2600.

    I have created an interoperable device for the Nortel and added a rule...
  46. Replies
    9
    Views
    3,002

    Re: Site-to-Site VPN Help Needed

    Is there an easy way to convert the existing policy? Or do I have to create a new simplified VPN policy and make it look the same as the existing one.

    I am kinda hoping there is a "save as...
  47. Replies
    9
    Views
    3,002

    Re: Site-to-Site VPN Help Needed

    I have one last question...

    Seeing as there are all of these steps to do this in traditional mode should I be converting my policy to a simplified VPN policy? Are there any advantages or...
  48. Replies
    9
    Views
    3,002

    Re: Site-to-Site VPN Help Needed

    Hi,

    Thanks for the reply.

    I do not see the VPN tab when I open the rulebase for that gateway. If simplified was there I see how it would be easy cause when I create a rule and want it to...
  49. Replies
    9
    Views
    3,002

    Re: Site-to-Site VPN Help Needed

    Thanks for that...

    Also one more thing. I am not using "simplified VPN" so how do I create encryption rules telling the traffic destined for that network to encrypt?
  50. Replies
    9
    Views
    3,002

    Site-to-Site VPN Help Needed

    Hello,

    I am establishing a site-to-site VPN between an external company and my own. My gateway is R60 with HFA04 on a Nokia device. I have created the mesh site-to-site VPN community and setup the...
  51. Replies
    0
    Views
    2,043

    Member keeps leaving the cluster..

    Hello,

    I have a Nokia IPSO cluster running 4.2 Build042_HF002 and I see one of my members constantly leaving and rejoining the cluster. It is always the same member and the activity continues even...
  52. Replies
    1
    Views
    10,625

    Web Intelligence Issue...

    Hello,

    I have Web Intelligence setup and working but for some reason if the URL is HTTPS the protection doesn't work???

    Is there something I'm missing here?

    Many thanks :)
  53. Replies
    8
    Views
    3,386

    Re: R60 to R65 Upgrade issue

    Hi,

    Thanks for the reply...

    I have one active/active Nokia IP cluster and two other single gateways... Looks like I'm in for four 3 web licenses...

    Do I use the IP of the management server...
  54. Replies
    8
    Views
    3,386

    Re: R60 to R65 Upgrade issue

    Hello,

    So I am guessing that I need to swap my 10 web license for three 3 web licenses... I will then also assume that my three gateways will each have a license which gets added under the...
  55. Replies
    8
    Views
    3,386

    Re: R60 to R65 Upgrade issue

    Hello,

    Thanks for the reply...

    If I have a IP cluster in production will I need a second license when I try to add webs that are protected by that gateway?

    I was always given the impression...
  56. Replies
    8
    Views
    3,386

    Re: R60 to R65 Upgrade issue

    Hello,

    Here is the error when I try to push a policy... I get this error even if I try to push a policy with only one web added to the list???

    "Additional licenses for Web Intelligence are...
  57. Replies
    8
    Views
    3,386

    R60 to R65 Upgrade issue

    Hello,

    We want to use Web Intelligence and have used a 30 evaluation license to do so to this point. When we started the evaluation, we have used about 3 30 day evals so far, we were on R60 on our...
  58. Thread: Please HELP

    by brierw
    Replies
    2
    Views
    1,971

    Please HELP

    Hello,

    We have an IPSO cluster running version 4.2-Build042 HF002 using Checkpoint R60 with HFA04 and are having a very odd issue. We have three ip's, one for each cluster member as would be...
  59. Re: Trouble applying HFA_04 to Nokia IP Clustered IP390's running R60

    Anyone... Bueller... :)
  60. Trouble applying HFA_04 to Nokia IP Clustered IP390's running R60

    --------------------------------------------------------------------------------

    I have a setup in a lab that has two IP390's using Nokia IP clustering and want to apply HFA_04 to it. I am running...
  61. Replies
    6
    Views
    3,896

    Re: R60_HFA_04 on IPs0 4.1 Build013 (IP390)

    I have a simialr setup in a lab to what is described here. 4.1 with R60 vanilla install and looking to apply HFA_04 to a Nokia clustered pair of IP390's. The install is not flash based (I have a pair...
  62. Thread: High CPU

    by brierw
    Replies
    1
    Views
    4,510

    High CPU

    Hello,

    I have an IP350 running IPSO v4.1 with checkpoint NGXR60 and I am getting a 99% CPU. When I check the process log and it tells me this process is taking up most of the CPU ...

    nobody...
  63. Thread: DNS issue

    by brierw
    Replies
    0
    Views
    1,877

    DNS issue

    Hello,

    We started getting smart defense messages that tell us we are getting two things blocked...

    Traffic on port 1039 between our DNS servers using service domain-udp (53)

    and
    ...
Results 1 to 63 of 63