CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Search:

Type: Posts; User: varera

Page 1 of 5 1 2 3 4

Search: Search took 0.01 seconds.

  1. Replies
    9
    Views
    17,441

    Re: How to output fw ctl zdebug + drop to a file ?

    As mentioned here already, you can redirect output to a text file. That iis pretty much it. If you need a proper capture file that would be compatible with WireShark and tcpdump, use fw ctl debug set...
  2. Replies
    2
    Views
    21,434

    Re: Checkpoint 3 tier Architecture

    There is an article about that under “CPUG Papers”
  3. Replies
    7
    Views
    15,230

    Re: CCSM R77.30 courseware for sale

    yes, the last one
  4. Should we continue scaring our customers into security spending?

    My personal answer is no

    http://checkpoint-master-architect.blogspot.ch/2018/02/the-main-cyber-security-questions-of.html
  5. Replies
    12
    Views
    6,726

    Re: Anyone attending CPX360 2018?

    Oh come on, I was young and needed some money
  6. Goodbye Check Point, hello Guardicore, wish me luck, etc

    http://checkpoint-master-architect.blogspot.co.uk/2018/01/goodbye-check-point-hello-guardicore.html

    I am switching my professional focus to cloud security and mostly leaving Check Point behind....
  7. Replies
    0
    Views
    6,005

    CPET project is closed

    Hi all, I have some changes in my professional life, and as the result, I will have to close CPET. Thanks a lot for being with me.

    More details can be found here:...
  8. Replies
    25
    Views
    19,305

    Re: R80.10 in VMware

    Any Gaia. To deploy VSX, you install a physical GW first and then run provisioning.
  9. Replies
    25
    Views
    19,305

    Re: R80.10 in VMware

    WebUI setup wizard must be run once a new Gaia installation is made.
  10. Replies
    25
    Views
    19,305

    Re: R80.10 in VMware

    yet there is a very important reason to block webUI after enabling VSX. I do agree initial WebUI setup seems to be unnecessary
  11. Replies
    7
    Views
    4,513

    Re: VSX - Virtual Systems not sending logs to MDS

    so no Fws. Check if your policies on VS0 allow communications between MLM and VSs. Otherwise, config issue
  12. Replies
    7
    Views
    4,513

    Re: VSX - Virtual Systems not sending logs to MDS

    anything in between VSX cluster and MDS?
  13. Replies
    1
    Views
    3,634

    Re: automatic restore of P1 backup

    Good one. MDSM restore is must as part of regular sanity checks
  14. Replies
    16
    Views
    20,367

    Re: Check Point "e-kits"

    Editor? Not a viewer?
  15. Replies
    16
    Views
    20,367

    Re: Check Point "e-kits"

    Looking forward to see the tool out. I hope that’s not two weeks for alpha fix :)
  16. Thread: cphastart error

    by varera
    Replies
    7
    Views
    5,817

    Re: cphastart error

    Why are you using this command in the first place? What are you trying to achieve?
  17. Replies
    16
    Views
    20,367

    Re: Check Point "e-kits"

    Dameon, seriously? You gave me the same answer 5 month back. Unless this "private beta" becomes a tested GA release, this info does not help.

    When I mentioned 5 years ago in a blog post, there is...
  18. Replies
    8
    Views
    9,492

    Re: Periodic High latency problems on a single VS

    Look here: 23486 admin RT -20 1380m 845m 39m R 99 0.7 3368:00 fwk32_0

    Your VS 32 is running 100% CPU. Why is a good question, but this is a clear CPU utilisation issue. May be caused by million...
  19. Re: Multi domain management server in vmware workstation doesn't run

    Just look above, the guy had a licensing issue. With minimal effort, vmware implementation of MDSM should not be a problem. I do agree with disk performance note. One does want to have very fast...
  20. Replies
    4
    Views
    4,372

    Re: wiered r80.10 error when pushing policy

    it seems you do not have FW license. please post the output of "cplic print" command
  21. Re: Checkpoint firewall can't reach tacacs servers-> logs show allowed

    we need like button in this forum. thumbs up
  22. Re: Question regarding 'host access' during provisioning

    Second that
  23. Replies
    7
    Views
    3,611

    Re: Anyone interested in scientific research?

    no go unless there is some beer on the table
  24. Replies
    9
    Views
    9,249

    Sticky: Re: Latest CCSA R80 exam information

    Have to remind you that Capsule Docs is still not working on Mac. Windows experience is also mediocre. 100% students give not really encouraging feedback concerning their own experience with the...
  25. A unique chance to buy printed textbooks for self-study: CCSA, CCSM, CCMSE

    I have the surplus courseware for sale:

    CCSA versions R77 and R80
    CCSM R77
    CCMSE R77

    These are probably the last remaining printed courseware sets you can purchase. Check Point now...
  26. Thread: licensing issue

    by varera
    Replies
    1
    Views
    2,380

    Re: licensing issue

    You need an open server license for MGMT
  27. Re: What are correct steps to roll back from R77.30 to R76?

    Jees, that sounds scary...
  28. Re: Bridge mode cluster - object's IP address is required in SmartConsole

    To be on the safe side, I would recommend using another address from bond0 subnet. 0.0.0.0 is not a host address, it is a network. the rest is up to you.
  29. Replies
    8
    Views
    7,847

    Re: fw ctl zdebug command is a bad practice

    LOL, hilarious, but I am afraid, wrong in this context
  30. Re: Bridge mode cluster - object's IP address is required in SmartConsole

    No, that won't do.

    You need to set an actual IP address for the cluster anyway, otherwise CP cannot handle it. Just use an additional address form MGMT network. You do need physical IP addresses...
  31. Re: Multi domain management server in vmware workstation doesn't run

    I have multiple customers running MDSM on VMware VMs without any trouble, for decades.
  32. Re: HELP - dropped by fw_runfilter_ex Reason: F_INDOM

    Known issue. Look into sk110687
  33. Replies
    4
    Views
    2,617

    Re: Changing hardware for R77.3 gateway - HELP

    1. Save Gaia CLISH configuration from both old GWs to files
    2. Copy out, adjust to different interface names with the new appliances, if required
    3. take celan-installed 15000 boxes and drop clish...
  34. Replies
    9
    Views
    5,596

    Re: fw ctl zdebug command question

    I am expressing my displeasure with the situation to Check Point for years.
  35. Re: What are correct steps to roll back from R77.30 to R76?

    Oh gosh... Running an outdated unsupported version and justifying it. Are you in health industry by any chance?
  36. Replies
    8
    Views
    7,847

    Re: fw ctl zdebug command is a bad practice

    Of course you are objecting, guys, as you are way too comfortable with the tool. That is the danger, being comfortable.

    Now, here is the bummer, you should never be at ease with kernel debug in...
  37. Replies
    8
    Views
    7,847

    Re: fw ctl zdebug command is a bad practice

    Right. Why teaching someone gun safety rules, ballistics and do target practice. Just load his gun and teach him how to get safety off. What can go wrong?
  38. Replies
    8
    Views
    7,847

    Re: fw ctl zdebug command is a bad practice

    It seems you misunderstand what the debug buffer size is. It does not control the volume of the output from the kernel. It only gives you a memory space where that output is whitten too. Once the...
  39. Re: What are correct steps to roll back from R77.30 to R76?

    Gaia does not require stopping services on GWs to make snapshots. Although, it is called "image management" now :-)
  40. Replies
    8
    Views
    7,847

    fw ctl zdebug command is a bad practice

    Hello all, after seeing way to many mentions of zdebug on this forum, I have decided to make an effort in explaining why it should not be used at all.

    Please feel free to read and comment by the...
  41. Replies
    9
    Views
    5,596

    Re: fw ctl zdebug command question

    oh boy, i really hate zdebug leaking out. it gets out of control.

    fw ctl zdebug is problematic. it was never intended to leave Check Point RND bubble. use fw ctl debug mechanism, it provides you...
  42. Re: What are correct steps to roll back from R77.30 to R76?

    Snapshot mechanism provides the best rollback option, but it takes time, obviously.
  43. Replies
    3
    Views
    2,441

    Re: Connections drops same time every day!

    it seems your VSX cluster is under load at this time. CUL refers to "cluster under load".

    I have had a similar symptoms when an Internet facing VS was scanned. Scans were dropped on a clean-up...
  44. Replies
    3
    Views
    2,441

    Re: Connections drops same time every day!

    You are correct, there is a policy push at this time. Please make sure you do not have scheduled IPS update at this time. Automated IPS updates may cause policy push, depending on the settings.
    ...
  45. Replies
    3
    Views
    4,008

    Re: Well Hello There!

    Welcome Jan
  46. Replies
    6
    Views
    17,812

    Re: Smart Console 'Unable the connect server'

    CPM only exists on R80 and above. All management servers, SMS or MDSM, will have this command working. Mind your MDSM environment when running, as CPM will run on every context of MDS
  47. Replies
    6
    Views
    17,812

    Re: Smart Console 'Unable the connect server'

    There is a script that ensures that CPM is up and running, and SMS is fully operational.

    Run $FWDIR/scripts/cpm_status.sh command. CPM is not fully operational till it returns "Check Point...
  48. Thread: CZ/GR Greetings

    by varera
    Replies
    2
    Views
    3,340

    Re: CZ/GR Greetings

    Welcome!
  49. Replies
    6
    Views
    17,812

    Re: Smart Console 'Unable the connect server'

    check if you meet HW requirements on your VM before moving any further.
  50. Replies
    8
    Views
    7,781

    Re: Check Point debugging GUI

    Just my 10 cents for the matter. In my view, only experts should be allowed to debug in the first place. And if it is an expert going to debug, why does he need to have a GUI? He should be able to do...
  51. Thread: QOS question...

    by varera
    Replies
    1
    Views
    1,707

    Re: QOS question...

    There is a Quality of Service Admin Guide in R77 documentation package that has all the answers for you.

    https://sc1.checkpoint.com/documents/R77/CP_R77_QoS_WebAdminGuide/html_frameset.htm
  52. Re: Checkpoint to Fortigate IPSEC tunnel (SPIs being deleted)

    Oh boy, this is a VERY old document...
  53. Replies
    9
    Views
    5,413

    Re: VPN failing with Invalid Certificate error

    This is a classic situation for MGMT behind NAT. If your remote device is managed form the same MGMT server, there are two ways to resolve the issue:

    1. Make NAT static settings on the management...
  54. Replies
    8
    Views
    7,781

    Re: Check Point debugging GUI

    Ah, no new debug modules for R80.10, as I see :-)
  55. Replies
    10
    Views
    5,148

    Re: cplic print -x licensing issue

    yet, additive effect for the cores is kinda... unexpected, ah?
  56. Re: Check Point 4800 on either end of 1gb FIOS. VPN Throughput question

    Call the company, by all means. You have acquired this box legally, and if it was stolen or decommissioned, you are entitled to know. If any issue, raise the hell to the seller through Ebay
  57. Replies
    8
    Views
    15,150

    Re: How to use LOM interface on CP 12600

    Now, this is already a much better way
  58. Re: Followed sk97648 to replace with 3rd party cetificate, but result:page cant be di

    restart httpd? check new cert file permissions?
  59. Replies
    3
    Views
    2,132

    Re: Deploying IPS blade in Prevent mode

    The IPS tuning guide is very good and elaborate.

    Yet, the approach can be simplified a bit, to start easy.

    1. Get default profile and modify it to put all protections to "detect only", where...
  60. Replies
    8
    Views
    15,150

    Re: How to use LOM interface on CP 12600

    LOM is supposed to be placed in a secured management access internal segment. Exposing it to internet directly without additional filtering, event with an access list, is an extremely bad idea. To...
  61. Replies
    4
    Views
    5,761

    Re: QoS & Date / Time Operation

    Easily worked around by re-installing policy at the beginning and the end of the working hours, with "rematch opened connections" option active on FW object.
  62. Re: Is there a way to automatically delete backups older then x days?

    There was a thread on CPUG about similar task for log management. just lookit up and modify the script to manage backup files.
  63. Thread: HW Balancer

    by varera
    Replies
    6
    Views
    5,100

    Re: HW Balancer

    clusterXL load sharing was never good and brings way too many limitations and issues to the table.

    never ever use CXL LS. If you are concerned about platform utilization, convert your physical FW...
  64. Re: Migrating from VRRP Cluster to Load Sharing CLuster XL

    Please do me a favor and never ever use ClusterXL load-sharing, unless you are running VSX VSLS, where "load-sharing" is in fact HA on per VS level.
  65. Replies
    0
    Views
    3,283

    CCSM status is extended till mid-2018

    In case you missed, Check Point has extended CCSM status till July 2018 for all certified professionals with certification expiring in between January 2017 and March 2018, including those whose...
  66. Replies
    0
    Views
    3,051

    ATRG aggregation page

    Check Point SecureKnowledge now has an an aggregation page for all available ATRGs. Details by the link:
    ...
  67. Replies
    6
    Views
    5,109

    Re: Newbie Question - What Does Prob Stands For?

    cphaprob:

    cp - Check Point
    ha - High Availability
    prob - probe
  68. Re: Gateways per CMA? Large scale deployment experience?

    Amount of GWs managed from a single management server is only limited by license. However, for effective management LSM is advised, as mentioned above
  69. Thread: vSEC or VSX

    by varera
    Replies
    6
    Views
    5,427

    Re: vSEC or VSX

    As Dameon already said, there is no point to run VSX unsell your FW cluster is outside of eSX environment.
  70. Replies
    2
    Views
    3,538

    Re: procedure for immediately terminating a user

    Two options:

    1. You remove the user and push policy. Every new session for this user will be rejected. Tunnel and remaining sessions will continue till key re-negotiation.
    2. If you want to kill...
  71. Replies
    5
    Views
    3,077

    Re: Explanation on PXL traffic

    I am just trying to clarify, nothing more than that.

    On the other subject, your book is exceptionally good :-)
  72. Replies
    5
    Views
    3,077

    Re: Explanation on PXL traffic

    The reason it is not documented is that there is nothing to document. For any of the security features than need streaming to analyse the flow, FW has to do F2F, so the packets get to FW instance as...
  73. Replies
    5
    Views
    3,077

    Re: Explanation on PXL traffic

    You are correct, PXL stands for Middle Path, which is in fact practically FW path. Session handshake may be accelerated through SND/SecureXL, but once data stream starts, each next packet goes to FW...
  74. Replies
    3
    Views
    3,165

    Re: R80.10 SmartConsole Bug

    all good at the latest GA smartConsole, check the pic below

    1307
  75. Re: Can smartlog show old logs? (e.g from few month ago)

    One more note. if the index depth is high, this will affect Performance of smartLog GUI.
  76. Re: Can smartlog show old logs? (e.g from few month ago)

    smartlog only shows the indexed logs. Log indexing depth depends on how you configure it on the server object and also how much free disk space you got there. Look on the object under Logs / Storage...
  77. Replies
    20
    Views
    22,334

    Re: BGP Failover Time

    drouter is syncing dynamic routes between the cluster members over port 2010. By default it should be allowed via implied rules. If you do not sue those, it then can be blocked and cause late BGP...
  78. Replies
    19
    Views
    6,632

    Re: VSX Cluster Questions

    You are trying to use a template when creating VSX cluster object. Don't. Without a template you will not have this confusing question about external communication interface.

    You will be able to...
  79. Capsule Doc Viewer is unable to open protected files on Sierra 10.12.6

    Some details and screenshots are here:

    checkpoint-master-architect.blogspot.ch/2017/08/capsule-docs-on-mac-forget-about-it.html
  80. Re: Hitcount does not increase when rule has a time object

    Tufin and Algosec can only show rules that are logged. Just saying...
  81. Re: SmartLog indexing depth is limited to about 30 minutes

    SmartLog stops indexing when certain percentage of HDD is no longer available.

    After some cleaning, we now have good one month of indexed logs.
  82. Thread: This is a test

    by varera
    Replies
    4
    Views
    2,647

    Re: This is a test

    lol
  83. Replies
    1
    Views
    4,246

    Re: CPET session 3 - Kernel Debug Best Ptractices

    The recording is now available:

    http://checkpoint-master-architect.blogspot.ch/2017/07/cpet-session-3-video-is-published.html
  84. Re: CPET session 2 - Some details about Unified Policy

    But of course, there is always a trade-in between quality of the video and the upload size.

    Wanna see in good resolution, join the live session. It is free
  85. Replies
    5
    Views
    3,594

    Re: Minimum Password Requirements Missing

    or even better, I can do that for you
  86. Replies
    5
    Views
    3,594

    Re: Minimum Password Requirements Missing

    file RFE, bro :-)
  87. Re: Stateful Ispection Status on Gateway - Drop out of state TCP

    wrong thread, mate
  88. Re: VPN Remote User with timeouts and low performance

    no, afaik
  89. Re: Stateful Ispection Status on Gateway - Drop out of state TCP

    since R75
  90. Replies
    1
    Views
    4,560

    Re: does TE/TEX scans macros and XML?

    TEX just prints your files into pdf or stips them out of all active content.

    List of the files that TE can scan is in the documentation. Assuming the file type is supported, the potential...
  91. Replies
    0
    Views
    1,574

    R80.10 gateway debug documents are now public

    Details and links are here

    http://checkpoint-master-architect.blogspot.ch/2017/07/r8010-debug-documents-are-now-public.html
  92. Replies
    1
    Views
    4,246

    CPET session 3 - Kernel Debug Best Ptractices

    The people have spoken. The session is on. Details here:

    http://checkpoint-master-architect.blogspot.ch/2017/07/cpet-session-3-it-is-on.html

    Please join me to talk about kernel debug
  93. Replies
    1
    Views
    3,221

    Re: CCSM courseware for sale

    One set is still available, if you are interested
  94. Replies
    7
    Views
    15,230

    Re: CCSM R77.30 courseware for sale

    Hi all, one book is still available for sale.
  95. Re: What are the recommended protocols for s2s vpn today?

    Correct. My point was, the full answer would be "those encryption and hash protocols, unless your local laws require something different"
  96. Re: What are the recommended protocols for s2s vpn today?

    Second that. One just need to see these settings are legal in your country. Not the case for Russia, China and probably some other places.
  97. Re: crypt.def following - sk86582 - how to exclude protocols

    You can exclude certain protocols in VPN Community Advanced section. However, that would apply to all communications between both encryption domains.
  98. Re: https inspection both on proxy and check point

    Two SSL decryptions for a single connection makes 4 times trickier certificate management and trust chains. It is as complex as one can handle for a single SSL inspection point.

    I would say, one...
  99. Re: How to convert traditional mode VPN policy to simplified mode VPN policy

    the process of conversion is thoroughly described in Check Point VPN admin guide: https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/13941.htm
  100. Replies
    4
    Views
    6,646

    Re: Antispoofing problem

    I am sorry, but this does not make any sense. You can only create exclusions IF automatic anti-spoofing is disabled.
Results 1 to 100 of 500
Page 1 of 5 1 2 3 4