CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Search:

Type: Posts; User: ttpm123

Search: Search took 0.00 seconds.

  1. Replies
    5
    Views
    3,420

    Re: ARP, NAT and gateway

    Thanks for the replies. I do have auto ARP set in Global policy.

    I spoke with someone with +10 years on many Check Point platforms. He told me this is not uncommon on SPLAT. SPLAT can fail to...
  2. Replies
    5
    Views
    3,420

    Re: ARP, NAT and gateway

    northlandboy, thanks for the suggestion. I thought of the static route too but want to hold that card for last if I cannot see the source of this problem.

    hotice, I do not have entries for the...
  3. Replies
    5
    Views
    3,420

    ARP, NAT and gateway

    I am working on a SPLAT R65 HFA02 box. I have created an object in a DMZ with auto static NAT address (A.B.C.197/24). No 'Internet' src can get to the box. Zero entries in the logs and zero tcpdump...
  4. Replies
    1
    Views
    1,763

    User Authority and Cisco?

    What is the Cisco technology that implements User Authority - type functionality?

    My management wants to know how tough it would be for me to replace our 9 Checkpoint firewalls with Cisco to save...
  5. Replies
    8
    Views
    3,369

    Re: 'Reliable' NAT failing

    This suggestion is what I am going to move forward on. It seems to have the benefit of simplicity. I am not sure why the previous admin defined 2 nodes for each server to implement NAT'g. Thanks...
  6. Replies
    8
    Views
    3,369

    Re: 'Reliable' NAT failing

    Bingo! That worked.

    I looked through the rule base for traffic between the same internal and NAT subnets and see rules (and traffic) with and without the NAT object included in the policy. Is...
  7. Replies
    8
    Views
    3,369

    Re: 'Reliable' NAT failing

    Yes, a rule is in place to allow traffic from the vendors subnets on defined ports to the RFC 1918 addresses for the servers.

    The NAT rule is also defined; traffic sourced from Vendors subnets to...
  8. Replies
    8
    Views
    3,369

    'Reliable' NAT failing

    A NAT technique I have used successfully is suddenly failing and I cannot find the loose thread.

    DMZ servers use RFC 1918 space.
    DMZ servers are static NAT'd to addresses in a public subnet for...
  9. Replies
    0
    Views
    2,365

    Log maintenance on R60 Solaris

    In R55 I managed our logs by deleting and restarting User Authority.

    I would kill and restart the UserAuthority process to release the log's file descriptor.
    ...
  10. Replies
    8
    Views
    19,229

    Re: Clean up $FWDIR/log/ - remove old logs

    Thank you, this is very useful.
  11. Replies
    8
    Views
    19,229

    Re: Clean up $FWDIR/log/ - remove old logs

    In R55, I can remove all files in /CPuag-R55/log after a backup. But which files in R60 (CPsuite-R60/fw1/log can be removed and what is the purpose of these? Or are their pointers to good...
  12. CP R60 and Netscreen SSG 520 - one way traffic

    I have setup a VPN with a partner's SSG 520; tunnel is up successfully and their telnet requests to our sever are working fine. Policy is good, NAT works and snoop shows traffic inbound through the...
  13. Replies
    3
    Views
    7,642

    Re: installx_top: MtMutexCreate failed

    The problem was isolated to the management server running linux. The 'mutex' error refers only to Linux.

    The lock files are written to $CPDIR/tmp. Delete those files in tmp and the problem is...
  14. Replies
    3
    Views
    7,642

    Re: installx_top: MtMutexCreate failed

    I have learned that a mutex is a "lock" on key system resources that prevents 2 processes from using or writing to the 'locked' resource at the same time. This is used in multi-threaded programming...
  15. Replies
    3
    Views
    7,642

    installx_top: MtMutexCreate failed

    I am pushing policy to an R55 NG AI and am seeing a strange error message on policy install failure:

    installx_top: MtMutexCreate failed

    I see it is failing on validate and install but when I...
  16. Replies
    3
    Views
    6,001

    Re: Adding an Administrator

    OK, beneath 'Administrator' is an object 'cpconfig_administrators'. In 'cpconfig_administrators' are myself and boss (who has been out of STD for months). When I right-click 'Administrator' and...
  17. Replies
    3
    Views
    6,001

    Adding an Administrator

    Let me start by saying I'm a newbie at security and CP in particular. I have inherited several firewalls. No support contract and no training.

    I am trying to add an new admin so he can use...
  18. Replies
    0
    Views
    1,912

    Hello everyone!

    I am a L2/3 engineer, mostly Cisco for 10 years. Our Security engineer reported to me for the past 2 years and has recently left the company. I am picking up were he left off. I have very little...
  19. Replies
    6
    Views
    6,583

    Re: extended vpn authentication failure

    RayPesek; thanks for the advice. I have seen the clock problem before - in fact I fixed a vendor SC connection yesterday with that solution.

    Our connectivity was restored after many hours with CP...
  20. Replies
    6
    Views
    6,583

    Re: extended vpn authentication failure

    Are scc commands server or client side?
  21. Replies
    6
    Views
    6,583

    Re: extended vpn authentication failure

    I'm not sure if this debug output helps:

    [vpnd 891 1]@saintpeter[19 Jun 13:38:59] fwCert_FindCertListAndKey: Entering
    [vpnd 891 1]@saintpeter[19 Jun 13:38:59] Cert Reqeust got from peer:
    [vpnd...
  22. Replies
    6
    Views
    6,583

    extended vpn authentication failure

    Our SC VPNs are all failing with the 2 errors; one is "Negotiation with gateway XYZ at site ABC.NYR has failed. Make sure the user is properly defined on the firewall. Connection canceled" others say...
  23. Replies
    3
    Views
    2,099

    Re: installed wrong policy - pls help

    Thank you. I was able to load the correct policy from the console.
  24. Replies
    3
    Views
    2,099

    installed wrong policy - pls help

    I installed border policy on an internal firewall, should I simply install the correct policy to fix this?
Results 1 to 24 of 24