CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Search:

Type: Posts; User: simon

Search: Search took 0.00 seconds.

  1. Re: Endpoint Connect VPN R75 blocks traffic when inside LAN

    Sorry, for that unclear answer, I was in a hurry.

    It is a known issue that after installation of the client all incoming traffic is blocked. A solution for "traffic is blocked inside the vpn...
  2. Re: Endpoint Connect VPN R75 blocks traffic when inside LAN

    This is a known limitation. Maybe removed with HFA1, which probably will be released end of March.
    R75 also blocks some registry keys, therefore some GPOs aren't applied anymore. For example IE...
  3. Re: Cisco Load Balancer not working after FW failover

    If you choose not to modify your CSS or can't in case of ASAs, you might consider implementing Virtual MAC addresses with your Check Point solution. Take a look into sk50840 which describes how to...
  4. Re: Non-routable addresses with default GW and automatic ARP

    banduraj, I agree having cluster addresses on a different subnet isn't a very good idea. I don't recommend it to customers either.

    However, if there is a situation you have no other solution at...
  5. Re: Non-routable addresses with default GW and automatic ARP

    Hi Paul,

    I will try to clarify it for you.




    In detail:
    The Linux OS will not allow you to set a default route to an IP address which isn't directly reachable (via an interface device)...
  6. Replies
    21
    Views
    9,112

    Re: NGx R65 to R70 upgrade misery

    Hi cciesec2006,

    I also had trouble with some upgrades from R65 to R70/R71. The error message is familar and doesn't give you much about possible reasons, unfortunately. I would guess your OS...
  7. Replies
    5
    Views
    3,881

    Re: licence upgrade and hardware upgrade

    Good Morning,

    Yes you will need ADN for Dynamic Routing. If you already have SecurePlatform PRO Licenses those will be upgraded to ADN. But it is best to check that in your UserCenter. Click on...
  8. Replies
    6
    Views
    4,132

    Re: upgrade from SPLAT R71.20 to R71.30 advice

    PhoneBoy, if I'm allowed to modify your official advice:



    If you take the definition of SHOULD from RFC2119, it MAY match. :)

    Seriously: In my experience "Plugins" often stands for trouble....
  9. Replies
    5
    Views
    3,881

    Re: licence upgrade and hardware upgrade

    Hi symon,

    As serlud wrote, it depends on your current License(s).

    Usually you will not have to pay to change hardware, unless you use an Appliance which comes with a License bound to it.
    ...
  10. Replies
    3
    Views
    3,116

    Re: Management Interface for Gateway install

    Hi dchoy,

    I think you mean the "management connection / management interface" you would select through sysconfig during the first-time wizard?

    The "Management Interface" you select through...
  11. Replies
    1
    Views
    4,018

    Re: Installing strace RPM on SecurePlatform?

    Hi cephalon,

    strace from CentOS 3.8 should work fine. You can find it here.

    Check Point is still using glibc 2.3.2 based on RHEL3.x. R65 SPLAT 2.6 and R70+ is using kernel 2.6.18 based on...
  12. Replies
    6
    Views
    4,132

    Re: upgrade from SPLAT R71.20 to R71.30 advice

    Actually you don't necessarily need to uninstall CPSG80CMP-R71-00, the management will just check the installed Plugins.
    But I also don't see why it should be left on a Log Server/Eventia System....
  13. Replies
    4
    Views
    2,996

    Re: Multiple CMA log synchronization

    Have a look into sk12882. This SK describes how to send logs to a Log Server/CLM which has no SIC Trust with the sending device (your VSes).
    You can then fetch logs from the Log Server with your LEA...
  14. Replies
    6
    Views
    4,132

    Re: upgrade from SPLAT R71.20 to R71.30 advice

    Hi cciesec2006,

    I would say you have three options:

    Install R71.30 and then uninstall both Plugins
    Modify Wrapper.conf and skip installing both Plugins
    Activate the Plugins on your PV1

    ...
  15. Replies
    8
    Views
    5,526

    Re: Unable to ping Standby Physical IP

    Hi Shaps,

    Your Management tries to reach the Standby Members Main IP, which is the external IP in your case. As the Management only has a default route which is pointing to the VIP it tries to...
  16. Replies
    39
    Views
    20,089

    R75 available for download..

    No announcement but R75 is available for download!

    Checkout the Release Notes and have fun! :)
  17. Thread: Project Gaia

    by simon
    Replies
    82
    Views
    61,317

    Re: Project Gaia

    Yes, there will be some impressive features coming!

    Still I wished Check Point would have choosen the iproute2 framework for policy based routing over the IPSO implementation. It would have been...
  18. Replies
    0
    Views
    2,076

    [OT] Funny "Certification"

    <cynism on="on">
    Another "very important" "certification" for the information security sector: Institute for Certified Application Security Specialists (ASS)

    How could I miss it for so long?...
  19. Replies
    15
    Views
    20,749

    Re: How to block SSH tunneling ?

    Hi all,

    regarding SSL/TLS Inspection read this post, this post or the complete thread.

    Inspecting SSH Traffic on a Security Gateway uses the same method known as MITM attack.

    There are some...
  20. Re: New Series 80 Appliance Pushing Software Blades to the Edge of the Network

    Hi PhoneBoy, Hi serlud,

    Thanks for the info.

    Of course I know that CP isn't releasing the tech specs of their appliances. At least not officially. And I guess most of us know why. ;)

    I had...
  21. Re: New Series 80 Appliance Pushing Software Blades to the Edge of the Network

    Sounds interesting.

    No moving parts, external power supply, 10 1Gbit ports, new deployment tool..

    Are any detailed specs available for the new Appliance?
    CPU, RAM, ..
  22. Replies
    13
    Views
    6,521

    Re: multiple tunnels to same peer

    Hello tomo,

    I don't know the reason why you want to split the traffic into different tunnels, especially why you need different Phase 1 negotiations.

    If you try to utilise different Links...
  23. Replies
    2
    Views
    2,151

    Re: Desktop Policies & EC/SC.

    Hi member054,

    To your questions:
    - Desktop Policy does only have impact on your client. For desktop policies to work, you need SecureClient or the new Discovery Client (currently still in EA)....
  24. Replies
    1
    Views
    2,398

    Re: ISP Redudancy UTM1073 R70.20 SB

    Hi caro06,

    late answer but hopefully not too late. ;)

    If a failover occurs your active sessions remain on the old address / ISP link and will fail. ISP Redundancy should be an easy/cheap way to...
  25. Replies
    3
    Views
    2,622

    Re: VLAN.20 on Extenal interface is not reachable

    For the archive, this is a continued thread from the post UTM-1 ISP redundancy with 1 External interface.

    Please look there.
  26. Replies
    9
    Views
    4,637

    Re: UTM-1 ISP redundancy with 1 External interface

    Hello johnny,

    I reply to this thread instead of VLAN.20 on Extenal interface is not reachable.

    First, please make sure your Enforcement Gateway can reach both ISP routers. Try pinging both...
  27. Re: Configure each VPN community to use a different local IP address

    Hello and welcome adelgados!

    I would recommend you to use a second interface for the new ISP and migrate your VPNs one-by-one. The second interface can be a VLAN interface or a real one, doesn't...
  28. Thread: HTTPS thru Proxy

    by simon
    Replies
    12
    Views
    7,957

    Re: HTTPS thru Proxy

    Hi manuadoor,

    Yes, this is like it should be.

    The curious reader should take a short look into RFC2616 Section 9.9 and a not so short look into RFC2817 Section 5.2 "Requesting a Tunnel with...
  29. Replies
    2
    Views
    2,420

    Re: Crafting Probe Packets to test policies

    Hi Markus,

    FTester could be what you want.

    hping and nemesis are also very helpful tools for crafting your very own IP packets.

    Would be nice to read about your results. :)
  30. Thread: HTTPS thru Proxy

    by simon
    Replies
    12
    Views
    7,957

    Re: HTTPS thru Proxy

    Hi,

    The following products will support scanning HTTPS traffic: IronPort S Series, BlueCoat, McAfee Web Gateway and Squid+SSL Bump.

    Basically those Proxies use a MITM (Man-in-the-Middle) Attack...
  31. Replies
    9
    Views
    4,637

    Re: UTM-1 ISP redundancy with 1 External interface

    Hi johnny, You're welcome!

    You do not need to use IPSec for ISP Redundancy or VLANs.

    You can, however, use ISP Redundancy to increase the availaiblity in performance of your IPSec based VPNs....
  32. Replies
    9
    Views
    4,637

    Re: UTM-1 ISP redundancy with 1 External interface

    Hi johnny,

    You need two interfaces for ISP Redundancy to work. If you do not want to or can't use another physical interface you can separate both ISP Links by VLAN on one physical interface. This...
  33. Replies
    9
    Views
    4,415

    Re: VPN accelerator card

    Hi *tomo*,

    First: You are not alone!

    QoS is not working with CoreXL, therefore you can't really utilise your Multi-Core Hardware.

    The Accelerator Cards are not supported for...
  34. Replies
    6
    Views
    5,211

    Re: upgrade import from R70.30 to R71

    Hi murderousmurk,
    Did you use the R71 upgrade tools to export the configuration on your old management?

    If not, transfer the whole $FWDIR/bin/upgrade_tools directory from your new R71 machine to...
  35. Replies
    2
    Views
    2,271

    Re: Endpoint Connect - Requirements

    Hi bytes,

    Take a look at the Endpoint Connect R73 Release Notes, Section Updating the Endpoint Connect Version on the Gateway (Page 4) says:
    You have to update the Endpoint Connect version on...
  36. Re: creating preconfigured package Endpoint-Connect... Question

    Hi bytes,

    Take a look into the documentation. R70 VPN Administration Guide Page 385 "Using the Packaging Tool".
    You'll get an MSI Package which you can deploy to your clients.

    You can also...
  37. Replies
    8
    Views
    5,022

    Re: correct bios setup for processors in HP380G6

    Hi serlud,

    True. Sorry I forgot to mention it. Usually the onboard NICs are used as secured interfaces in a cluster configuration, at a max.

    The following network adapters are supported by...
  38. Replies
    1
    Views
    2,752

    Re: Authentication issue with AD - DLP GW

    Hi varera,

    I don't have a DLP to play but the error indicates that the UPN (user@domain.tld) could not be read. Maybe you should check if the user has an UPN set. I have seen users without UPN,...
  39. Replies
    8
    Views
    5,022

    Re: correct bios setup for processors in HP380G6

    Hi Roluf,

    Adam was faster, but I will add some comments.

    Intel Virtualisation / Intel VT-d
    You will not need Virtualisation, so you can savely disable it.

    Intel Hyperthreading
    On Check...
  40. Replies
    7
    Views
    24,520

    Re: Clear ARP Cache - SPLAT

    Hi belvdr,

    I know. :)

    I think ifconfig and route are deprecated since linux kernel 2.2, which was released quite a while ago (1999/2000 ?). ;)

    But alot of distributions are still using...
  41. Replies
    10
    Views
    6,100

    re: R65 -> R70 Upgrade fails

    Hi,

    there is no direct upgrade from R65 to R70.1/20/30. Therefore you still need to use the WebUI for the R70 upgrade.

    According to the R71 Installation and Upgrade Guide it is still only...
  42. Replies
    7
    Views
    24,520

    Re: Clear ARP Cache - SPLAT

    Hi,

    here is an alternative by using the fabulous ip utility.
    (Only supported on SecurePlatform/Linux)

    Flush all arp enties on interface eth0:

    # ip neigh flush dev eth0Flush arp entry for...
  43. Replies
    6
    Views
    3,022

    re: Root Username change

    Hi Kevin,

    Technically it is possible to change the username 'root'. Depending on the scripts used for different OS/Check Point tasks you may run into tremendous issues during operation, upgrade,...
  44. Replies
    10
    Views
    6,100

    re: R65 -> R70 Upgrade fails

    Hi Alex,

    For the Power-1 and UTM-1 Appliances it is important to do the Upgrade through the WebUI. An Upgrade through CLI fails with the error you described.

    On page 168 in the R70 ...
  45. Re: Setting up mail alerts on windows management station

    Hello sonayny,

    Do you use the command internal_sendmail or sendmail in Global Properties?
    From the documentation (SmartDashboard Help):Try using internal_sendmail if you didn't.
    I assume your...
  46. Replies
    11
    Views
    3,785

    Re: Finding IP of SCS from Gateway

    Hi Manu,

    Yes, there are ways to find the IP of your Security Management Server.

    You can look up the IP address in $FWDIR/database/objects.C or in the state table management_list.

    Here is an...
  47. Re: R71 is GA? SmartEvent? SmartReporter?.. and other Smart Product..

    Hm.. I think I like the IPSec VPN Enhancements.

    Especially Service Based Link Selection sounds promising!


    IMHO
    For DLP (and for IPS) SSL/TLS Interception is a key feature. I think this is...
  48. Thread: R71 availablity

    by simon
    Replies
    30
    Views
    13,544

    Re: R71 availablity

    Hi all,

    I would be interested how Check Point is going to manage all this forks in near future.


    R65 HFA40 -> R65 HFA50 -> R65 HFA60 -> R65 HFA70
    | /
    \ ...
  49. Replies
    11
    Views
    5,247

    Re: Reporting broken post

    This Maybe my fault. I posted a reply, since then the error apears.
    Don't know why, I didn't use any special characters or control commands.

    I already wrote a PM to the site admin last night.
    ...
  50. Re: Having trouble getting R65 Win Export to R65 Splat Import

    Hi pmb1010,

    Do a SmartDefense Upgrade, it will fix your issue.

    Additionally I would recommend you to look for CRLF formated textfiles.
    There may be some pretty important files which where...
  51. Re: UTM-1: Does License include LDAP and AD integration?

    You can use RADIUS as an alternative if you like.

    Use External User Profiles to match users without the need to create them on your SmartCenter. Of course this is not as flexible as SmartDirectory...
  52. re: Problem Accessing Microsoft shares through the Firewall

    Hi slocmiester,

    It is hard to say what the actual problem is without more details.

    What I would recommend you to to is:

    Check SmartDefense settings. Every CIFS relevant protection should be...
  53. Thread: DR from cpinfo

    by simon
    Replies
    11
    Views
    7,949

    Re: DR from cpinfo

    Yes Thorpuse, you are absolutely right!

    I wouldn't recommend to use this method if there is another way. But in case this is your last resort, it may be worth it.

    At least you get your object...
  54. Thread: DR from cpinfo

    by simon
    Replies
    11
    Views
    7,949

    Re: DR from cpinfo

    InternalCA will be gone but you can get most other stuff. It will help you to restore and the missing parts will remind you to do backups AND TEST THEM! ;)

    Basically it works like this:
    Setup the...
  55. Replies
    14
    Views
    14,800

    Re: How the policy based routing works

    @Ajit: Back to the orignial problem. I could think of two possible ways to solve the problem on a SPLAT gateway. Both have limitations.


    ISP Redundancy
    You can force ISP Redundancy to route...
  56. Replies
    14
    Views
    14,800

    Re: How the policy based routing works

    Hi,

    Please also read this post: http://www.cpug.org/forums/check-point-utm-1-appliances/10190-power-1-appliances-5070-9070-a.html#post39869.

    Unfortunately you can't utilize FULL IPRoute 2...
  57. Replies
    6
    Views
    5,929

    Re: Encryption Domain with Exclusion Group

    And this sk25675 describes this snippet of INSPECT code you were referring to.

    It is a very powerful and useful directive indeed. :)

    Would be nice to hear/read/see use cases for it.
  58. Replies
    34
    Views
    15,172

    Re: R70 is finally here?

    Hi guys,

    Check Point just released R70.

    Some interesting links:

    R70 Known Limitations sk37042

    R70 Documentation
  59. Replies
    6
    Views
    5,929

    Re: Encryption Domain with Exclusion Group

    Hi,

    In my experience a Group with Exclusion works for Site2Site VPNs with Check Point GWs in the same Management Domain.

    I know about trouble with SR/SC when a GW has a VPN Domain of this type...
  60. Replies
    3
    Views
    3,464

    Re: Cleaning Unused Network Objects

    Hi scucci,

    Stupid question: Do you mean something like View -> Objects List?

    If you need a CSV of your objects odumper might be of interest to you.
  61. Replies
    3
    Views
    2,079

    Re: Help of checking up module by CLI

    Hi shmilyh,

    Take a closer look at cpstat. It might be very helpful for your customer. It is documented in the R65 CLI Reference/Admin Guide.
    Also ver or cd_ver might be of interest to you.

    Of...
  62. Re: Moving SmartCentre into VMWare - not going as easily as anticipated

    Hi,

    Please take a look in %FWDIR%\log\fwm.elg. Is there anything suspicous?

    Is the fwm.exe process running?
    Is fwm.exe listening on TCP port 18190 (do a netstat –an on cmd)?

    Make sure...
  63. Replies
    9
    Views
    5,824

    Re: Periodic FIB Failures

    Sorry for the cphaprob –ie list, this is wrong! I meant cphaprob –ia list .
    I remembered a special R65 HFA30 for advanced routing, I think you should take a look at it: sk35205

    If your problem...
  64. Replies
    16
    Views
    6,277

    Re: IMPORTANT - People still using SecuRemote

    SecuRemote and Office Mode
    This is a grey area indeed. It is technically possible and shipped with VPN-1 Edges in combination with SecuRemote, but not officially supported. It seems as Check Point...
  65. Replies
    9
    Views
    5,824

    Re: Periodic FIB Failures

    Hi yheffen,

    Some things you should check:

    Does sk31243 help you?
    Are both cluster member SPLAT PRO?
    Is the gated daemon running on both cluster members?
    Do you really need SPLAT PRO...
  66. Replies
    4
    Views
    3,183

    Re: Defining the VPN interface

    Hi banduraj,

    You do not need SPLAT PRO unless you want dynamic routing (routing protocols) through gated.

    You do not need VTIs, Route based VPN. Domain based VPN is just fine for your purpose....
  67. Replies
    7
    Views
    4,915

    Re: Power-1 Appliances - 5070/9070

    Hi,

    iproute2 is around for years and provides PBR capabilities.

    You can use iproute2 to do PBR. As there is no official support for PBR I wouldn’t recommend you to use it if you need to rely on...
  68. Replies
    2
    Views
    2,445

    Re: High Availability

    Hi nathang,

    This depends on your license.

    If you purchased your license recently or you are not using a very old one, it is included. For Load Sharing (active/active) you will need an...
  69. Replies
    2
    Views
    2,228

    Re: Finding internal using natted address....

    Hi TIA,

    You should take a look in your Firewall logs.

    Open SmartView Tracker and select Query Properties in the View menu.
    Look for XlateSrc and XlateDst (propably in the end of the list),...
  70. Replies
    3
    Views
    3,440

    Re: Single VPN Authentication using Certificate

    Hi giuffrolo,

    You could use a SmartCard to store the user certificate in a secure manner.

    SmartCards prevent copying the private key, so users cannot compromise security by handing over...
  71. Re: UTM-1: Does License include LDAP and AD integration?

    Hi Tom,

    Your UTM-1 Appliance should come with a SmartDirectory license.

    See: https://pricelist.checkpoint.com/
  72. Replies
    3
    Views
    2,582

    Re: How do "you" build your SmartCentre servers?

    Hi,

    Here are some of my thoughts.

    Disk size is more a matter of how long you would like to keep your logs and view them with SmartView Tracker. Of course the log volume matters to. So...
  73. Replies
    1
    Views
    1,573

    Re: connectcontrol monitor servers state

    Hi lifeng1656,

    There is nothing like a green, yellow or red bulb to indicate the status of your logical servers or its members. At least not that I know off.

    You can take a look into your...
  74. Re: Unable to compile edge policy after upgrade to NGX 65 HFA30

    Hi Morphus,

    1. Did you try with a different policy?
    2. Did you update to the latest libsw version?

    According to the error message, there is a parsing error. So maybe there is something wrong...
  75. Re: disable SmartDefense Protection on NGx R61 gateways with NGx R65 SmartCenter/CMA

    Hi cciesec2006!

    To your questions.

    1. SmarDefense Protection Profiles were introduced with R62, so they are not available on a R61 SmartCenter.

    2. Yes it is possible and it will work. At...
  76. Replies
    1
    Views
    2,655

    Re: FWD Dies with SIGSEGV(11)

    Hi menardk,

    A segmentation fault is always a bad thing and may be a result of a memory leak.
    There are several things you can do to find out the problem source.
    You could start fwd in debug mode...
  77. Replies
    6
    Views
    53,255

    re: Sychronising time on gateways

    Hi archie,

    You can use NTP for time synchronisation with an external source.
    Checkout www.pool.ntp.org for different external sources.

    Take a look in the R65 SecurePlatform & SecurePlatform...
  78. Re: No log-entries in SmartView Tracker from Nokia Cluster (really hard nut)

    Hi DeLaRio!
    To me your logging problem seems to be a SIC issue too.

    I would ask you to try the following.

    1. Switch off one cluster module. This makes debugging more easy.
    Make sure time is...
  79. Thread: Help!

    by simon
    Replies
    12
    Views
    5,166

    Re: Help!

    Hi kevin,

    If the certificate expiration date is still 3 years ahead I wouldn't worry too much. ;)
    You should consider renewal a few months ahead of the expiration date. Same for VPN Clients like...
  80. Re: Non-routable addresses with default GW and automatic ARP

    What you gain or loose depends on your configuration. ;-)

    For example consider the following Scenario:

    Internet --- Router --- Firewall Cluster --- Internal Network

    IP Network between Router...
  81. Re: Account Unit: Usage of Domain Admin account mandatory?

    Hello hotice!

    A domain administrator is not necessarily mandatory to fetch branches and use SmartDirectory within your Check Point environment.
    If you do not use the Check Point schema extension...
  82. Replies
    9
    Views
    5,695

    Re: How to create redundant VPN link

    Hi Sam,

    This is a completely different scenario.

    You will not need to configure your gateways like stated above, RDP probing is not necessary in your scenario.
    The routers should recognize a...
  83. Thread: Help!

    by simon
    Replies
    12
    Views
    5,166

    Re: Help!

    Hi Kevin,

    No, the certificates are not renewed automatically.

    You need to do this manually by pressing the "Renew.." button in the VPN tab of the checkpoint host object.
    The certificate will...
  84. Thread: Help!

    by simon
    Replies
    12
    Views
    5,166

    Re: Help!

    Hi kevin,

    Go to the VPN tab in the relevant checkpoint host object. Select the certificate you would like to check and press "View..".

    You will find the expiration date there..

    By the way,...
  85. Replies
    9
    Views
    5,695

    Re: How to create redundant VPN link

    Hi Sam,

    You are right, the probing is only available to "VPN enabled" interfaces.

    Acording to your diagram both links are terminated at your enforcement points, so that all traffic is passing...
  86. Re: Issue with SD not showing Application Inteligence droppdown

    Hi John,

    Take a look at sk34541 and sk32570. Those do not describe your specific problem but maybe those help you anyway.

    I stumbled upon both articles while surfing the skb some time ago.
    ...
  87. Replies
    9
    Views
    5,695

    Re: How to create redundant VPN link

    Hi menz456,

    Did I forget to mention that you should define both interfaces as external? ;)
    You should not have any problems with anti-spoofing in this case.

    Let's assume
    Site A has a VPN...
  88. Re: Non-routable addresses with default GW and automatic ARP

    Hi banduraj,

    For 1) try:
    # ip route delete default
    # ip route add DEFAULT_GW_IP/32 dev INTERFACE
    # ip route add default via DEFAULT_GW_IP
    # route --save

    This will tell your SPLAT that the...
  89. Replies
    9
    Views
    5,695

    Re: How to create redundant VPN link

    Hi Sam,

    As I don't know about the version you are using I assume you use R65.
    You can do this with Link Selection.

    Here is a short example configuration:

    Site A:
    Open Gateway properties ->...
  90. Replies
    1
    Views
    2,090

    Re: Allocated IP Addresses

    Hi felxo,

    Take a look into the CheckPoint_R65_VPN_AdminGuide.pdf.

    The Remote Access VPN section (Chapter 14 and 15) covers the topic you look for.
    Watch out for OfficeMode configuration via...
  91. Replies
    1
    Views
    1,948

    Re: Migrating Splat Network settings

    Hi Michael!

    I don't know off a direct export/import, but what I would do is:
    1. Backup current R55 configuration.
    2. Restore R55 configuration in a vmware install.
    3. Upgrade vmware install to...
  92. Replies
    4
    Views
    2,089

    Re: isp redundancy with clustering on splat

    Hello sebastan,

    Yes it is possible to use ISP Redundancy with ClusterXL New Mode HA on SPLAT and Linux.

    And yes there are several limitations and requirements. You should have a look in the...
  93. Replies
    1
    Views
    2,250

    Re: Install on Suse 10 OSS CA Errors

    Hi winsoc,

    SuSE is not a supported OS, you should consider using RedHat Enterprise Linux 3 or SecurePlatform, which is available for free if you are a Check Point customer.

    Because Check Point...
  94. Replies
    5
    Views
    10,738

    Re: allowing icmp redirect

    Hello compubear,

    at this point some more details are needed to help you fixing the problem.

    Should the firewall send icmp redirects, should it receive them, are you running a cluster, is it a...
  95. Replies
    5
    Views
    10,738

    Re: allowing icmp redirect

    You need to enable the global kernel variable "fw_icmp_redirects".

    You can do this by editing the file "$FWDIR/boot/modules/fwkern.conf".

    Simply add the following line:
    fw_icmp_redirects=1
    ...
  96. Replies
    2
    Views
    3,888

    Re: replacing Nokia with SPLAT

    Hi,

    replacing Nokia Clusters with SPLAT may or may not be easy, it depends on the "Nokia specific" functionalities you are using.

    You should first check your Nokia configuration and compare it...
  97. Replies
    4
    Views
    4,354

    Re: Difference between NGX R60 and R60A?

    Hi,

    R60A integrates Content Inspection (the Express CI series).

    Regards,
    Simon
  98. Replies
    1
    Views
    3,907

    Re: Office Mode and ipassignment.conf

    Hi jcamillo,

    make sure you define more specific entries on top of your generic settings.

    For example:
    Line #1: cpmodule addr 192.168.1.100 wins=(), dns=() JohnDoe
    Line #2: cpmodule net ...
Results 1 to 98 of 98