CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Search:

Type: Posts; User: Barry J. Stiefel

Page 1 of 5 1 2 3 4

Search: Search took 0.01 seconds.

  1. Re: "Forbidden" when attempting to reply to thread

    ModSecurity can be rather aggressive and hard to tune properly. I'll see what I can find.
  2. Replies
    4
    Views
    3,915

    Re: customer partition?

    I've changed the title of this thread as you've requested.
    Can you tell me more about the problem you're seeing, like which browser, what's your screen resolution, etc.? I'm not seeing this nor have...
  3. Replies
    11
    Views
    6,427

    Re: Hi everyone!

    While inside a specific forum you should see at the top of the page a blue action button that says "+ Post New Thread". Is that not present?
  4. Replies
    26
    Views
    24,287

    Re: Check Point R77.20

    I think it was in this thread that someone's quoting (quoting a previous post in one's reply) was messed up because someone had accidentally deleted part of the "QUOTE" tag; I saw it and jumped in...
  5. Re: Apparently "too many links" in a post generates 403 errors

    Found it:

    Access denied with code 403 (phase 2). Pattern match "(?:\\[ ?(url|link) ?= ?\"? ?https?://.*\\[ ?(url|link) ?= ?\"? ?https?://.*\\[ ?(url|link) ?= ?\"? ?https?://.*\\[ ?(url|link) ?=...
  6. Re: Apparently "too many links" in a post generates 403 errors

    I just did some research on this. It appears that mod_security (a type of Layer 7 HTTP firewall) is blocking this and not being very graceful about it.

    Could you please e-mail me exactly what you...
  7. Replies
    2
    Views
    2,587

    Re: Logging all traffic to/from China

    Here's a useful list: http://www.okean.com/thegoods.html

    Here's another: http://www.wizcrafts.net/chinese-iptables-blocklist.html

    You could probably use ofiller/odumper to create the objects,...
  8. Re: Smartdashboard user password limit 8 character

    You're right about this, except now you have to worry about keeping those local Linux accounts and their passwords synchronized across every Security Gateway. At least with the other way there was...
  9. Re: Smartdashboard user password limit 8 character

    I think it's been like that forever. It always struck me as being insecure, also. I suspect there's a marketing reason behind it, like if you want better security you'll have to buy an additional...
  10. Re: Immediate Opening for Multiple Check Point Consultants in Nebraska

    I have some more information about this opportunity:

    1. The work location is in Omaha, Nebraska
    2. The hourly rate is up to $80/hour
    3. The contract is for 12+ months

    Feel free to contact...
  11. Immediate Opening for Multiple Check Point Consultants in Nebraska

    Recruiter Peter Roos sends the following message:

    Our Client requires IT Project support to assist with two critical network security infrastructure upgrades. The customer will be replacing...
  12. Replies
    5
    Views
    3,374

    Re: Connections table max's out

    I seem to remember reading somewhere that each connection needs about 1K of RAM in the connections table (if I'm wrong on this, somebody please tell me), so for most platforms increasing the size of...
  13. cpug.org does not have a problem with the Heartbleed bug

    http://filippo.io/Heartbleed/#cpug.org
  14. Re: What's the difference between routers and switches ?

    The original post in this thread had a spammy link to a commercial site that sells routers and switches. I think we've been duped by a spammer. I've removed that link.
  15. Re: Security Management server and Gateway Combo - Is it still possible ?

    That's it. torontosecurity you're getting a temporary ban until you respond to my communications...
  16. Re: Management server upgrade R65 to R75

    Please check your private messages...
  17. Replies
    16
    Views
    6,513

    Re: Passing public ip???

    No, this new public IP address would really just be a public /32 network that they would forward to your gateway. They wouldn't actually put it on an interface anywhere. You would put it on the...
  18. Replies
    16
    Views
    6,513

    Re: Passing public ip???

    You wouldn't actually bind this new single public IP address to the external NIC on your Security Gateway. You'd just have your ISP forward all packets destined to this new public IP address to this...
  19. Re: Endpoint Security VPN Version compatibility

    You're much more likely to get a helpful response if you actually ask a question at the end of your post...
  20. Re: VPNs restricted to Endpoint Security Clients?

    Who do you mean by "we"? Check Point? Your company?

    Please go easy on the spamminess. I've sent you a private message.

    The signal-to-noise ratio here is very high; if you're just spewing...
  21. Replies
    16
    Views
    6,513

    Re: Passing public ip???

    Here's another suggestion:

    Ask your ISP for an additional single public IP address. Have them forward traffic destined for this new public IP address to the public IP address on the outside of...
  22. Re: MDS and SmartEvent - Report Generation

    Hmmmm... burger.
  23. Re: About Slipstreamed Fixes Retroactively Inserted Into Already-Released Versions

    There are places for pioneers: alpha testing, beta testing and the Early Availability Program. People in these programs have been informed that the code they receive is provisional, is expected to...
  24. Re: HTTPS Certificatre Expired for cpug.org

    All better now. We're using an "Extended Validation" certificate (the kind that gives you the green bar in your browser's address bar), and there was a glitch in renewing this.

    Carry on, in most...
  25. Re: About Slipstreamed Fixes Retroactively Inserted Into Already-Released Versions

    Is that information going to be part of the new CCRE (Check Point Certified Release Engineer) exam?
  26. Re: HTTPS Certificatre Expired for cpug.org

    Well, I thought this was taken care of, but apparently it's not. I'm working on it. I suspect it may take a day or two.
  27. About Slipstreamed Fixes Retroactively Inserted Into Already-Released Versions

    I think retroactively inserting slipstreamed fixes into already-released versions is a really bad idea.

    It seems Check Point has two goals here:

    1. Release versions as soon as possible to meet...
  28. Replies
    10
    Views
    9,480

    Re: Intermittent Tunnel Loss

    Thanks for a detailed and helpful response, ShadowPeak.com.
  29. Congratulations and Thanks to CPUG Members for Civil Discussion!

    Hello Everyone,

    Here is a post from James Fallows on his blog at The Atlantic:

    No Man Is a (Comments-Free) Island ... - James Fallows - The Atlantic

    We should be proud of ourselves that his...
  30. Replies
    50
    Views
    33,939

    Re: Check Point R77

    Now that there are two different versions of the .iso images for both R75.47 and R77, does anybody know if these updates have different version numbers, or how to tell them apart? Should we call...
  31. A little help, please, on installing GAiA in WMware (ISO disconnects during install)

    Hello,

    I'm running VMware ESXi 5.1 and I'm trying to install GAiA 75.46 or 75.47 in a VM. I've uploaded the ISO's into the datastore and before booting I've changed the BIOS to boot from the...
  32. CPUG CON Check Point User Conference SeptemberFest in Munich, September 9th-12th.

    Hello Everyone,

    It's that time of year again!. Please join us at CPUG CON 2013 SeptemberFest in Munich on September 9th-12th!

    This will be our 6th annual conference for Check Point firewall...
  33. Replies
    53
    Views
    133,075

    Sticky: Re: Check Point 1100 Appliance - FAQ

    Now it's sticky and I've renamed the forum. Let me know what else I can do to help.
  34. Replies
    53
    Views
    133,075

    Sticky: Re: Check Point 1100 Appliance - FAQ

    Excellent! Let me know if you need anything special here on the discussion board.
  35. Replies
    0
    Views
    4,203

    Gil Shwed Interviewed

    Firewall tech pioneer Gil Shwed: Former teen sysadmin on today's infosec biz ? The Register
  36. Replies
    2
    Views
    2,635

    Re: Hi everyone

    Welcome to CPUG!

    Your English is fine; please jump in an participate!

    With kind regards,

    Barry
  37. Replies
    4
    Views
    22,457

    Re: Reset admin CLI password in Gaia

    I'm looking into this. It sounds like one of the protections we use to prevent SQL injection attacks...

    Barry
  38. Re: One VPN Domain per Gateway, multiple encryption domains required

    mcnallym, you're awesome. Thanks for your really good posts lately.
  39. Replies
    3
    Views
    5,573

    Re: R76 GAIA / SmartLog

    (moved thread to new SmartLog forum)
  40. Re: [Gaia] SNMPd crash upon topology change

    (fixed the thread title)
  41. CPUG University Class in Luxembourg Week of March 18th

    Hello European CPUG Members!

    We'll be holding a special edition of our Course 101: “Hands-On Check Point Firewall Administration” in Luxembourg the week of March 18th, 2013. For those of you who...
  42. Replies
    1
    Views
    1,917

    Re: Hello Everybody

    Welcome to CPUG!

    Please jump in an participate.

    With kind regards from San Francisco,

    Barry
  43. Replies
    1
    Views
    3,800

    Re: Will this be updated anytime soon?

    It's likely we'll be holding CPUG CON in Munich this year in September. We're working on finalizing the dates.

    Updates coming soon!

    Barry
  44. Replies
    11
    Views
    6,427

    Re: Hi everyone!

    I don' think this is the correct forum to ask for that sort of information.
  45. Replies
    0
    Views
    1,883

    Just completed some minor upgrades

    Hello Everybody!

    Happy New Year from San Francisco!

    We've just completed some minor upgrades:



    Update kernel to Linux 2.6.18-308.16.1.el5 #1 SMP Tue Oct 2 22:01:43 EDT 2012 x86_64 x86_64...
  46. Replies
    1
    Views
    2,123

    Re: Howdy!

    Hello and Welcome to CPUG!

    Please jump in and participate!

    With kind regards,

    Barry
  47. Replies
    1
    Views
    2,824

    Re: Default Password for SPLAT

    Yes:

    username: admin
    password: admin
  48. Replies
    2
    Views
    2,037

    Re: Hey !!! am in

    Hello Spawn,

    Welcome to CPUG! Please jump in and participate. Our goal is for this discussion board to be incredibly useful, fast and free.

    With kind regards,

    Barry
  49. Re: Can't download SPLAT R70 or R75 from Checkpoint site

    Thanks for helping a newbie with a useful, detailed answer.
  50. Replies
    1
    Views
    1,854

    Re: Hello CPUG

    Hello dvanr and Welcome to CPUG!

    Please jump in and participate. The discussion board is really useful, fast, and free.

    With kind regards,

    Barry
  51. Replies
    1
    Views
    1,906

    Re: Hello from Spain

    Hello and Welcome to CPUG!

    We're glad to have you; please jump in and participate. Hello to Spain!

    Barry
  52. Special CPUG University Course in Boston Week of December 10th!

    We're offering a special week-long Course 101: “Hands-On Check Point Firewall Administration course in Boston the week of December 10th, 2012.

    Read about CPUG University.

    Please contact me for...
  53. Re: cp_uploader - Checkpoints new alternative to providing SFTP details

    This is useful. Thanks for doing this.

    Barry
  54. Re: For Sales: Checkpoint U-10 UTM-1 270 Security Appliance

    If we turn it right side up, will it work here in North America?
  55. Replies
    1
    Views
    1,633

    Re: Hello everybody, I'm new here

    Please, no spam in your signature block. [spam removed]

    Welcome to CPUG!

    Barry
  56. Re: No machines eligible for policy installation

    Thanks for figuring this out. I wasted an hour and a half this week trying to figure out what I'd done wrong. I even reinstalled the Security Gateway to try to fix this problem. Grrr.
  57. Replies
    1
    Views
    2,004

    Re: New CPUG Member

    Hello Jeff!

    Thanks for being a good student this week!

    Welcome to CPUG; please jump in and participate. You've got a nice little town there, in State College. People are friendly and polite...
  58. Re: Block websites with offensive language - Creating URL browsing reports

    Must resist... Trying... ...so... ...hard... ...to... ...not... ...reply... ...with... "why the fuck would you want to do that?". Must resist. Must resist.

    Must resist...

    [bites finger]
  59. Replies
    2
    Views
    4,775

    Re: CCSE R75 Training Material for sale

    What do you mean by "photocopy books"? Are these just photocopies of the original Check Point books? If so, this sounds like a trademark violation and you shouldn't try to sell them here. If not,...
  60. Thread: Hi

    by Barry J. Stiefel
    Replies
    2
    Views
    2,256

    Re: Hi

    Hello and Welcome to CPUG!

    I hope you were one of the attendees at our conference this year (Check Point Conference).

    Please jump in and participate here!

    Barry
  61. Re: YALI (yet another lousy introduction)

    Hello to Northern Germany from CPUG. Please jump in and participate.

    Will you be attending our conference starting a week from tomorrow in Switzerland?

    Check Point Conference

    With kind...
  62. Replies
    1
    Views
    2,091

    Re: Hi all

    Welcome to CPUG. We're glad to have you. Please jump in and participate.

    Barry
  63. Replies
    1
    Views
    2,004

    Re: New member :D

    A big welcome from CPUG to the Land of the Vikings! Please jump in and participate!

    Barry
  64. Re: Time Drift tolerance on site to site VPN community

    Thanks for a detailed, useful response, Shadowpeak.
  65. Replies
    1
    Views
    2,026

    Re: Hi all

    Hello! We're glad to have you. Please jump in and participate.

    Barry
  66. Replies
    2
    Views
    2,913

    Re: Anyone have search tips to share??

    I'm the board administrator. Can you tell me more about these searches and what you're getting/not getting? I'll see if there's something going on here.

    Also, Google is a very good index of what...
  67. Re: Strange outgoing https connections from R75.30 GW

    Anybody at Check Point want to explain what's going on?
  68. Replies
    4
    Views
    2,820

    Re: Management Server HA for R65 SMS

    Management HA is not a very sophisticated product. It appears that development work on it stopped at least ten years ago.
  69. Re: Strange outgoing https connections from R75.30 GW

    80.255.143.119
    Moscow, Russia
    http://www.geobytes.com/IpLocator.htm?GetLocation&IpAddress=80.255.143.119
    143-119.ranetka.ru


    80.239.141.119
    London, England...
  70. Replies
    1
    Views
    2,065

    Re: Hello CPUG!

    Hello and Welcome to CPUG!

    Please jump in an participate!

    Barry
  71. Re: Thread: R75.40: Migrating from Standalone to Distributed (sk61681)

    I don't know how to translate this...
  72. Re: Check Point Power-1 5077 - Security Appliance 4 units available

    Just out of curiosity: Why would someone lease them from you for only eight months? Or maybe they intended for longer but then dropped the project or went out of business? As a business owner who...
  73. Re: Hello Check Point Users Check Point Power-1 5077 - Security Appliances

    There is a top-level forum here where you can post your for-sale or for-lease announcement. I think some of our members might be interested. We welcome these sorts of ads/announcements.
  74. Replies
    5
    Views
    3,249

    Re: Hello Everyone

    Hello and Welcome to CPUG!

    Please jump in and participate; we're glad to have you.

    Barry
  75. Re: GAiA: no sysconfig for you, use clish

    (new GAiA forum just created and this thread moved to it)
  76. Re: Upgrade SPLAT to GAIA - login incorrect

    What was the problem with that character? You could no longer use it in a password?
  77. Replies
    1
    Views
    2,017

    Re: Hi everyone!

    We're glad to have you. Welcome to CPUG.

    Please jump in and participate!

    Barry
  78. Replies
    2
    Views
    2,076

    Re: Hello from the Netherlands

    Welcome to CPUG! We're glad to have you. Please jump in and participate.

    Barry
  79. It's working fine for me right now on my Android...

    It's working fine for me right now on my Android phone.

    (sent by Forum Runner from my Samsung Galaxy Note)
  80. Tapatalk is now updated to the current version (3.9.4)

    We've updated the Tapatalk plug-in to the current version (3.9.4).

    Please let us know if there are any problems.

    With kind regards from San Francisco,

    Barry
  81. If you've had trouble making a complex post lately...

    If you've had trouble making a complex post lately, please try again. We've been tuning out protections against SQL Injection attacks and I see we've had at least one false positive. It should be...
  82. Forum Runner is now working properly!

    We've made some upgrades and Forum Runner is now working properly, even with https.

    Yay for us!

    Barry
  83. Replies
    24
    Views
    19,637

    Re: What happen to Checkpoint Website

    After rising for weeks, their stock price was at $64.77 on Monday. Since the outage, it's been falling steadily and closed today at $63.07, down 2.6% since Monday, representing a $340,000,000 loss...
  84. Replies
    24
    Views
    19,637

    Re: What happen to Checkpoint Website

    Ouch! (This is what it looked like on Monday)

    http://regmedia.co.uk/2012/04/02/checkpoint.jpg
  85. Replies
    24
    Views
    19,637

    Re: What happen to Checkpoint Website

    Maybe it's part of a new marketing campaign: "Check Point: We take Internet security so seriously we're not even on the Internet"

    Has Check Point said anything about what happened yet?
  86. Replies
    24
    Views
    19,637

    Re: What happen to Checkpoint Website

    First weak SSL, and now this. I don't know how they stay in business.
  87. Re: Error: Error while processing the request

    Thanks for posting the solution.
  88. 2011-12-16 Gartner Magic Quadrant for Enterprise Network Firewalls

    Check Point does well.

    Here's the link: Magic Quadrant for Enterprise Network Firewalls

    Here it is saved as an XPS file: ...
  89. Replies
    1
    Views
    1,813

    Re: Hello Everyone

    Welcome to CPUG! Please jump in and participate.
  90. We're testing some improvements; let me know if something isn't working properly

    Hello Everybody,

    We're testing some improvements on the web server. It shouldn't cause any problems, but please let me know if something isn't working properly.

    With kind regards from San...
  91. Replies
    5
    Views
    4,128

    Re: Tapatalk is now working with HTTPS!

    Hello,

    Can you try the fix discussed in this thread:

    Failed to connect to forum. | Tapatalk Support

    Does that fix it?

    (I'm still searching for solutions)
  92. Replies
    5
    Views
    4,128

    Re: Tapatalk is now working with HTTPS!

    Hello jacobsen,

    I just did quite a bit of searching around and it appears there is no separate plugin for TapatalkHD, that there's only one thing to install and it's installed properly on our...
  93. Replies
    1
    Views
    1,787

    Re: Hi all ,new from Bangalore

    Hello Bangalore! Welcome to CPUG. Please jump in and participate.
  94. Replies
    3
    Views
    3,185

    Re: RIP Not Starting

    I don't know if this is relevant or not, but I'll mention it: In the Policies => Global Properties dialogue box, there's a setting that manages an implied rule that allows RIP. Could that have...
  95. Replies
    2
    Views
    11,942

    Re: web intelligence licensing

    If I remember correctly, at least in previous versions, to enable the Web Intelligence protections, you had to go to the host/node object representing your web server and check the box for Web...
  96. Re: It looks like we're going to stay with HTTPS for CPUG.org for good

    Now you can!
  97. I just added my request for HTTPS support at ForumRunner

    I hope this is something they can do.

    Sent from my SAMSUNG-SGH-I717 using Tapatalk
  98. Replies
    5
    Views
    4,128

    Tapatalk is now working with HTTPS!

    I was finally able to go to their website and change the protocol to HTTPS. Please let me know if there are any problems.

    Sent from my SAMSUNG-SGH-I717 using Tapatalk
  99. Replies
    15
    Views
    6,649

    Re: gcc included

    Maybe in the future we'll (be able to) / (be required to) compile our own patches?
  100. It looks like we're going to stay with HTTPS for CPUG.org for good

    Hello Everyone,

    It seems we've worked out most of the problems with implementing HTTPS. Thanks for all your help with troubleshooting.

    Here's a current discussion on Reddit discuss the...
Results 1 to 100 of 500
Page 1 of 5 1 2 3 4