<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>My Check Point Blog</title>
	<atom:link href="http://blog.lachmann.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.lachmann.org</link>
	<description>Notes from a CCSE+</description>
	<lastBuildDate>Wed, 08 Sep 2010 12:24:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Documents related to troubleshooting</title>
		<link>http://blog.lachmann.org/2010/09/documents-related-to-troubleshooting/</link>
		<comments>http://blog.lachmann.org/2010/09/documents-related-to-troubleshooting/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 09:46:07 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=518</guid>
		<description><![CDATA[The Check Point knowledge base contains a lot of useful documents related to troubleshooting. Here&#8217;s a selection. Feel free to send an email to blog@lachmann.org when you think that a document is missing in the list. NGX Basic Debugging VPN-1 Power/UTM Dropped Traffic Troubleshooting Document fw monitor: A Troubleshooting Tool Troubleshooting MTU related issues How [...]]]></description>
			<content:encoded><![CDATA[<p>The Check Point knowledge base contains a lot of useful documents related to troubleshooting. Here&#8217;s a selection. Feel free to send an email to blog@lachmann.org when you think that a document is missing in the list.</p>
<ul>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10534">NGX Basic Debugging</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10454">VPN-1 Power/UTM Dropped Traffic Troubleshooting Document</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=9068">fw monitor: A Troubleshooting Tool</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=6024">Troubleshooting MTU related issues</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10847">How to Troubleshoot SmartDashboard Connection Issues</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10532">Sync Troubleshooting Guide for ClusterXL &#8211; NG-AI and NGX</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10484">Troubleshooting Guide for Content Inspection &#8211; Anti Virus Protection </a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10284">Anti Virus Signatures Update Process Troubleshooting Flowchart</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10530">SmartDefense Web Intelligence Troubleshooting Guide</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10531">SecurePlatform Debugging for NGX R60</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10479">Handling Core Files</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10481">VPN-1 Power/UTM NGX R65 Debugging with CoreXL</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10485">Analyzing Binary Log Files and Pointers Files</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10521">SmartProvisioning Debugging and Troubleshooting in Versions R65 HFA 40 and later (including R70)</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10342">Certificate Authority Issues &#8211; Tips and troubleshooting</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=7787">VPN-1 UTM Edge Advanced Troubleshooting Guide</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10495">How to debug SSL Network Extender</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10480">Debugging Connectra Issues</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=10545">Debugging SecuRemote/SecureClient</a>
</li>
<li><a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk38848">Practical troubleshooting steps for logging issues</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=7291">NGX Advanced Technical Reference Guide (ATRG)</a>
</li>
<li><a href="http://downloads.checkpoint.com/dc/download.htm?ID=6156">Advanced Technical Reference Guide (ATRG) for NG </a>
</li>
<li><a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk34385">General troubleshooting advisor for Content Inspection Database Update</a>
</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/09/documents-related-to-troubleshooting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SmartSPLAT &#8211; very nice SSH GUI client for SPLAT</title>
		<link>http://blog.lachmann.org/2010/09/smartsplat-very-nice-ssh-gui-client-for-splat/</link>
		<comments>http://blog.lachmann.org/2010/09/smartsplat-very-nice-ssh-gui-client-for-splat/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 16:08:18 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=510</guid>
		<description><![CDATA[I&#8217;d like to share with you that today I got aware of the project SmartSPLAT. Cagdas Ulucan, CCSE+ from Turkey, developed a nice GUI that uses a simple SSH connection to login into your SPLAT-based box and display, change and collect a lot of useful information. The three shell windows show output of fw monitor, [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;d like to share with you that today I got aware of the project <a href="http://www.smartsplat.com/index.htm">SmartSPLAT</a>.</p>
<p>Cagdas Ulucan, CCSE+ from Turkey, developed a nice GUI that uses a simple SSH connection to login into your SPLAT-based box and display, change and collect a lot of useful information.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/09/smartsplat.gif"><img src="http://blog.lachmann.org/wp-content/uploads/2010/09/smartsplat-1024x623.gif" alt="SmartSPLAT" title="SmartSPLAT" width="450" height="273" class="alignnone size-large wp-image-511" /></a></p>
<p>The three shell windows show output of fw monitor, actual fw logging and the main commands, parameters for them can be set using the GUI.</p>
<p>When you click on a button (for example &#8220;debug vpn&#8221;), you can actually see what commands are issued to the shell, so here you have a learning effect.</p>
<p>The tool has a build-in ftp and syslog server, so produced debug files can the uploaded easily.</p>
<p>At the first moment you&#8217;re overwhelmed of all the tabs that address different (troubleshooting) topics, but I think the GUI will improve and Cagdas will find a way to enhance the presentation of his tool.</p>
<p>What is really cool is the cluster view, where you have a windows with two panes, each representing one cluster member. An easy way to send commands to both cluster members and compare the results!</p>
<p><strong>Try his tool, it&#8217;s completely free and very very useful.</strong><br />
<strong>Send him his suggestion for improvement and make it even better.</strong></p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/09/smartsplat-very-nice-ssh-gui-client-for-splat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>resize2fs: Operation not permitted While trying to add group #128</title>
		<link>http://blog.lachmann.org/2010/08/resize2fs-operation-not-permitted-while-trying-to-add-group-128/</link>
		<comments>http://blog.lachmann.org/2010/08/resize2fs-operation-not-permitted-while-trying-to-add-group-128/#comments</comments>
		<pubDate>Mon, 30 Aug 2010 13:52:55 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Appliance]]></category>
		<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=504</guid>
		<description><![CDATA[Today I tried to increase the logical volume on a UTM-1 appliance as described before in this blog. I got the error resize2fs: Operation not permitted While trying to add group #128 when issuing the resize2fs command. The solution to this problem: the journal was to small and had to be re-created: [Expert@firewall]# dumpe2fs /dev/vg_splat/lv_log [...]]]></description>
			<content:encoded><![CDATA[<p>Today I tried to increase the logical volume on a UTM-1 appliance as described before in this blog.</p>
<p>I got the error<br />
<code>resize2fs: Operation not permitted While trying to add group #128</code><br />
when issuing the resize2fs command.</p>
<p>The solution to this problem: the journal was to small and had to be re-created:</p>
<p><code>[Expert@firewall]# dumpe2fs /dev/vg_splat/lv_log | grep Journal\ size</code><br />
Journal size: 32M</p>
<p><code>[Expert@firewall]# tune2fs -O ^has_journal /dev/vg_splat/lv_log              </code></p>
<p><code>[Expert@firewall]# tune2fs -j /dev/vg_splat/log </code><br />
Creating journal inode:<br />
done </p>
<p><code>[Expert@firewall]# dumpe2fs /dev/vg_splat/lv_log | grep Journal\ size</code><br />
Journal size: 128M</code></p>
<p>After that do a filesystem check and issue the resize2fs command, which will succeed.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/resize2fs-operation-not-permitted-while-trying-to-add-group-128/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Increasing HTTP connection buffer for Anti Virus scanning</title>
		<link>http://blog.lachmann.org/2010/08/increasing-buffer/</link>
		<comments>http://blog.lachmann.org/2010/08/increasing-buffer/#comments</comments>
		<pubDate>Thu, 26 Aug 2010 10:17:50 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Content Inspection]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=499</guid>
		<description><![CDATA[Just stumbled about sk36090 which describes that Anti Virus scanning for HTTP traffic can significantly slows down browsing. The resolution is easy, just increase the buffer assigned to each HTTP connection. Go to Policy -> Global Properties -> SmartDashboard Customization. Click on Advanced Configuration. Change the http_buffers_size from 4096 bytes to a higher value. Since [...]]]></description>
			<content:encoded><![CDATA[<p>Just stumbled about <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk36090">sk36090 </a>which describes that Anti Virus scanning for HTTP traffic can significantly slows down browsing.<br />
The resolution is easy, just increase the buffer assigned to each HTTP connection.</p>
<p>Go to Policy -> Global Properties -> SmartDashboard Customization. Click on  Advanced Configuration.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/08/http_buffer.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/08/http_buffer.jpg" alt="http_buffers_size" title="http_buffers_size" width="450" height="387" class="alignnone size-full wp-image-500" /></a></p>
<p>Change the http_buffers_size from 4096 bytes to a higher value. Since the default number of concurrent connections is 1000 for HTTP, changing the parameter to the maximum of 65500 bytes would only allocate ~ 63 MB  for all buffers together, so why not go with the max?</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/increasing-buffer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Application Control &#8211; the next big thing?</title>
		<link>http://blog.lachmann.org/2010/08/application-control-the-next-big-thing/</link>
		<comments>http://blog.lachmann.org/2010/08/application-control-the-next-big-thing/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 10:19:52 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Content Inspection]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=495</guid>
		<description><![CDATA[Check Point announced their new Application Control software blade. Not it is not only possible to use URL filtering for blocking or allowing specific sites, but also to determine what exactly is allowed or denied. For example: allow Facebook in general, but block Facebook games. The AppWiki database is listing several thousand webbased applications to [...]]]></description>
			<content:encoded><![CDATA[<p>Check Point announced their new <a href="http://www.checkpoint.com/products/softwareblades/application-control.html">Application Control software blade</a>. </p>
<p>Not it is not only possible to use URL filtering for blocking or allowing specific sites, but also to determine what exactly is allowed or denied.<br />
For example: allow Facebook in general, but block Facebook games.</p>
<p>The <a href="http://appwiki.checkpoint.com/appwiki/applications.htm">AppWiki </a>database is listing several thousand webbased applications to choose from for use in your policy.</p>
<p>Like DLP, this blade comes with UserCheck technology. This resident (Windows) client allows the gateway to interact with the user. If for example access to YouTube is allowed only for business use and not for personal use, UserCheck can present a dialog to the user asking what&#8217;s the intended purpose of visiting the site. If the user confirms that it&#8217;s for business, he is allowed to access the site.</p>
<p>At the moment I&#8217;m wondering if this is the next big thing&#8230;.. will customers buy this blade and enforce their very own policy? Will this be a considerable alternative to pure content inspection products like WebWasher? What are the implications for the company security policy? Who&#8217;s defining the allow/block lists?</p>
<p>To be honest, I&#8217;m not sure at the moment how customers will use the technology.</p>
<p>Maybe for them it&#8217;s enough to block one or two specific apps as reason to buy this blade.</p>
<p>Maybe it&#8217;s getting as complex as a full-blown IPS solution with a security engineer defining policies and checking logs all day&#8230;. and how many companies can afford that?</p>
<p>I guess we have to wait some time to see where it&#8217;s going&#8230;</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/application-control-the-next-big-thing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>new kernel modules starting with R70</title>
		<link>http://blog.lachmann.org/2010/08/new-kernel-modules-starting-with-r70/</link>
		<comments>http://blog.lachmann.org/2010/08/new-kernel-modules-starting-with-r70/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 09:20:40 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=491</guid>
		<description><![CDATA[On a SPLAT machine, which is based on (RedHat) linux, the Check Point software is running as user mode process or as linux kernel module. This modules can be shown using lsmod [Expert@firewall]# lsmod Module Size Used by Tainted: PF rtmmod_smp.2.4.21.cp.i686 281120 1 bridge 27680 0 (autoclean) (unused) vpnmod_smp.2.4.21.cp.i686 1269512 3 fwmod_smp.2.4.21.cp.i686 7858176 11 simmod_smp.2.4.21.cp.i686 [...]]]></description>
			<content:encoded><![CDATA[<p>On a SPLAT machine, which is based on (RedHat) linux, the Check Point software is running as user mode process or as linux kernel module.</p>
<p>This modules can be shown using <code>lsmod</code></p>
<p><code>[Expert@firewall]# lsmod<br />
Module                  Size  Used by    Tainted: PF<br />
<b>rtmmod_smp.2.4.21.cp.i686</b>  281120   1<br />
bridge                 27680   0  (autoclean) (unused)<br />
<b>vpnmod_smp.2.4.21.cp.i686</b> 1269512   3<br />
<b>fwmod_smp.2.4.21.cp.i686</b> 7858176  11<br />
<b>simmod_smp.2.4.21.cp.i686</b>  827904   1<br />
<b>vpntmod_smp.2.4.21.cp.i686</b>   13808   0  (unused)<br />
e1000                 126728   6<br />
bnx2                   79432   2<br />
crc32                   3592   0  [bnx2]<br />
sg                     38092   0  (autoclean) (unused)<br />
microcode               7072   0  (autoclean)<br />
ide-cd                 35840   0  (autoclean)<br />
cdrom                  33248   0  (autoclean) [ide-cd]<br />
dm-mod                 59428   0<br />
keybdev                 3048   0  (unused)<br />
mousedev                5688   0  (unused)<br />
hid                    22628   0  (unused)<br />
input                   5504   0  [keybdev mousedev hid]<br />
ehci-hcd               20968   0  (unused)<br />
usb-uhci               27308   0  (unused)<br />
usbcore                79680   1  [hid ehci-hcd usb-uhci]<br />
ext3                   92840   5<br />
jbd                    54056   5  [ext3]<br />
cciss                  70432  12<br />
sd_mod                 14128   0  (unused)<br />
scsi_mod              118312   2  [sg cciss sd_mod]<br />
</code></p>
<p>When Check Point is referring to the firewall kernel, they&#8217;re actually talking about this linux kernel modules.</p>
<p>The Check Point kernel itself is composed of several modules, which can be shown using the <code>fw ctl debug -h</code> command.</p>
<p>In NGX we had the following:</p>
<ul>
<li>fw &#8220;Firewall Module&#8221;</li>
<li>VPN &#8220;VPN Module&#8221;</li>
<li>FG-1 &#8220;Floodgate-1 QoS Module&#8221;</li>
<li>H323 &#8220;VoIP H.323 Module&#8221;</li>
<li>BOA &#8220;Malicious Code Protection Module&#8221;</li>
<li>WS &#8220;SmartDefense Web Intelligence Module&#8221;</li>
<li>CPAS &#8220;Active Streaming Module&#8221;</li>
<li>CLUSTER &#8220;ClusterXL Module&#8221;</li>
<li>RTM &#8220;SmartView Monitor Module&#8221;</li>
</ul>
<p>Now with R70 and Software Blades, we have some more kernel modules:</p>
<ul>
<li>kiss ???</li>
<li>kissflow ???</li>
<li>multik ???</li>
<li>SFT ???</li>
<li>CI ???</li>
<li>fw &#8220;Firewall Module&#8221;</li>
<li>VPN &#8220;VPN Module&#8221;</li>
<li>FG-1 &#8220;Floodgate-1 QoS Module&#8221;</li>
<li>H323 &#8220;VoIP H.323 Module&#8221;</li>
<li>BOA &#8220;Malicious Code Protection Module&#8221;</li>
<li>WS &#8220;SmartDefense Web Intelligence Module&#8221;</li>
<li>CPAS &#8220;Active Streaming Module&#8221;</li>
<li>CLUSTER &#8220;ClusterXL Module&#8221;</li>
<li>RTM &#8220;SmartView Monitor Module&#8221;</li>
</ul>
<p>In the moment I have not found any reference for the new modules, no explanation of the modules itself or the modul kernel debugging options.</p>
<p>I opened a service request with Check Point to get this information. </p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/new-kernel-modules-starting-with-r70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>code generator for fw monitor and tcpdump</title>
		<link>http://blog.lachmann.org/2010/08/code-generator-for-fw-monitor-and-tcpdump/</link>
		<comments>http://blog.lachmann.org/2010/08/code-generator-for-fw-monitor-and-tcpdump/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 09:01:16 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=487</guid>
		<description><![CDATA[Joost de Cock has a PHP application running on this site which allows you to easily create INSPECT code to use with the fw monitor command or an equivalent expressions to use with tcpdump. A very handy tool, try it! Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>Joost de Cock has a PHP application running on this <a href="http://decock.org/ginspect/">site </a> which allows you to easily create INSPECT code to use with the fw monitor command or an equivalent expressions to use with tcpdump.</p>
<p>A very handy tool, try it!</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/code-generator-for-fw-monitor-and-tcpdump/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Determine current Antivirus version</title>
		<link>http://blog.lachmann.org/2010/08/determine-current-antivirus-version/</link>
		<comments>http://blog.lachmann.org/2010/08/determine-current-antivirus-version/#comments</comments>
		<pubDate>Fri, 20 Aug 2010 14:19:05 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Content Inspection]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=483</guid>
		<description><![CDATA[We&#8217;ve seen problems with updating the AntiVirus patterns in the past on UTM-1 appliances. Somehow the reported version numbers seemed wrong. But where to check what&#8217;s the current version? Easy answer to that: http://sigcheck.checkpoint.com/Siglist2.txt Compare your version from SmartView Monitor or avsu_client to the version you see on the above page. Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve seen problems with updating the AntiVirus patterns in the past on UTM-1 appliances.<br />
Somehow the reported version numbers seemed wrong.</p>
<p>But where to check what&#8217;s the current version?</p>
<p>Easy answer to that:<br />
<code>http://sigcheck.checkpoint.com/Siglist2.txt </code></p>
<p>Compare your version from SmartView Monitor or <code>avsu_client </code>to the version you see on the above page.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/determine-current-antivirus-version/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DLP again</title>
		<link>http://blog.lachmann.org/2010/08/dlp-again/</link>
		<comments>http://blog.lachmann.org/2010/08/dlp-again/#comments</comments>
		<pubDate>Fri, 20 Aug 2010 12:53:06 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Data Loss Prevention]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=480</guid>
		<description><![CDATA[Well, some thoughts about DLP were in my mind for some time and I want to write them down. First, DLP is about unintentional data loss. There are always ways to get data out of a secure area, if it&#8217;s by USB drives, HTTPS upload, CD-Rs, steganography or what so ever. It&#8217;s nearly impossible to [...]]]></description>
			<content:encoded><![CDATA[<p>Well, some thoughts about DLP were in my mind for some time and I want to write them down.</p>
<p>First, DLP is about unintentional data loss. There are always ways to get data out of a secure area, if it&#8217;s by USB drives, HTTPS upload, CD-Rs, steganography or what so ever. It&#8217;s nearly impossible to prevent data leaks completely.</p>
<p>But that&#8217;s not what DLP is aiming for&#8230; it&#8217;s for the user that accidental chooses the wrong email-adress or picks the wrong file for uploading on a website. And for that purpose, it&#8217;s totally sufficient.</p>
<p>The underlaying engine which does the processing is amazing and you can do all kinds of stuff with the data types. For most of your requirements Check Point brings build-in datatypes, if it&#8217;s credit card numbers or social security numbers.</p>
<p>Second: the hard part with DLP is to define a company policy and a list of data that should not leave the company. This is were technical and organizational security meet and the biggest challenge.</p>
<p>Concerning the DLP-1 appliances that I mentioned before, I have some information about the hardware.</p>
<p>The DLP-1 2571 has Dual Core CPU, 4 GB RAM and 500 GB HDD, so it&#8217;s pretty much a UTM-1 3070 series appliance with more memory and HDD.</p>
<p>The DLP-1 9571 is based on the Power-1 9075 and comes with 2x QuadCore CPU, 8 GB RAM and 2x 1 TB HDD.</p>
<p>Internal Check Point sources say that by now it&#8217;s safe to assume that for real live traffic you have to divide the performance numbers by 4. This will change with the next releases that improve performance.</p>
<p>If you haven&#8217;t noticed, DLP-1 appliances come with UserDirectory blade to allow easy connectivity to Activce Directory domains or LDAP directories.</p>
<p>DLP-1 will be able to scan also HTTPS traffic in the near future (Q1/11) and I&#8217;m really looking forward to that feature.</p>
<p>If someone has solid hands-on experience with a DLP implementation, please share them with me: blog@lachmann.org</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/dlp-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Check Point Series 80 Appliance</title>
		<link>http://blog.lachmann.org/2010/08/new-check-point-series-80-appliance/</link>
		<comments>http://blog.lachmann.org/2010/08/new-check-point-series-80-appliance/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 15:26:05 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Appliance]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=470</guid>
		<description><![CDATA[Check Point released a new appliance, the SG80 or Series 80 appliance. It is aimed for branch offices and it is positioned between UTM-1 appliances and UTM-1 Edge appliances. Performance-wise it is very close to the bigger UTM-1 appliances, if we can trust die datasheets. The specs are: Firewall Throughput 1500 Mbps VPN Throughput 220 [...]]]></description>
			<content:encoded><![CDATA[<p>Check Point released a new appliance, the SG80 or Series 80 appliance.<br />
It is aimed for branch offices and it is positioned between UTM-1 appliances and UTM-1 Edge appliances.<br />
Performance-wise it is very close to the bigger UTM-1 appliances, if we can trust die datasheets.<br />
The specs are:</p>
<ul>
<li>Firewall Throughput 1500 Mbps </li>
<li>VPN Throughput 220 Mbps </li>
<li>IPS Throughput 720 Mbps </li>
<li>AV Throughput 100 Mbps </li>
</ul>
<p>Since I measured only 20 Mbps AV scanning throughput with R71 on a UTM-1 270 appliance, I don&#8217;t trust this figures for real rule bases and real live traffic. But anyway, at least good enough for comparison to other Check Point appliances.</p>
<p>The management of this gateway has to be done over a Security Management server of Provider-1, it is not self-managed unlike UTM-1 appliances.</p>
<p>The desktop form factor is quite nice, I&#8217;m just wondering about the cooling. The UTM-1 130 appliances use passive cooling, too, and can get pretty hot sometimes.</p>
<p>What&#8217;s nice for smaller offices are the build-in 8 LAN ports with GigabitEthernet, so under some circumstances you can eliminate an additional switch in the office. The SG80 has one additional Gigabit WAN port and a Gigabit DMZ port.</p>
<p>As for now I have no info about the hardware in this appliance, nor the operating system. But I think that it is SPLAT based, deriving from the feature set.</p>
<p>The SG80 is comparably low cost for the performance, as it starts at $2500,&#8211;</p>
<p>At the moment this appliance can only be configured over the R70.40 version management / SmartConsole.</p>
<p>The wizard is a little bit different than for normal gateways, but very straight forward.<br />
They changed the SIC handling here. At creation of the object in SmartDashboard you enter a secret and you can install the policy for this device.<br />
But SIC is not established right away, but status of this object is &#8216;waiting&#8217;.<br />
The administrator in the remote office can install the appliance later and connect to the Security Management with this secret, establishing SIC completely.<br />
It&#8217;s a mixture of handling normal gateways and Edge appliances and very nice.<br />
Also the most needed configuration option can be chosen when creating the SG80 object using the wizard.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard1.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard1.jpg" alt="SG80 wizard" title="SG80 wizard" width="450" height="294" class="alignnone size-full wp-image-471" /></a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard2.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard2.jpg" alt="SG80 wizard" title="SG80 wizard" width="450" height="294" class="alignnone size-full wp-image-471" /></a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard3.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard3.jpg" alt="SG80 wizard" title="SG80 wizard" width="450" height="294" class="alignnone size-full wp-image-471" /></a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard4.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard4.jpg" alt="SG80 wizard" title="SG80 wizard" width="450" height="294" class="alignnone size-full wp-image-471" /></a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard5.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard5.jpg" alt="SG80 wizard" title="SG80 wizard" width="450" height="294" class="alignnone size-full wp-image-471" /></a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard6.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/08/wizard6.jpg" alt="SG80 wizard" title="SG80 wizard" width="450" height="294" class="alignnone size-full wp-image-471" /></a></p>
<p>All in all it&#8217;s a very nice approach with this new appliance and I can&#8217;t wait to get my hand on one of this boxes to test it.</p>
<p>If you had the possibility to test one, please send your findings to blog@lachmann.org</p>
<p>Tobias Lachmann</p>
<p><strong>UPDATE: The SG80 runs Secure Platform Embedded as operating system. Sounds like a striped down version of SPLAT to me.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/new-check-point-series-80-appliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>R70.40 released &#8211; use with care</title>
		<link>http://blog.lachmann.org/2010/08/r70-40-released-use-with-care/</link>
		<comments>http://blog.lachmann.org/2010/08/r70-40-released-use-with-care/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 12:39:56 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=467</guid>
		<description><![CDATA[Yesterday Check Point released R70.40 with some modifications for the new UTM-1 Edge N series and die Security Gateway 80 series, support for Embedded NGX 8.1 firmware, provisioning for IPSO 6.2 and enchanced vsx_util. We have some improvements here, judging by the resolved issues. This release is also the first one to handle SG80 gateways. [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday Check Point released R70.40 with some modifications for the new UTM-1 Edge N series and die Security Gateway 80 series, support for Embedded NGX 8.1 firmware, provisioning for IPSO 6.2 and enchanced vsx_util.</p>
<p>We have some improvements here, judging by the <a href="http://supportcontent.checkpoint.com/solutions?id=sk44991">resolved issues</a>.</p>
<p>This release is also the first one to handle SG80 gateways. </p>
<p>But, as the <a href="http://supportcontent.checkpoint.com/documentation_download?ID=10770">Release Notes </a>state, the R70.40 cannot be upgraded to R71. You first have to uninstall it before upgrading. This is not very handy, so I would suggest to upgrade directly to R71.10 and wait for the upcoming R71.20 release, which should also contain the fixes and enhancements.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/r70-40-released-use-with-care/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disabling Anti-Spoofing</title>
		<link>http://blog.lachmann.org/2010/08/disabling-anti-spoofing/</link>
		<comments>http://blog.lachmann.org/2010/08/disabling-anti-spoofing/#comments</comments>
		<pubDate>Wed, 18 Aug 2010 12:16:54 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=465</guid>
		<description><![CDATA[When you want to disable Anti-Spoofing on a whole gateway you can use a specific kernel parameter for this. fw_antispoofing_enabled=0 Please refer to sk26202 for changing kernel global parameters and sk20364 for making them survive a reboot. Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>When you want to disable Anti-Spoofing on a whole gateway you can use a specific kernel parameter for this.</p>
<p><code>fw_antispoofing_enabled=0</code></p>
<p>Please refer to <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk26202">sk26202 </a>for changing kernel global parameters and <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk20364">sk20364 </a>for making them survive a reboot.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/disabling-anti-spoofing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Manual failover between ClusterXL members</title>
		<link>http://blog.lachmann.org/2010/08/manual-failover-between-clusterxl-members/</link>
		<comments>http://blog.lachmann.org/2010/08/manual-failover-between-clusterxl-members/#comments</comments>
		<pubDate>Tue, 17 Aug 2010 15:36:10 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[ClusterXL]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=460</guid>
		<description><![CDATA[A Check Point security gateway cluster running under ClusterXL uses certain devices that must be running on the cluster member for the member to be considered active. The devices can be displayed using cphaprob -ia list. A normal ouput will look like this: [Expert@firewall]# cphaprob -ia list Built-in Devices: Device Name: Problem Notification Current state: [...]]]></description>
			<content:encoded><![CDATA[<p>A Check Point security gateway cluster running under ClusterXL uses certain devices that must be running on the cluster member for the member to be considered active.</p>
<p>The devices can be displayed using <code>cphaprob -ia list</code>. A normal ouput will look like this:</p>
<p><code>[Expert@firewall]# cphaprob -ia list</p>
<p>Built-in Devices:</p>
<p>Device Name: Problem Notification<br />
Current state: OK</p>
<p>Device Name: Interface Active Check<br />
Current state: OK</p>
<p>Device Name: HA Initialization<br />
Current state: OK</p>
<p>Device Name: Load Balancing Configuration<br />
Current state: OK</p>
<p>Registered Devices:</p>
<p>Device Name: Synchronization<br />
Registration number: 0<br />
Timeout: none<br />
Current state: OK<br />
Time since last report: 13212.1 sec</p>
<p>Device Name: Filter<br />
Registration number: 1<br />
Timeout: none<br />
Current state: OK<br />
Time since last report: 13201.4 sec</p>
<p>Device Name: cphad<br />
Registration number: 2<br />
Timeout: 2 sec<br />
Current state: OK<br />
Time since last report: 0.1 sec</p>
<p>Device Name: fwd<br />
Registration number: 3<br />
Timeout: 2 sec<br />
Current state: OK<br />
Time since last report: 0.1 sec</code></p>
<p>If one or more of the devices have a problem, ClusterXL will do a failover from the active member to the standby member. This is only true as long as the second member has no problem itself. If this is happening, the cluster mechanism decides by its own which is the more suitable machine to handle the traffic and will or will not do a failover.</p>
<p>Failover will also occur if the issue <code>cpstop </code>or <code>cphastop </code>on the active member, stopping all Check Point services or just the ClusterXL related service.</p>
<p>For the purpose of maintenance it can be necessary to move away all the traffic from the active member to the secondary member through initiating a failover, leaving the security policy and services active on the machine.</p>
<p>This can be done by registering a new device and adding it to the list of the processes that must be running for the cluster member to be considered active and putting the new device in the problem state.</p>
<p>Use this command line: <code>cphaprob -d STOP -s problem -t 0 register</code></p>
<p>If you want to unregister the problematic device and make the cluster member available and active again, just use this: <code>cphaprob -d STOP unregister</code>.</p>
<p>Learn more about the usage of <code>cphaprob </code>from the CLI manual.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/manual-failover-between-clusterxl-members/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Determine version of Anti Virus</title>
		<link>http://blog.lachmann.org/2010/08/determine-version-of-anti-virus/</link>
		<comments>http://blog.lachmann.org/2010/08/determine-version-of-anti-virus/#comments</comments>
		<pubDate>Tue, 17 Aug 2010 15:20:30 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Content Inspection]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=458</guid>
		<description><![CDATA[All applications like SmartView Monitor get the information about the Anti Virus version running on the Security Gateway by reading the following file $FWDIR/av/ca/update/incoming/Anti_Virus.entitlement.C Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>All applications like SmartView Monitor get the information about the Anti Virus version running on the Security Gateway by reading the following file <code>$FWDIR/av/ca/update/incoming/Anti_Virus.entitlement.C</code></p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/determine-version-of-anti-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Display errors in SmartView Monitor</title>
		<link>http://blog.lachmann.org/2010/08/display-errors-in-smartview-monitor/</link>
		<comments>http://blog.lachmann.org/2010/08/display-errors-in-smartview-monitor/#comments</comments>
		<pubDate>Tue, 17 Aug 2010 15:17:24 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=453</guid>
		<description><![CDATA[Sometimes SmartView Monitor gets confused and it displaying wrong (cached) information. To clear this up you do the following: - issue cpstop on the Security Management server - delete $FWDIR/conf/applications.C, $FWDIR/conf/applications.C.backup, $FWDIR/conf/CPMILinksMgr.db and $FWDIR/conf/CPMILinksMgr.db.private - issue cpstart - install policy again - open SmartView Monitor again Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>Sometimes SmartView Monitor gets confused and it displaying wrong (cached) information.</p>
<p>To clear this up you do the following:</p>
<p>- issue <code>cpstop </code>on the Security Management server<br />
- delete <code>$FWDIR/conf/applications.C</code>,<br />
 <code>$FWDIR/conf/applications.C.backup</code>,<br />
<code>$FWDIR/conf/CPMILinksMgr.db </code><br />
and <code>$FWDIR/conf/CPMILinksMgr.db.private</code><br />
- issue <code>cpstart</code><br />
- install policy again<br />
- open SmartView Monitor again</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/display-errors-in-smartview-monitor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Appliance hardware &#8211; updated</title>
		<link>http://blog.lachmann.org/2010/08/appliance-hardware-updated/</link>
		<comments>http://blog.lachmann.org/2010/08/appliance-hardware-updated/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 19:08:51 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[OpenServer]]></category>
		<category><![CDATA[Power-1]]></category>
		<category><![CDATA[Smart-1]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=447</guid>
		<description><![CDATA[Here is a short list of the hardware used in UTM-1 / Power-1 / Smart-1 appliances. The details can be determined from the command line. For the CPU details use cat /proc/cpuinfo, for the RAM details use cat /proc/meminfo. If you have more details on appliances, feel free to send them to blog@lachmann.org All throughput [...]]]></description>
			<content:encoded><![CDATA[<p>Here is a short list of the hardware used in UTM-1 / Power-1 / Smart-1 appliances. </p>
<p>The details can be determined from the command line.</p>
<p>For the CPU details use <code>cat /proc/cpuinfo</code>, for the RAM details use <code>cat /proc/meminfo</code>.</p>
<p>If you have more details on appliances, feel free to send them to blog@lachmann.org</p>
<p>All throughput values are taken from official Check Point materials.</p>
<p>If you take the appliance hardware together with the <a href="http://www.checkpoint.com/products/downloads/appliances/appliance-comparison-chart.pdf">throughput stated by Check Point</a>, it might give you an idea how your OpenServer hardware will perform in comparison.</p>
<p>Have a close look of the throughput values of the UTM-1 450 in comparison to the UTM-1 570. The processor power is identical, also the memory. But the throughput values for the UTM-1 450 were measured with NGX R65, the values for the UTM-1 570 were measured with R71. See what a performance boost R71 can be, even on the &#8220;old&#8221; hardware. Sweet!</p>
<p><strong>UTM-1 130 </strong></p>
<ul>
<li>Intel Celeron M 600 MHz </li>
<li>1 GB RAM </li>
<li>80 GB ATA HDD</li>
<li>Firewall Throughput: 1.5 Gbps </li>
<li>VPN Throughput: 120 Mbps</li>
<li>IPS Troughput: 1.0 Gbps</li>
</ul>
<p><strong>UTM-1 270 </strong></p>
<ul>
<li>Intel Celeron M 600 MHz </li>
<li>1 GB DDR2 RAM 400 MHz </li>
<li>160 GB ATA HDD</li>
<li>Firewall Throughput: 1.5 Gbps </li>
<li>VPN Throughput: 120 Mbps</li>
<li>IPS Troughput: 1.0 Gbps</li>
</ul>
<p><strong>UTM-1 450 </strong></p>
<ul>
<li>Intel Celeron M 1.5 GHz </li>
<li>1 GB RAM </li>
<li>80 GB ATA HDD</li>
<li>Firewall Throughput (R65): 400 Mbps </li>
<li>VPN Throughput: (R65) 200 Mbps</li>
</ul>
<p><strong>UTM-1 570 </strong></p>
<ul>
<li>Intel Celeron M 1.5 GHz </li>
<li>1 GB RAM </li>
<li>160 GB ATA HDD </li>
<li>Firewall Throughput: 2.5 Gbps </li>
<li>VPN Throughput: 300 Mbps</li>
<li>IPS Troughput: 1.7 Gbps</li>
</ul>
<p><strong>UTM-1 1070 </strong></p>
<ul>
<li>Intel Celeron M 1.5 GHz </li>
<li>1 GB RAM </li>
<li>160 GB ATA HDD </li>
<li>Firewall Throughput: 3 Gbps </li>
<li>VPN Throughput: 350 Mbps</li>
<li>IPS Troughput: 2.2 Gbps</li>
</ul>
<p><strong>UTM-1 2050 </strong></p>
<ul>
<li>Intel Pentium 4 3.4 GHz </li>
<li>2 GB RAM </li>
<li>80 GB ATA HDD </li>
<li>Firewall Throughput (R65): 2.4 Gbps </li>
<li>VPN Throughput: (R65) 380 Mbps</li>
</ul>
<p><strong>UTM-1 2070 </strong></p>
<ul>
<li>Intel Celeron 440 2.00GHz</li>
<li>2 GB RAM </li>
<li>160 GB ATA HDD </li>
<li>Firewall Throughput: 3.5 Gbps </li>
<li>VPN Throughput: 450 Mbps</li>
<li>IPS Troughput: 2.7 Gbps</li>
</ul>
<p><strong>UTM-1 3070 </strong></p>
<ul>
<li>Intel Core2 Duo E6400 2.13GHz</li>
<li>3 GB RAM </li>
<li>160 GB ATA HDD </li>
<li>Firewall Throughput: 4.5 Gbps </li>
<li>VPN Throughput: 1100 Mbps</li>
<li>IPS Troughput: 4.0 Gbps</li>
</ul>
<p><strong>Power-1 5075 </strong></p>
<ul>
<li>Intel Xeon E5410 2.33GHz (QC)</li>
<li>2 GB RAM </li>
<li>160 GB ATA HDD </li>
<li>Firewall Throughput: 9.0 Gbps </li>
<li>VPN Throughput: 2.4 Gbps</li>
<li>IPS Troughput: 7.5 Gbps</li>
</ul>
<p><strong>Power-1 9075 </strong></p>
<ul>
<li>2x Intel Xeon E5410 2.33GHz (QC)</li>
<li>4 GB RAM </li>
<li>2x 160 GB HDD </li>
<li>Firewall Throughput: 9.0 Gbps </li>
<li>VPN Throughput: 2.4 Gbps</li>
<li>IPS Troughput: 7.5 Gbps</li>
</ul>
<p><strong>Smart-1 25 </strong></p>
<ul>
<li>Intel Core2 Duo T7400 2.16GHz</li>
<li>3 GB RAM </li>
<li>4x 500 GB SATA HDD in RAID 10</li>
</ul>
<p>Thanks to all the contributors for their info!</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/appliance-hardware-updated/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rumors, rumors&#8230;.</title>
		<link>http://blog.lachmann.org/2010/08/rumors-rumors/</link>
		<comments>http://blog.lachmann.org/2010/08/rumors-rumors/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 18:51:05 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=444</guid>
		<description><![CDATA[I heard some rumors recently that I&#8217;d like to share with you. True or not, nobody can tell. But sure interesting First, we can expect R75 GA by the end of the year. No idea what will be included, but maybe we see more improvements from software blades. As Dorit Dor stated some time ago, [...]]]></description>
			<content:encoded><![CDATA[<p>I heard some rumors recently that I&#8217;d like to share with you. True or not, nobody can tell. But sure interesting <img src='http://blog.lachmann.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>First, we can expect R75 GA by the end of the year. No idea what will be included, but maybe we see more improvements from software blades. As Dorit Dor stated some time ago, the introduction of software blades with R70 was the first step in a three-step-approach of a complete architecture re-design within the Check Point products. So personally I think that every new GA release will bring us closer to the goal and will give us additional performance and/or more features.</p>
<p>Second, Check Point seems to plan the content inspection of HTTPS traffic, availability should be around end of Q1/2011. This is a very interesting feature and I&#8217;m really locking forward to it. We had lot&#8217;s of projects where the customer choose not to use Check Point content scanning but rather a solution like WebWasher, which could inspect also SSL encrypted traffic. I wonder how the handling will be done in detail and how easy the setup will be in comparison with WebWasher etc.</p>
<p>That&#8217;s all for now. Wait and see, if these rumors have a valid background.</p>
<p>If you know more details, please do not hesitate and write an email to blog@lachmann.org</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/rumors-rumors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Behaviour of Data Loss Prevention</title>
		<link>http://blog.lachmann.org/2010/08/behaviour-of-data-loss-prevention/</link>
		<comments>http://blog.lachmann.org/2010/08/behaviour-of-data-loss-prevention/#comments</comments>
		<pubDate>Thu, 05 Aug 2010 12:15:00 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Data Loss Prevention]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=440</guid>
		<description><![CDATA[Mmmh&#8230;. the DLP software acts as a proxy between internal mail server and external mail server. It accepts the mail from the internal system and in the same time sends the data out to the external system besides the last package to complete the mail. When the mail is received by the DLP gateway from [...]]]></description>
			<content:encoded><![CDATA[<p>Mmmh&#8230;. the DLP software acts as a proxy between internal mail server and external mail server.</p>
<p>It accepts the mail from the internal system and in the same time sends the data out to the external system besides the last package to complete the mail. When the mail is received by the DLP gateway from the internal server completely, it is scanned for compliance to the DLP policy and if the check is ok, the last packet is transmitted to the external mail server, finishing mail delivery. </p>
<p>If the check is not ok, the last packet is withheld and the gateway shuts down the connection to the external mail server. So basically the mail has left the company, but because of the interrupted transfer, the external mail server is discarding the temp mail that has been deliverd by now.</p>
<p>I&#8217;m not sure at the moment that I like this behaviour&#8230; I&#8217;m thinking about better ways to handle this&#8230;. not finished thinking it through by now&#8230;. will let you know my thougts.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/08/behaviour-of-data-loss-prevention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure Client for Mac OS 10.6 (Snow Leopard) available</title>
		<link>http://blog.lachmann.org/2010/07/secure-client-for-mac-os-10-6-snow-leopard-available/</link>
		<comments>http://blog.lachmann.org/2010/07/secure-client-for-mac-os-10-6-snow-leopard-available/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 08:12:00 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Early Availability]]></category>
		<category><![CDATA[SecureClient]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=438</guid>
		<description><![CDATA[SecureClient NG-AI R56 HFA 2 for Mac OS X 10.6 (Snow Leopard) is now officially available through the Support Portal. I tested the EA versions (Build 8 and 15) and had good results. It&#8217;s sad that it took so long for Check Point to come up with a VPN client for 10.6 and also SNX [...]]]></description>
			<content:encoded><![CDATA[<p>SecureClient NG-AI R56 HFA 2 for Mac OS X 10.6 (Snow Leopard) is now officially available through the Support Portal. I tested the EA versions (Build 8 and 15) and had good results.</p>
<p>It&#8217;s sad that it took so long for Check Point to come up with a VPN client for 10.6 and also SNX support for Snow Leopard is not here at the moment.</p>
<p>Hope they&#8217;ll fix that soon.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/07/secure-client-for-mac-os-10-6-snow-leopard-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UTM-1 1050 and 2050 network problems</title>
		<link>http://blog.lachmann.org/2010/07/utm-1-1050-and-2050-network-problems/</link>
		<comments>http://blog.lachmann.org/2010/07/utm-1-1050-and-2050-network-problems/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 13:28:31 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[R71]]></category>
		<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=435</guid>
		<description><![CDATA[So, what is the problem about? Well, NIC connections stay up for about 1 or 2 minutes, then they&#8217;re down for about 5 minutes. We made an upgrade of an UTM-1 2050 series appliance to R71 and got massive connectivity problems. Two days later sk42174 came out which helped us fix the problem. Seems that [...]]]></description>
			<content:encoded><![CDATA[<p>So, what is the problem about? Well, NIC connections stay up for about 1 or 2 minutes, then they&#8217;re down for about 5 minutes.</p>
<p>We made an upgrade of an UTM-1 2050 series appliance to R71 and got massive connectivity problems. Two days later <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk42174">sk42174 </a>came out which helped us fix the problem. Seems that the Linux Kernel starting with R70 assigns new drivers to the NICs, which are incorrect.<br />
The solution for that problem is to change the settings back to the old driver.</p>
<p>For details please refer to the <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk42174">SK </a>and have it in mind when you&#8217;re updating older appliances.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/07/utm-1-1050-and-2050-network-problems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Back to Chur in September &#8211; CPUGCON 2010</title>
		<link>http://blog.lachmann.org/2010/07/back-to-chur-in-september-cpugcon-2010/</link>
		<comments>http://blog.lachmann.org/2010/07/back-to-chur-in-september-cpugcon-2010/#comments</comments>
		<pubDate>Fri, 16 Jul 2010 12:47:45 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[CPUG]]></category>
		<category><![CDATA[CPUGCON]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=427</guid>
		<description><![CDATA[I will be travelling to the Check Point Usergroup Conference (CPUGCON) in Chur this September! Thanks to my employer MCS for giving me the opportunity. Barry Stiefel accepted my presentations for &#8220;Best Practices For The Check Point Appliances&#8221; and &#8220;Check Point Troubleshooting&#8221; and I&#8217;m happy to speak again in front of such a great audience. [...]]]></description>
			<content:encoded><![CDATA[<p>I will be travelling to the Check Point Usergroup Conference (<a href="http://www.cpugcon.com/">CPUGCON</a>) in Chur this September! </p>
<p><strong>Thanks to my <a href="http://www.mcs.de">employer MCS </a>for giving me the opportunity.</strong></p>
<p>Barry Stiefel accepted my presentations for &#8220;Best Practices For The Check Point Appliances&#8221; and &#8220;Check Point Troubleshooting&#8221; and I&#8217;m happy to speak again in front of such a great audience.</p>
<p>It turned out last year that half of the attendees were working for Check Point partners, so enormous amount of knowledge and experience there. </p>
<p><strong>Make sure to attend, too!</strong></p>
<p>Where else can you meet people like yourself, dealing with the same topics and the same problems? Benefit from their experience and their solutions.</p>
<p>Check out the <a href="http://www.cpugcon.com/technical-sessions.htm">conference presentations </a>(work in progress) and meet the <a href="http://www.cpugcon.com/speakers.htm">speakers</a>.</p>
<p>And please don&#8217;t hesitate to speak to me and share some feedback about this blog when you see me in Chur.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/07/back-to-chur-in-september-cpugcon-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>R71.10 available</title>
		<link>http://blog.lachmann.org/2010/07/r71-10-available/</link>
		<comments>http://blog.lachmann.org/2010/07/r71-10-available/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 09:19:05 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[R71]]></category>
		<category><![CDATA[SSL VPN]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=422</guid>
		<description><![CDATA[The new R71.10 update is available. Find all the resources on this page within UserCenter. We now have Abra support on all gateway platforms, support for Outlook Web Access (OWA) 2010 over SSL VPN and R71.10 includes the hotfix for the SSL VPN blade, that was mandatory when using this blade with R70. Please note [...]]]></description>
			<content:encoded><![CDATA[<p>The new R71.10 update is available. Find all the resources on this <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk50246">page </a> within UserCenter.</p>
<p>We now have Abra support on all gateway platforms, support for Outlook Web Access (OWA) 2010 over SSL VPN and R71.10 includes the hotfix for the SSL VPN blade, that was mandatory when using this blade with R70.</p>
<p>Please note that the R71.10 upgrade package cannot be installed on gateways with DLP.</p>
<p>Check Point also released complete packages for a fresh installation with R71.10 but they sadly don&#8217;t include UTM-1 images.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/07/r71-10-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Proactive detection mode vs. Stream detection mode</title>
		<link>http://blog.lachmann.org/2010/07/proactive-detection-mode-vs-stream-detection-mode/</link>
		<comments>http://blog.lachmann.org/2010/07/proactive-detection-mode-vs-stream-detection-mode/#comments</comments>
		<pubDate>Sun, 11 Jul 2010 10:34:37 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Content Inspection]]></category>
		<category><![CDATA[R71]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=417</guid>
		<description><![CDATA[As I wrote a while ago, we had great performance improvements with Antivirus Scanning and the R71 release. On the same UTM-1 hardware the throughput doubled. While this was true for my lab testing, real world testing didn&#8217;t show the same results. Upgraded systems had no better AV performance and only slightly more overall performance [...]]]></description>
			<content:encoded><![CDATA[<p>As I wrote a while ago, we had great performance improvements with Antivirus Scanning and the R71 release. On the same UTM-1 hardware the throughput doubled. While this was true for my lab testing, real world testing didn&#8217;t show the same results. Upgraded systems had no better AV performance and only slightly more overall performance was showing.</p>
<p>The reason for that is that an upgraded systems keeps the old way of detecting viruses, the Proactive detection mode. In this mode, the traffic is trapped by the kernel and forwarded to the security server. The security server then forwards the traffic to the Antivirus engine and the traffic is allowed or blocked, depending on the response of the Antivirus engine. It is necessary to store the whole file first before scanning it. </p>
<p>The new Stream detection mode doesn&#8217;t need to store the file for scanning. Stream detection is able to scan uncompressed and compressed traffic while it is passing through the gateways kernel, doing decompression on the fly.</p>
<p>Stream detection mode works only signature-based, whereas Proactice detection mode works with Antivirus signatures and in addition with a sandbox where heuristic behaviour scans are done to detect malware, even if there no signature available at the moment.</p>
<p>Stream detection is default on fresh installations, so that&#8217;s why you can see great performance improvement on R71.</p>
<p>The mode can be changed within <code>SmartDasboard -> Antivirus &#038; URL Filtering tab -> Antivirus -> Security Gateway</code> and then choose the desired protocol.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/07/proactive.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/07/proactive.jpg" alt="Configuration of Antivirus detection mode" title="Configuration of Antivirus detection mode" width="500" height="425" class="alignnone size-full wp-image-418" /></a></p>
<p>HTTP and SMTP can work with Stream detection mode and Proactive detection mode, POP3 and FTP only work with Proactive detection mode.</p>
<p>While I appreciate the performance improvement which can be gained using Stream detection mode, I think we lower security a little bit by abstain from using Proactive detection mode. </p>
<p>This decission should be made with careful consideration of the specific setup and customer need. If you use solely Stream detection mode, make sure to have a good Antivirus solution from another vendor running on the end user&#8217;s desktop to double-check for malware.</p>
<p>What do you think about the two Antivirus modes? Mail your thoughts to blog@lachmann.org</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/07/proactive-detection-mode-vs-stream-detection-mode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Database Revision in R71</title>
		<link>http://blog.lachmann.org/2010/07/database-revision-in-r71/</link>
		<comments>http://blog.lachmann.org/2010/07/database-revision-in-r71/#comments</comments>
		<pubDate>Wed, 07 Jul 2010 10:07:05 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=412</guid>
		<description><![CDATA[R71 brings us an improvement in the handling of database revision. Now it is possible to define how long old version should be kept. Criteria can be number of versions, age of versions, storage consumption of versions of free diskspace. I think this is a very nice improvement and worth noticing. Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>R71 brings us an improvement in the handling of database revision.<br />
Now it is possible to define how long old version should be kept.<br />
Criteria can be number of versions, age of versions, storage consumption of versions of free diskspace.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/07/database_revision.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/07/database_revision.jpg" alt="Automatic Deletion of Database Revisions" title="Automatic Deletion of Database Revisions" width="401" height="285" class="alignnone size-full wp-image-413" /></a></p>
<p>I think this is a very nice improvement and worth noticing.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/07/database-revision-in-r71/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online partition resizing on UTM-1 appliances</title>
		<link>http://blog.lachmann.org/2010/06/online-partition-resizing-on-utm-1-appliances/</link>
		<comments>http://blog.lachmann.org/2010/06/online-partition-resizing-on-utm-1-appliances/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 13:21:19 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=406</guid>
		<description><![CDATA[Under SPLAT with 2.4 linux kernel (NGX R65) you had to follow a slightly complicated procedure to resize the partitions and the filesystems on an UTM-1 appliance. Now the R7x releases bring us the 2.6 kernel with lots of improvements. A very nice one it the ability to resize (meaning increase!) the partitions and filesystems [...]]]></description>
			<content:encoded><![CDATA[<p>Under SPLAT with 2.4 linux kernel (NGX R65) you had to follow a <a href="http://blog.lachmann.org/2010/06/update-to-r71-enlarging-utm-1-appliance-root-partitions/">slightly complicated procedure </a>to resize the partitions and the filesystems on an UTM-1 appliance.</p>
<p>Now the R7x releases bring us the 2.6 kernel with lots of improvements. A very nice one it the ability to resize (meaning increase!) the partitions and filesystems online, without the need of unmounting them.</p>
<p><code>[Expert@volvo]#<strong> lvresize -L 12GB vg_splat/lv_current</strong><br />
  Extending logical volume lv_current to 12.00 GB<br />
  Logical volume lv_current successfully resized</p>
<p>[Expert@volvo]# <strong>resize2fs /dev/mapper/vg_splat-lv_current</strong><br />
resize2fs 1.39 (29-May-2006)<br />
Filesystem at /dev/mapper/vg_splat-lv_current is mounted on /; on-line resizing required<br />
Performing an on-line resize of /dev/mapper/vg_splat-lv_current to 3145728 (4k) blocks.<br />
The filesystem on /dev/mapper/vg_splat-lv_current is now 3145728 blocks long.</code></p>
<p>Please note: this can only be done while increasing the filesystems. Reducing the filesystems requires them to be unmounted! </p>
<p>In that case go with <a href="http://blog.lachmann.org/2010/06/update-to-r71-enlarging-utm-1-appliance-root-partitions/">this procedure</a>.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/06/online-partition-resizing-on-utm-1-appliances/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Control UTM-1 Edge appliances from command line</title>
		<link>http://blog.lachmann.org/2010/06/control-utm-1-edge-appliances-from-command-line/</link>
		<comments>http://blog.lachmann.org/2010/06/control-utm-1-edge-appliances-from-command-line/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 12:13:38 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[UTM-1 Edge]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=398</guid>
		<description><![CDATA[The Edge gets its policy from the SmartCenter server over the SofaWare Management Server process (sms). The interval of pulling the policy is defined over Global Properties -> UTM-1 Edge Gateway -> Update configuration settings every XX minutes If you want to update an Edge immideately, you can do this be using the WebUI (access [...]]]></description>
			<content:encoded><![CDATA[<p>The Edge gets its policy from the SmartCenter server over the SofaWare Management Server process (sms).</p>
<p>The interval of pulling the policy is defined over Global Properties -> UTM-1 Edge Gateway -> Update configuration settings every XX minutes</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/06/gp_sms.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/06/gp_sms.jpg" alt="Global Properties for UTM-1 Edge appliances" title="Global Properties for UTM-1 Edge appliances" width="500" height="176" class="alignnone size-full wp-image-399" /></a></p>
<p>If you want to update an Edge immideately, you can do this be using the WebUI (access your SmartCenter over http://<ip>:9283/) or you can use the command line.</p>
<p>The directory <code>/opt/CPEdgecmp-R7<strong>x</strong>/bin </code>contains the tool <code>swcmd</code> which can be used to issue commands directly to the Edge appliance.</p>
<p><code>swcmd UpdateNowAll </code>will tell the Edges to update their policy immediately. </p>
<p><code>swcmd Reboot <GatewayName></code> will reboot the gateway.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/06/control-utm-1-edge-appliances-from-command-line/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Certificate Signing Request (CSR) key size</title>
		<link>http://blog.lachmann.org/2010/06/certificate-signing-request-csr-key-size/</link>
		<comments>http://blog.lachmann.org/2010/06/certificate-signing-request-csr-key-size/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 12:06:19 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[SSL VPN]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=392</guid>
		<description><![CDATA[In a recent blog entry I described how you can use 3rd party certificates within your Check Point gateway. Now I was informed by Brian that some commercial CA don&#8217;t sign any longer if the key size is only 1024 bit, you need at least 2048 bit. How can we change the behaviour of the [...]]]></description>
			<content:encoded><![CDATA[<p>In a <a href="http://blog.lachmann.org/2010/06/using-3rd-party-certificates-for-your-ssl-vpn/">recent blog entry </a>I described how you can use 3rd party certificates within your Check Point gateway.</p>
<p>Now I was informed by Brian that some commercial CA don&#8217;t sign any longer if the key size is only 1024 bit, you need at least 2048 bit.</p>
<p>How can we change the behaviour of the Check Point while issuing the CSR?</p>
<p>Just go to<code> Global Properties -> SmartDashboard Customination -> Configure -> Certificates and PKI properties</code>.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/06/csr1.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/06/csr1.jpg" alt="Global Properties -&gt; SmartDashboard Customization" title="Global Properties -&gt; SmartDashboard Customization" width="500" height="479" class="alignnone size-full wp-image-393" /></a></p>
<p>There we have an option the define the key size for the certificates. Available values are 1024, 2048 and 4096 bit.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/06/csr2.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/06/csr2.jpg" alt="Certificate and PKI properties" title="Certificate and PKI properties" width="500" height="592" class="alignnone size-full wp-image-394" /></a></p>
<p>Change this value according to your need and the requirements of the CA you chose for signing.</p>
<p>Starting with R71 they standard key size 2048.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/06/certificate-signing-request-csr-key-size/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update to R71 &#8211; enlarging UTM-1 appliance root partitions</title>
		<link>http://blog.lachmann.org/2010/06/update-to-r71-enlarging-utm-1-appliance-root-partitions/</link>
		<comments>http://blog.lachmann.org/2010/06/update-to-r71-enlarging-utm-1-appliance-root-partitions/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 14:05:57 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=386</guid>
		<description><![CDATA[In one of my previous blog entries I described a way to enlarge partitions of UTM-1 appliances. This was necessary especially for the older x50 series appliances, as they had a smaller hard drive and a bad partition layout. In the past I only enlarged the partition that held the log files because that&#8217;s were [...]]]></description>
			<content:encoded><![CDATA[<p>In one of my previous <a href="http://blog.lachmann.org/2010/01/enlarging-utm-1-partitions/">blog entries </a>I described a way to enlarge partitions of UTM-1 appliances. This was necessary especially for the older x50 series appliances, as they had a smaller hard drive and a bad partition layout.</p>
<p>In the past I only enlarged the partition that held the log files because that&#8217;s were you have the most data. The procedure was working just fine and I was happy.</p>
<p>A couple of days ago I started updating x50 series appliances from R65 to R71. Even with cleaning up the system of unused files right before the update I got into serious trouble. The cause was that the root partition was nearly about full. </p>
<p>The update process itself came up with no error, but while operating the appliance the root partition was completely full in no time. Especially updating the URL Filterung database, which is now about 370MB, filled the root partition quickly.</p>
<p>When I tried enlarging the root partition with the described procedure I failed.</p>
<p>Resizing requires to unmount the partition before &#8211; but you can&#8217;t unmount the root partition.</p>
<p>So I had to find another way to modify the partition sizes of the appliance.</p>
<p>Here&#8217;s what I did:</p>
<p>I downloaded an ISO-Image of <a href="http://grml.org">grml</a>, a Linux Live system for sysadmins. Then I modified the ISO to display output on the serial console. You can download this <a href="http://blog.lachmann.org/modified_GRML2010.04.iso">modified ISO </a>here.</p>
<p>I connected an USB-DVD-Drive to the appliance and booted the ISO image.</p>
<p>On the boot screen I added some parameters for the startup process:</p>
<p><code>Some information and boot options available via keys F2 - F10. http://grml.org/<br />
grml 2010.04 - Release Codename Grmlmonster                          2010.04.29<br />
boot:<strong> serial debug=noscreen lang=de lvm</strong></code></p>
<p>When grml was finished, it gave me a console with all the needed tools. LVM was loaded already and I was good to go.</p>
<p>I checked for the volume groups on the hard drive with the <code>vgscan </code>command:</p>
<p><code>root@grml ~ # vgscan -v<br />
    Wiping cache of LVM-capable devices<br />
    Wiping internal VG cache<br />
  Reading all physical volumes.  This may take a while...<br />
    Finding all volume groups<br />
    Finding volume group "vg_splat"<br />
  Found volume group "vg_splat" using metadata type lvm2</code></p>
<p>Then I activated the logical volumes with <code>vgchange</code>:</p>
<p><code>root@grml ~ # vgchange -a y<br />
  6 logical volume(s) in volume group "vg_splat" now active</code></p>
<p>You can display the volume group with <code>vgdisplay</code>:</p>
<p><code>root@grml ~ # vgdisplay<br />
  --- Volume group ---<br />
  VG Name               vg_splat<br />
  System ID<br />
  Format                lvm2<br />
  Metadata Areas        1<br />
  Metadata Sequence No  7<br />
  VG Access             read/write<br />
  VG Status             resizable<br />
  MAX LV                255<br />
  Cur LV                6<br />
  Open LV               0<br />
  Max PV                255<br />
  Cur PV                1<br />
  Act PV                1<br />
  VG Size               72.47 GiB<br />
  PE Size               4.00 MiB<br />
  Total PE              18553<br />
  Alloc PE / Size       7424 / 29.00 GiB<br />
  Free  PE / Size       11129 / 43.47 GiB<br />
  VG UUID               dCQA6u-z70X-LIsE-Xhmb-n5ho-ZMrX-JyBePy</code></p>
<p>You can display the logical volumes with <code>lvscan</code>:</p>
<p><code>root@grml ~ # lvscan<br />
  ACTIVE            '/dev/vg_splat/lv_current' [5.00 GiB] inherit<br />
  ACTIVE            '/dev/vg_splat/lv_log' [10.00 GiB] inherit<br />
  ACTIVE            '/dev/vg_splat/lv_hfa' [5.00 GiB] inherit<br />
  ACTIVE            '/dev/vg_splat/lv_upgrade' [5.00 GiB] inherit<br />
  ACTIVE            '/dev/vg_splat/lv_fcd' [2.00 GiB] inherit<br />
  ACTIVE            '/dev/vg_splat/lv_fcd62' [2.00 GiB] inherit</code></p>
<p>Then I did the resizing of the volumes groups to better values:</p>
<p><code>root@grml ~ # lvresize -L 11GB /dev/vg_splat/lv_current<br />
  Extending logical volume lv_current to 11.00 GiB<br />
  Logical volume lv_current successfully resized</p>
<p>root@grml ~ # lvresize -L 25G /dev/vg_splat/lv_log<br />
  Extending logical volume lv_log to 25.00 GiB<br />
  Logical volume lv_log successfully resized</code><br />
Keep in mind that you will need some free space for imaging purposes, so don&#8217;t use up all the space on the hard drive!</p>
<p>Then a file system check has to be done, followed by the resizing of the file system.</p>
<p><code>root@grml ~ # e2fsck -f /dev/vg_splat/lv_current<br />
e2fsck 1.41.11 (14-Mar-2010)<br />
Superblock last mount time is in the future.<br />
        (by less than a day, probably due to the hardware clock being incorrectly set)  Fix<y>? yes</p>
<p>Pass 1: Checking inodes, blocks, and sizes<br />
Pass 2: Checking directory structure<br />
Pass 3: Checking directory connectivity<br />
Pass 4: Checking reference counts<br />
Pass 5: Checking group summary information<br />
/dev/vg_splat/lv_current: ***** FILE SYSTEM WAS MODIFIED *****<br />
/dev/vg_splat/lv_current: 26973/655360 files (0.1% non-contiguous), 384238/1310720 blocks</p>
<p>root@grml ~ # resize2fs /dev/vg_splat/lv_current<br />
resize2fs 1.41.11 (14-Mar-2010)<br />
Resizing the filesystem on /dev/vg_splat/lv_current to 2883584 (4k) blocks.<br />
The filesystem on /dev/vg_splat/lv_current is now 2883584 blocks long.</p>
<p>root@grml ~ # e2fsck -f /dev/vg_splat/lv_log<br />
e2fsck 1.41.11 (14-Mar-2010)<br />
Superblock last mount time is in the future.<br />
        (by less than a day, probably due to the hardware clock being incorrectly set)  Fix<y>? yes</p>
<p>Pass 1: Checking inodes, blocks, and sizes<br />
Pass 2: Checking directory structure<br />
Pass 3: Checking directory connectivity<br />
Pass 4: Checking reference counts<br />
Pass 5: Checking group summary information</p>
<p>/dev/vg_splat/lv_log: ***** FILE SYSTEM WAS MODIFIED *****<br />
/dev/vg_splat/lv_log: 56/1310720 files (3.6% non-contiguous), 49409/2621440 blocks</p>
<p> root@grml ~ # resize2fs /dev/vg_splat/lv_log<br />
resize2fs 1.41.11 (14-Mar-2010)<br />
Resizing the filesystem on /dev/vg_splat/lv_log to 6553600 (4k) blocks.<br />
The filesystem on /dev/vg_splat/lv_log is now 6553600 blocks long.</code></p>
<p>To finish, deactive the logical volumes:</p>
<p><code>root@grml ~ # vgchange -a n<br />
  0 logical volume(s) in volume group "vg_splat" now active</p>
<p>root@grml ~ # lvscan<br />
  inactive          '/dev/vg_splat/lv_current' [11.00 GiB] inherit<br />
  inactive          '/dev/vg_splat/lv_log' [25.00 GiB] inherit<br />
  inactive          '/dev/vg_splat/lv_hfa' [5.00 GiB] inherit<br />
  inactive          '/dev/vg_splat/lv_upgrade' [5.00 GiB] inherit<br />
  inactive          '/dev/vg_splat/lv_fcd' [2.00 GiB] inherit<br />
  inactive          '/dev/vg_splat/lv_fcd62' [2.00 GiB] inherit</code><br />
That&#8217;s it. Reboot again and start the Secure Platform.</p>
<p>Check with <code>df -h</code> that you have the desired partition layout:</p>
<p><code>[Expert@cpmodule]# df -h<br />
Filesystem            Size  Used Avail Use% Mounted on<br />
/dev/mapper/vg_splat-lv_current<br />
                       11G  1.4G  8.9G  14% /<br />
none                   11G  1.4G  8.9G  14% /dev/pts<br />
/dev/hdc1             145M   13M  125M   9% /boot<br />
none                  502M     0  502M   0% /dev/shm<br />
/dev/mapper/vg_splat-lv_log<br />
                       25G   33M   24G   1% /var/log</code></p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/06/update-to-r71-enlarging-utm-1-appliance-root-partitions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>R71 SSL VPN blade &#8211; how sweet is this?</title>
		<link>http://blog.lachmann.org/2010/06/r71-ssl-vpn-blade-how-sweet-is-this/</link>
		<comments>http://blog.lachmann.org/2010/06/r71-ssl-vpn-blade-how-sweet-is-this/#comments</comments>
		<pubDate>Thu, 17 Jun 2010 07:56:15 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[SSL VPN]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=372</guid>
		<description><![CDATA[I&#8217;m not sure if anyone noticed it, but R71 comes with a brandnew SSL VPN blade. And I really like how quickly you can do the setup. After a few clicks it is running, providing a demo-application (world clock). Setting up the rest is a piece of cake. Well done guys, well done! Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m not sure if anyone noticed it, but R71 comes with a brandnew SSL VPN blade. And I really like how quickly you can do the setup. After a few clicks it is running, providing a demo-application (world clock). Setting up the rest is a piece of cake.</p>
<p>Well done guys, well done!</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/06/sslvpn11.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/06/sslvpn11.jpg" alt="Check Point R71 SSL VPN blade - Wizard step 1" title="Check Point R71 SSL VPN blade - Wizard step 1" width="500" height="381" class="alignnone size-full wp-image-374" /></a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/06/sslvpn21.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/06/sslvpn21.jpg" alt="Check Point R71 SSL VPN blade - Wizard step 2" title="Check Point R71 SSL VPN blade - Wizard step 2" width="500" height="382" class="alignnone size-full wp-image-375" /></a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/06/sslvpn31.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/06/sslvpn31.jpg" alt="Check Point R71 SSL VPN blade - Wizard step 3" title="Check Point R71 SSL VPN blade - Wizard step 3" width="500" height="381" class="alignnone size-full wp-image-376" /></a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/06/sslvpn4.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/06/sslvpn4.jpg" alt="Check Point R71 SSL VPN blade - Wizard step 4" title="Check Point R71 SSL VPN blade - Wizard step 4" width="499" height="382" class="alignnone size-full wp-image-381" /></a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/06/sslvpn51.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/06/sslvpn51.jpg" alt="Check Point R71 SSL VPN blade - Login" title="Check Point R71 SSL VPN blade - Login" width="495" height="269" class="alignnone size-full wp-image-378" /></a></p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/06/r71-ssl-vpn-blade-how-sweet-is-this/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Keep up 2 date? Why 8?</title>
		<link>http://blog.lachmann.org/2010/06/keep-up-2-date-why-8/</link>
		<comments>http://blog.lachmann.org/2010/06/keep-up-2-date-why-8/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 18:59:13 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Content Inspection]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=364</guid>
		<description><![CDATA[I stumpled about the process keepup2date8, which was running after a R71 upgrade for quite a while on the machine. Took me some time to find out that it is nothing to worry, but the Kaspersky process for updating the antivirus-database. Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>I stumpled about the process <code>keepup2date8</code>, which was running after a R71 upgrade for quite a while on the machine.<br />
Took me some time to find out that it is nothing to worry, but the Kaspersky process for updating the antivirus-database.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/06/keep-up-2-date-why-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using 3rd party certificates for your SSL VPN</title>
		<link>http://blog.lachmann.org/2010/06/using-3rd-party-certificates-for-your-ssl-vpn/</link>
		<comments>http://blog.lachmann.org/2010/06/using-3rd-party-certificates-for-your-ssl-vpn/#comments</comments>
		<pubDate>Tue, 08 Jun 2010 09:14:49 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[SSL Network Extender]]></category>
		<category><![CDATA[UTM-1]]></category>
		<category><![CDATA[VPN-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=345</guid>
		<description><![CDATA[With Check Point software it&#8217;s very easy to configure client authentication over https or SSL VPN with the SSL Network Extender (SNX). But unfortunately, Check Point presents a self-signed certificate from the internal CA to the users. This warning message can be confusing for the users and even might not work, depending on the company [...]]]></description>
			<content:encoded><![CDATA[<p>With Check Point software it&#8217;s very easy to configure client authentication over https or SSL VPN with the SSL Network Extender (SNX).</p>
<p>But unfortunately, Check Point presents a self-signed certificate from the internal CA to the users. </p>
<p>This warning message can be confusing for the users and even might not work, depending on the company policy and settings in the browser.</p>
<p>The better way is to have a certificate on the gateway that was issued from one of the big CA like Verisign, Thawte etc. and present this to the users. </p>
<p>Because these CAs are known to the browser as trustworthy, no error message appears while connecting.</p>
<p>I&#8217;m going to show you how to configure your gateway with a certificate from a 3rd party CA.</p>
<p>1. First, we need to create a trusted CA object under the Servers and OPSEC Applications section.<br />
<a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl1.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl1.jpg" alt="Creating a trusted CA object" title="Creating a trusted CA object" width="311" height="114" class="alignnone size-full wp-image-344" /><br />
</a></p>
<p>2. Then we give a name to the CA object and choose OPSEC PKI as CA type.<br />
<a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl2.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl2.jpg" alt="CA properties" title="CA properties" width="342" height="413" class="alignnone size-full wp-image-336" /><br />
</a></p>
<p>3. On the next tab you can import the CA certificate from a file.<br />
<a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl3.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl3.jpg" alt="OPSEC PKI properties" title="OPSEC PKI properties" width="342" height="412" class="alignnone size-full wp-image-337" /><br />
</a></p>
<p>Here you can also choose to do an automatic enrollment for certificate renewal over three different protocols. However, this isn&#8217;t supported by all CA. Personally I don&#8217;t do automatic renewals but do it by hand instead every time.</p>
<p>If you uncheck CRL retrieval from HTTP servers, all certificates will be trusted, wether revoked or not. For our purpose it&#8217;s ok to have this unchecked.</p>
<p>4. While importing the CA certificate you have to approve it.<br />
<a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl4.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl4.jpg" alt="Accept CA certificate" title="Accept CA certificate" width="358" height="334" class="alignnone size-full wp-image-338" /><br />
</a></p>
<p>5. Now we&#8217;re done with the CA object and can actually go to the gateway object.<br />
<a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl5.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl5.jpg" alt="Gateway properties" title="Gateway properties" width="500" height="570" class="alignnone size-full wp-image-339" /><br />
</a></p>
<p>6. Click on <code>Add</code> to create a new certificate. You&#8217;re asked for a Nickname of the certificate which is used in various places in the GUI and in config files. I would suggest to keep it short and descriptive. Choose to enroll this certificate from the CA created in the steps before.<br />
<a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl5a.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl5a.jpg" alt="Certificate properties" title="Certificate properties" width="355" height="308" class="alignnone size-full wp-image-340" /><br />
</a></p>
<p>7. At this point a CSR (certificate signing request) is going to be generated. The DN (Distinguished Name) has to be correct for the certificate to be created by the CA, so take good care here!<br />
<a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl5b.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl5b.jpg" alt="Generate CSR" title="Generate CSR" width="347" height="429" class="alignnone size-full wp-image-341" /><br />
</a></p>
<p>In our example we sign the certificate by United Internet CA and we have to use this DN for a gateway with the DNS name of fw.test.de</p>
<p><em>CN=fw.test.de,OU=Comodo InstantSSL,OU=Authorized by United SSL,OU=Authorized by United SSL,O=TEST GmbH,STREET=Test Straße 90,L=Hamburg,ST=Hamburg,OID.2.5.4.17=22159,C=DE</em><br />
Alternatives DNS are defined as FQDN.</p>
<p>8. After filling in the details a CSR is presented. Copy it to the clipboard are save it to a file and hand it over to the CA you chose for signing. Make sure that the text is copied completely.<br />
<a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl6.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl6.jpg" alt="CSR view" title="CSR view" width="311" height="281" class="alignnone size-full wp-image-342" /><br />
</a></p>
<p>9. When the CA give you back your signed certificate, complete the process by selecting the appropriate nickname and click on Complete.<br />
<a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl5.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl5.jpg" alt="Gateway properties" title="Gateway properties" width="500" height="570" class="alignnone size-full wp-image-339" /><br />
</a></p>
<p>10. Load the certificate, accept it and attach it to the gateway.<br />
<a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl7.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl7.jpg" alt="Accept certificate" title="Accept certificate" width="312" height="281" class="alignnone size-full wp-image-343" /><br />
</a></p>
<p>11. Now you can choose this certificate to be presented when connecting to SSL Network Extender etc.<br />
<a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl8.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl8.jpg" alt="Clientless VPN configuration" title="Clientless VPN configuration" width="500" height="275" class="alignnone size-full wp-image-347" /><br />
</a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl9.jpg"><br />
<img src="http://blog.lachmann.org/wp-content/uploads/2010/06/ssl9.jpg" alt="VPN Clients configuration" title="VPN Clients configuration" width="500" height="207" class="alignnone size-full wp-image-348" /><br />
</a></p>
<p>To use this certificate in client authentication you have to configure the file <code>$FWDIR/conf/fwauthd.conf</code>. </p>
<p>Change the entry to</p>
<p><code>900     fwssd       in.ahclientd    wait    900         ssl:fw.test.de</code></p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/06/using-3rd-party-certificates-for-your-ssl-vpn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Discount on Check Point exams</title>
		<link>http://blog.lachmann.org/2010/06/discount-on-check-point-exams/</link>
		<comments>http://blog.lachmann.org/2010/06/discount-on-check-point-exams/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 15:52:36 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Certification]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=333</guid>
		<description><![CDATA[Check Point offers 25% discount on R70 exams. You can find the VUE promotion code on this webpage. Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>Check Point offers 25% discount on R70 exams. You can find the VUE promotion code on this <a href="http://www.checkpoint.com/services/education/leads/training/index.html">webpage</a>.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/06/discount-on-check-point-exams/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Check Point User Group Conference 2010</title>
		<link>http://blog.lachmann.org/2010/06/check-point-user-group-conference-2010/</link>
		<comments>http://blog.lachmann.org/2010/06/check-point-user-group-conference-2010/#comments</comments>
		<pubDate>Sun, 06 Jun 2010 16:31:14 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[CPUG]]></category>
		<category><![CDATA[CPUGCON]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=331</guid>
		<description><![CDATA[Don&#8217;t forget to register for the Check Point User Group Conference 2010 in lovely Chur. Barry will update the site ongoing to keep you informed about agenda, speakers and other details. I&#8217;m not sure if I can attend CPUGCON this year, but I will try. If I get accepted again as speaker, I might afford [...]]]></description>
			<content:encoded><![CDATA[<p>Don&#8217;t forget to register for the <a href="http://www.cpugcon.com/">Check Point User Group Conference 2010 </a>in lovely Chur.</p>
<p>Barry will update the site ongoing to keep you informed about agenda, speakers and other details.</p>
<p>I&#8217;m not sure if I can attend CPUGCON this year, but I will try. If I get accepted again as speaker, I might afford the trip.</p>
<p>At the moment I submitted presentations about troubleshooting, DLP, VPN-1 VE and UTM-1 appliances.</p>
<p>We&#8217;ll see how many of those can make it to the agenda.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/06/check-point-user-group-conference-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New EA for Discovery VPN client</title>
		<link>http://blog.lachmann.org/2010/06/new-ea-for-discovery-vpn-client/</link>
		<comments>http://blog.lachmann.org/2010/06/new-ea-for-discovery-vpn-client/#comments</comments>
		<pubDate>Sun, 06 Jun 2010 08:57:03 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Early Availability]]></category>
		<category><![CDATA[Endpoint Connect]]></category>
		<category><![CDATA[SecureClient]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=327</guid>
		<description><![CDATA[Check Point now has an open EA for the Discovery VPN client, which is the successor of the well-known SecureClient. Based on the documentation, it&#8217;s a mixture of Endpoint Connect when it comes to the VPN client engine and Endpoint Security Secure Access when it comes to the build-in personal firewall. The good part is, [...]]]></description>
			<content:encoded><![CDATA[<p>Check Point now has an open EA for the Discovery VPN client, which is the successor of the well-known SecureClient. Based on the documentation, it&#8217;s a mixture of Endpoint Connect when it comes to the VPN client engine and Endpoint Security Secure Access when it comes to the build-in personal firewall. The good part is, that the personal firewall rules can be managed the old-fashioned way through the SmartDashboard, like today with SecureClient. So no change her and the ability to use all the existing object in your database.</p>
<p>To access this EA, log into your UserCenter account, go to <code>Products </code>-> <code>Early Availability </code>and choose to register for <code>Discover VPN client</code>.</p>
<p>In the moment the Discovery VPN client is only available for NGX R65 HFA60, a release for R70/R71 will follow shortly. Supported gateway platforms are SecurePlatform, Windows and IPSO 4.2. </p>
<p>The client has support for Windows XP 32 bit with SP2 or SP3, Windows Vista 32 and 64 bit with SP1 and Windows 7 32 and 64 bit, so most of the operating system platforms found in companies are covered.</p>
<p>The following features are not supported at the moment:</p>
<ul>
<li>Single Sign-on (SSO)</li>
<li>“Suggest Connect” Mode (Auto Connect)</li>
<li>Pre/Post Connect Script</li>
<li>Entrust Entelligence Support</li>
<li>Diagnostic Tools</li>
<li>Compression</li>
<li>VPN Connectivity to VPN-1 VSX</li>
<li>DNS Splitting</li>
<li>&#8220;No Office Mode&#8221; Connect Mode</li>
</ul>
<p>But this is OK as it is an EA on the GA version will surely have all those features.</p>
<p>In addition, Discovery VPN client has features that Endpoint Connect is offering, like better Location Awareness, Automatic Site Detection, better Roaming etc.</p>
<p>A hotfix has to be installed on the gateway to enable Discovery support, no changes at the SmartCenter are needed. The configuration has no Discovery specific details, just a normal SecureClient configuration. If you have an exisiting deployment, nothing has to be changed.</p>
<p>I will test this client in the next weeks. If you have done so, please feel free to send comments to blog@lachmann.org and share your experience.</p>
<p>Personally I miss support for Mac OS 10.4, 10.5 and 10.6 very much. Especially media related companies such as advertisement agencies, print and TV producers use Mac OS as operating system, so this is a significant number of users.</p>
<p>Sadly, Check Point hasn&#8217;t these operating systems in the same focus as the Windows OS. This leads to the point where the customers change from SecureClient to <a href="http://www.lobotomo.com/products/IPSecuritas/">IPSecuritas</a>, a freeware VPN client. Using this client means more work for the client administrators, as settings can&#8217;t be distributed in the way it is done with SecureClient for Mac OS.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/06/new-ea-for-discovery-vpn-client/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UTM-1 hardware</title>
		<link>http://blog.lachmann.org/2010/05/utm-1-hardware/</link>
		<comments>http://blog.lachmann.org/2010/05/utm-1-hardware/#comments</comments>
		<pubDate>Tue, 25 May 2010 10:22:10 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[OpenServer]]></category>
		<category><![CDATA[Power-1]]></category>
		<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Smart-1]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=311</guid>
		<description><![CDATA[Here is a short list of the hardware used in UTM-1 / Power-1 / Smart-1 appliances. If you take the appliance hardware together with the throughput stated by Check Point, it might give you an idea how your OpenServer hardware will perform in comparison. The details can be determined from the command line. For the [...]]]></description>
			<content:encoded><![CDATA[<p>Here is a short list of the hardware used in UTM-1 / Power-1 / Smart-1 appliances.<br />
If you take the appliance hardware together with the <a href="http://www.checkpoint.com/products/downloads/appliances/appliance-comparison-chart.pdf">throughput stated by Check Point</a>, it might give you an idea how your OpenServer hardware will perform in comparison.</p>
<p>The details can be determined from the command line.</p>
<p>For the CPU details use <code>cat /proc/cpuinfo</code>, for the RAM details use <code>cat /proc/meminfo</code>.</p>
<p>If you have more details on UTM-1 appliances, feel free to send them to blog@lachmann.org</p>
<p><strong>UTM-1 130 </strong></p>
<ul>
<li>Intel Celeron M 600 MHz </li>
<li>1 GB RAM </li>
<li>80 GB ATA HDD</li>
</ul>
<p><strong>UTM-1 270 </strong></p>
<ul>
<li>Intel Celeron M 600 MHz </li>
<li>1 GB DDR2 RAM 400 MHz </li>
<li>160 GB ATA HDD</li>
</ul>
<p><strong>UTM-1 450 </strong></p>
<ul>
<li>Intel Celeron M 1.5 GHz </li>
<li>1 GB RAM </li>
<li>80 GB ATA HDD</li>
</ul>
<p><strong>UTM-1 570 </strong></p>
<ul>
<li>Intel Celeron M 1.5 GHz </li>
<li>1 GB RAM </li>
<li>160 GB ATA HDD </li>
</ul>
<p><strong>UTM-1 1070 </strong></p>
<ul>
<li>Intel Celeron M 1.5 GHz </li>
<li>1 GB RAM </li>
<li>160 GB ATA HDD </li>
</ul>
<p><strong>UTM-1 2050 </strong></p>
<ul>
<li>Intel Pentium 4 3.4 GHz </li>
<li>2 GB RAM </li>
<li>80 GB ATA HDD </li>
</ul>
<p><strong>UTM-1 2070 </strong></p>
<ul>
<li>Intel Celeron 440 2.00GHz</li>
<li>2 GB RAM </li>
<li>160 GB ATA HDD </li>
</ul>
<p><strong>UTM-1 3070 </strong></p>
<ul>
<li>Intel Core2 Duo E6400 2.13GHz</li>
<li>3 GB RAM </li>
<li>160 GB ATA HDD </li>
</ul>
<p><strong>Power-1 5070 </strong></p>
<ul>
<li>Intel Xeon E5410 2.33GHz (QC)</li>
<li>2 GB RAM </li>
<li>80 GB ATA HDD </li>
</ul>
<p><strong>Smart-1 25 </strong></p>
<ul>
<li>Intel Core2 Duo CPU T7400 2.16GHz</li>
<li>3 GB RAM </li>
<li>4x 500 GB SATA HDD in RAID 10</li>
</ul>
<p>Thanks to all the contributors for their info!</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/utm-1-hardware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Avatar &#8211; the gateway, not the film!</title>
		<link>http://blog.lachmann.org/2010/05/avatar-the-gateway-not-the-film/</link>
		<comments>http://blog.lachmann.org/2010/05/avatar-the-gateway-not-the-film/#comments</comments>
		<pubDate>Thu, 20 May 2010 19:21:04 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Software Blades]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[VPN-1 VE]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=307</guid>
		<description><![CDATA[Check Point opened the public EA for the successor of VPN-1 VE, codename Avatar. Avatar is designed to run with vSphere 4. Register for the EA within your Usercenter account. Go to Products and then Early Availability. Register for Avatar EA and download the software and documentation. I have waited for this EA for a [...]]]></description>
			<content:encoded><![CDATA[<p>Check Point opened the public EA for the successor of VPN-1 VE, codename Avatar. Avatar is designed to run with vSphere 4.</p>
<p>Register for the EA within your Usercenter account. Go to <em>Products </em>and then <em>Early Availability</em>. Register for Avatar EA and download the software and documentation.</p>
<p>I have waited for this EA for a while and I&#8217;m very curious. There are rumours that the licensing will also be changed and I hope it&#8217;s more affordable than the current pricing.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/avatar-the-gateway-not-the-film/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Delete all ARP entries on SPLAT</title>
		<link>http://blog.lachmann.org/2010/05/delete-all-arp-entries-on-splat/</link>
		<comments>http://blog.lachmann.org/2010/05/delete-all-arp-entries-on-splat/#comments</comments>
		<pubDate>Wed, 19 May 2010 17:01:15 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=301</guid>
		<description><![CDATA[We stumbled over this one yesterday: some servers behind a gateway had a problem with ARP resolution and we wanted to make sure that ARP worked. To verify this we tried to delete all ARP entries and see if the ARP cache was filled up again (and correctly). While Windows has arp -d * as [...]]]></description>
			<content:encoded><![CDATA[<p>We stumbled over this one yesterday: some servers behind a gateway had a problem with ARP resolution and we wanted to make sure that ARP worked. To verify this we tried to delete all ARP entries and see if the ARP cache was filled up again (and correctly).</p>
<p>While Windows has <code>arp -d *</code> as a working command to delete all entries at once, under Linux and therefor SPLAT you have to try something different.</p>
<p>This little script will do the job for you:</p>
<p><code>#!/bin/bash<br />
for arpentries in `awk -F ' ' '<br />
{ if ( $1 ~ /[0-9{1,3}].[0-9{1,3}].[0-9{1,3}].[0-9{1,3}]/ )<br />
  print $1 }' /proc/net/arp`<br />
do<br />
  arp -d $arpentries<br />
done<br />
</code></p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/delete-all-arp-entries-on-splat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More benefits for recent CCSE certification</title>
		<link>http://blog.lachmann.org/2010/05/more-benefits-for-recent-certifications/</link>
		<comments>http://blog.lachmann.org/2010/05/more-benefits-for-recent-certifications/#comments</comments>
		<pubDate>Wed, 19 May 2010 05:03:29 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Certification]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=298</guid>
		<description><![CDATA[Check Point changed the benefits for their Check Point Certified Security Expert (CCSE) certification. In the past we had Expert Access to SecureKnowledge Newsletter Logo rights Now they added Access to level-3 TAC support engineers I&#8217;m not sure what this means. I deal a lot with the TAC in Israel as part of my daily [...]]]></description>
			<content:encoded><![CDATA[<p>Check Point changed the benefits for their Check Point Certified Security Expert (CCSE) certification. </p>
<p>In the past we had</p>
<ul>
<li>Expert Access to SecureKnowledge</li>
<li>Newsletter</li>
<li>Logo rights</li>
</ul>
<p>Now they added </p>
<ul>
<li>Access to level-3 TAC support engineers </li>
</ul>
<p>I&#8217;m not sure what this means. I deal a lot with the TAC in Israel as part of my daily work, but never encountered a &#8220;level-3&#8243; engineer. Normally your call is handled by a support engineer and, if escalated, handed over to an escalation engineer. And maybe a diamond engineer from the diamond support team assists. Would we interesting to know what &#8220;level-3&#8243; means.</p>
<p>Anyway, the goal is clear: give the higher certified people direct access to support engineers that have the same level.</p>
<p>In addidtion, Check Point changed the handling of calls from Check Point Certified Master Architects (CCMA). Now they get escalation priority while opening a case. Also a good thing, as a CCMA is so highly trained that he could easily work as escalation support engineer with Check Point. If a CCMA opens a case, it must be severe.</p>
<p>The community demanded such priviliges for skilled people a long time (see CPUG board for the discussion) I&#8217;m glad that Check Point now made a step forward!</p>
<p> Tobias Lachmann</p>
<p><strong>UPDATE: Pierre Lamy, Technical Lead of Ottawa TAC, <a href="http://www.cpug.org/forums/general-exam-topics/13580-greater-benefits-certified-engineers.html#post58596">pointed out </a>what tiers/levels exist. A level-3 engineer is the normal support engineer who&#8217;s handling a case opened with Israel TAC. </strong> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/more-benefits-for-recent-certifications/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Again backup problems after R70.30 upgrade when using SCP</title>
		<link>http://blog.lachmann.org/2010/05/again-backup-problems-after-r70-30-upgrade-when-using-scp/</link>
		<comments>http://blog.lachmann.org/2010/05/again-backup-problems-after-r70-30-upgrade-when-using-scp/#comments</comments>
		<pubDate>Thu, 13 May 2010 21:04:23 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Secure Platform]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=292</guid>
		<description><![CDATA[We had this before, now it&#8217;s back: the problem with not working scheduled backups after upgrading to a R70.xx version. Seen on R70.20, now I upgraded a environment from R70.10 to R70.30 &#8211; and the error is still there. The backup files are not correctly transfered to the SCP server configured. The solution is to [...]]]></description>
			<content:encoded><![CDATA[<p>We had this before, now it&#8217;s back: the problem with not working scheduled backups after upgrading to a R70.xx version. Seen on R70.20, now I upgraded a environment from R70.10 to R70.30 &#8211; and the error is still there. The backup files are not correctly transfered to the SCP server configured.</p>
<p>The solution is to disable scheduled backup through the WebUI.</p>
<p>Then go to the <code>/var/CPbackup/conf </code>directory and delete the file <code>backup_sched.conf</code>.</p>
<p>Afterwards open the WebUI again and re-configure scheduled backup.</p>
<p>Next time the backup runs everything will be OK and files are transfered to another server with SCP.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/again-backup-problems-after-r70-30-upgrade-when-using-scp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New firmware 8.1.37 for UTM-1 Edge X series</title>
		<link>http://blog.lachmann.org/2010/05/new-firmware-8-1-37-for-utm-1-edge-x-series/</link>
		<comments>http://blog.lachmann.org/2010/05/new-firmware-8-1-37-for-utm-1-edge-x-series/#comments</comments>
		<pubDate>Tue, 11 May 2010 14:37:02 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[UTM-1 Edge]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=289</guid>
		<description><![CDATA[Check Point released a new firmware for the UTM-1 Edge appliance series. As the release notes show, modifications were made for the new N-series appliances, along with some bug fixing. The most interesting details: - support for Endpoint Connect clients - support for new USB modems - times based rules are now supported In the [...]]]></description>
			<content:encoded><![CDATA[<p>Check Point released a new firmware for the UTM-1 Edge appliance series.</p>
<p>As the <a href="http://downloads.checkpoint.com/dc/download.htm?ID=10840">release notes </a>show, modifications were made for the new N-series appliances, along with some bug fixing.</p>
<p>The most interesting details:</p>
<p>- support for Endpoint Connect clients<br />
- support for new USB modems<br />
- times based rules are now supported</p>
<p>In the release notes some more features are listed, but with a reference that they will only work with hardware version 1.4.<br />
I guess that is the hardware version of the new N-series appliances. </p>
<p>Nice features supporting hardware version 1.4</p>
<p>- 802.11n support<br />
- GigabitEthernet support<br />
- ore firewall throughput<br />
- more VPN tunnels<br />
- support for some more USB modems</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/new-firmware-8-1-37-for-utm-1-edge-x-series/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Details on Data Loss Prevention (DLP) blade licensing</title>
		<link>http://blog.lachmann.org/2010/05/details-on-data-loss-prevention-dlp-blade-licensing/</link>
		<comments>http://blog.lachmann.org/2010/05/details-on-data-loss-prevention-dlp-blade-licensing/#comments</comments>
		<pubDate>Mon, 10 May 2010 09:14:33 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Content Inspection]]></category>
		<category><![CDATA[Data Loss Prevention]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=285</guid>
		<description><![CDATA[It has taken a long time to get information from Check Point how to license the DLP blade, but now I got an answer: For the 500 and 1500 user DLP blade a 2-Core-Container is needed. For the unlimited user DLP blade you need a 8-Core-Container. The size of the blade is determined by the [...]]]></description>
			<content:encoded><![CDATA[<p>It has taken a long time to get information from Check Point how to license the DLP blade, but now I got an answer:</p>
<p>For the 500 and 1500 user DLP blade a 2-Core-Container is needed. For the unlimited user DLP blade you need a 8-Core-Container.<br />
The size of the blade is determined by the number of users behind the gateway!</p>
<p>So that would mean you need an SG201 container (included: gateway for up to 500 users) for the CPSB-DLP-500 blade.</p>
<p>For the CPSB-DLP-1500 blade a SG203U pre-defined system is needed, to allow more than 500 users.</p>
<p>For the CPSB-DLP-U blade a SG801 container is needed.</p>
<p>So the solution for 500 users will cost $3000 for the blade and $6500 for the container, so $9500 in total. </p>
<p>The solution for 1500 users will cost $7000 for the blade, $14000 for the container, so $21000 in total. </p>
<p>The unlimited solution will cost $12000 for the blade and $18000 for the container, so $30000 in total.</p>
<p>This is the pure software side, you will also need hardware, for example an open server for additional $4000. </p>
<p>If we look at the appliance solution DLP-1 2571 we&#8217;ll find that it is limited to 1500 users but costs only $14990.</p>
<p>In case your organization need DLP protection for up to 500 users, a solution with software running on an open server is about $1500 cheaper. If you need up to 1500 users, you pay $10000 more with an open server solution than for the DLP-1 2571. Lot&#8217;s of money&#8230;.. but still worth thinking about it because of the higher performance you will get from an open server.</p>
<p>More easy with the DLP-1 9571 that you need for unlimited users, as the appliances costs $49900. The software solution on an open server is only $34000, that is about $16000 cheaper.</p>
<p>What&#8217;s the baseline here? Well, carefully think about your setup before you buy. Think about performance limitations you may encounter with an appliance. Think about the cost for the 2nd and 3rd year&#8230; and then make your decision!</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/details-on-data-loss-prevention-dlp-blade-licensing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Delete old log files on SPLAT machines</title>
		<link>http://blog.lachmann.org/2010/05/delete-old-log-files-on-splat-machines/</link>
		<comments>http://blog.lachmann.org/2010/05/delete-old-log-files-on-splat-machines/#comments</comments>
		<pubDate>Mon, 10 May 2010 08:34:12 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=281</guid>
		<description><![CDATA[There is no way to configure your SPLAT box or UTM-1 appliance in a way, that only logs for the last X days were kept. The only work-around would be to configure on the firewall object -> Logs and Masters -> Required Free Disc Space together with the option Do not delete log files from [...]]]></description>
			<content:encoded><![CDATA[<p>There is no way to configure your SPLAT box or UTM-1 appliance in a way, that only logs for the last X days were kept.</p>
<p>The only work-around would be to configure on the <code>firewall object -> Logs and Masters -> Required Free Disc Space </code>together with the option <code>Do not delete log files from the last X days</code>. </p>
<p>By configuring a very high value for required free disc space you could have the script run every day and with the other option prevent it from deleting the needed logs.</p>
<p>OR &#8211; you could implement a short script:</p>
<p><code>[Expert@fw1]# cat /usr/bin/del_logs.sh<br />
#!/bin/bash<br />
/usr/bin/find /var/log/opt/CPsuite-R65/fw1/*.log* -ctime +217 -print -exec rm -f {} \;</code></p>
<p>The parameter <code>ctime </code>is the amount of days for the logs to keep.</p>
<p>Run the script with cron:</p>
<p><code>[Expert@fw1]# crontab -l<br />
# DO NOT EDIT THIS FILE - edit the master and reinstall.<br />
# (/tmp/crontab.19431 installed on Mon May 10 10:21:33 2010)<br />
# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $)<br />
42 11 * * * /usr/bin/del_logs.sh<br />
50 2 * * 1,2,3,4,5,6,7 backup_util sched</code></p>
<p>Now you&#8217;re able to delete the old logs as you like. If you backup your firewall or SmartCenter to your local disc, maybe you want to do this with your backups, too?</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/delete-old-log-files-on-splat-machines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to build an UTM-1 cluster with SmartCenter HA (aka Full Cluster)</title>
		<link>http://blog.lachmann.org/2010/05/how-to-build-an-utm-1-cluster-with-smartcenter-ha-aka-full-cluster/</link>
		<comments>http://blog.lachmann.org/2010/05/how-to-build-an-utm-1-cluster-with-smartcenter-ha-aka-full-cluster/#comments</comments>
		<pubDate>Sun, 09 May 2010 10:32:21 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[CPUG]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=274</guid>
		<description><![CDATA[Maybe you&#8217;ve seen my presentation on CPUGCON 2009 about migration to an UTM-1 cluster from a distributed environment. Now I was asked to provide a how-to about building this kind of UTM-1 Full Cluster from scratch. Actually this is very easy. Building UTM-1 clusters was supported from the start, but the SmartCenter could only reside [...]]]></description>
			<content:encoded><![CDATA[<p>Maybe you&#8217;ve seen my <a href="http://www.cpugcon.com/2009-CPUG-CON-EUROPE/presentations/2009-CPUG-CON-Tobias-Lachmann-Migration-From-A-Distributed-Environment-To-A-UTM-1-Cluster-2009-09-09.ppt">presentation</a> on CPUGCON 2009 about migration to an UTM-1 cluster from a distributed environment.</p>
<p>Now I was asked to provide a how-to about building this kind of UTM-1 Full Cluster from scratch.</p>
<p>Actually this is very easy. Building UTM-1 clusters was supported from the start, but the SmartCenter could only reside on one appliance. With the introduction of NGX R65 with Messaging Security, we also got SmartCenter High-Availability for free.</p>
<p>In our setup we assume that we have two appliances, one primary and one secondary. Setup both with the normal First Time Configuration Wizard. </p>
<p>Make sure to install the <strong>primary</strong> on as locally managed and primary cluster member. </p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/05/primary01.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/05/primary01.jpg" alt="" title="Setup of primary UTM-1 appliance" width="400" height="347" class="aligncenter size-full wp-image-272" /></a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/05/primary02.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/05/primary02.jpg" alt="" title="Setup of primary UTM-1 appliance" width="400" height="347" class="aligncenter size-full wp-image-270" /></a></p>
<p>The<strong> secondary </strong>appliance is also installed as locally managed but as secondary cluster member. </p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/05/secondary01.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/05/secondary01.jpg" alt="" title="Setup of secondary UTM-1 appliance" width="400" height="347" class="aligncenter size-full wp-image-273" /></a></p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/05/secondary02jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/05/secondary02.jpg" alt="" title="Setup of secondary UTM-1 appliance" width="400" height="347" class="aligncenter size-full wp-image-273" /></a></p>
<p>On the secondary appliance you also have to fill in a SIC secret to establish the communication later.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/05/sic.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/05/sic.jpg" alt="" title="Configuring SIC on secondary UTM-1 appliance" width="500" height="328" class="aligncenter size-full wp-image-275" /></a></p>
<p>After completing the First Time Configuration Wizards on both appliances, connect with the SmartDashboard to the primary UTM-1 appliance.</p>
<p>Now the wizard for configuring the cluster pops up. When defining the secondary cluster member, fill in the SIC secret entered in the WebUI wizard.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/05/wizard.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/05/wizard.jpg" alt="" title="Entering the SIC secret for secondary UTM-1 appliance" width="500" height="389" class="aligncenter size-full wp-image-269" /></a></p>
<p>Fill in all the details that reflect your cluster. Make sure to have at least one dedicated sync network.</p>
<p>Topology could look like this afterwards:</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/05/topology.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/05/topology.jpg" alt="" title="Simple UTM-1 cluster topology" width="500" height="221" class="aligncenter size-full wp-image-268" /></a></p>
<p>Now you can define rules, push the policy and make the cluster work. After that check the Management HA in the SmartDashboard:</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/05/dashboard_mgmt_ha.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/05/dashboard_mgmt_ha.jpg" alt="" title="Access the SmartCenter Management HA through the Dashboard" width="400" height="336" class="aligncenter size-full wp-image-267" /></a></p>
<p>This picture shows that both cluster members have a SmartCenter installed and are working in Management High-Availability mode.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/05/mgmt_ha.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/05/mgmt_ha.jpg" alt="" title="SmartCenter Management High-Availability" width="500" height="392" class="aligncenter size-full wp-image-266" /></a></p>
<p>That&#8217;s it for building an UTM-1 cluster with Management High Availability &#8211; also known as UTM-1 Full Cluster.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/how-to-build-an-utm-1-cluster-with-smartcenter-ha-aka-full-cluster/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Abra documentation and software available</title>
		<link>http://blog.lachmann.org/2010/05/abra-documentation-and-software-available/</link>
		<comments>http://blog.lachmann.org/2010/05/abra-documentation-and-software-available/#comments</comments>
		<pubDate>Thu, 06 May 2010 12:37:30 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Abra]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=262</guid>
		<description><![CDATA[Documentation and software for the Abra stick is now available in the Check Point suppport center. I stumbled over two things in the known limitations. First, Office mode is not supported on Abra. And second, CIFS is not supported over a VPN tunnel that was established with Abra. By now I don&#8217;t know why these [...]]]></description>
			<content:encoded><![CDATA[<p>Documentation and software for the Abra stick is now available in the Check Point suppport center. I stumbled over two things in the known limitations. First, Office mode is not supported on Abra. And second, CIFS is not supported over a VPN tunnel that was established with Abra.</p>
<p>By now I don&#8217;t know why these limitations exist, but I would rate them as servere. Especially Office Mode is a must-have while working with Client-2-Site VPNs.</p>
<p>Pricing seems to be $140 for a 4GB Abra stick and $210 for a 8GB Abra stick. I&#8217;m not sure if we have to purchase an additional Endpoint Security license (container + VPN) when Abra is able to do Office mode, but I think so. That&#8217;s the way you have to license Endpoint Connect at the moment.</p>
<p>I will now play around with Abra a little bit and come back with more information in a couple of days.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/abra-documentation-and-software-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>R71 performance on UTM-1 appliances</title>
		<link>http://blog.lachmann.org/2010/05/r71-performance-on-utm-1-appliances/</link>
		<comments>http://blog.lachmann.org/2010/05/r71-performance-on-utm-1-appliances/#comments</comments>
		<pubDate>Tue, 04 May 2010 15:30:31 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Content Inspection]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Software Blades]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=253</guid>
		<description><![CDATA[As mentioned before, the UTM-1 appliance had performance trouble when doing content scanning and I would not recommend doing this in this machines. Now R71 claimes to give a big boost by new methods of scanning. I tested the performance improvement of the new R71 release with the following setup: UTM-1 270 mit GigabitEthernet-Uplink to [...]]]></description>
			<content:encoded><![CDATA[<p>As mentioned before, the UTM-1 appliance had performance trouble when doing content scanning and I would not recommend doing this in this machines. Now R71 claimes to give a big boost by new methods of scanning. I tested the performance improvement of the new R71 release with the following setup:</p>
<p>UTM-1 270 mit GigabitEthernet-Uplink to the Internet and GigabitEthernet-Link to the internal network. 4 Servers mit GigabitEthernet as clients running <a href="http://www.httrack.com/">HTTrack website copier</a> in the internal network. I used HTTrack to download several website at the same time, creating a mixture of HTML, graphic, archives and executables content.</p>
<p>The UTM-1 270 was installed out-of-the box using the wizard. I activated VPN, SmartView Monitor and Antivirus in addition the moduls already activated as standard.</p>
<p>The rulebase had two rules, on allowing access to the systems from a management client outside the network and one rule for allowing access to the Internet for the servers. No NAT was used, no additional settings.</p>
<p>With NGX R65 with Messaging Security (HFA25) I had an average throughput of 1,026,474 Bytes / sec while running with 100% CPU load for a couple of minutes.</p>
<p>With NGX R65 with Messaging Security (HFA70) I had an average throughput of 1,094,563 Bytes / sec while running with 100% CPU load for a couple of minutes.</p>
<p>With R70 I had an average throughput of 1,647,257 Bytes / sec while running with 100% CPU load for a couple of minutes.</p>
<p>With R71 I had an average throughput of 1,999,611 Bytes / sec while running with 100% CPU load for a couple of minutes.</p>
<p>My test maybe not so accurate as the ones that Check Point is doing, but I thing the traffic blend reflects the behaviour of normal users really good.</p>
<p>And, having 2x the performance with Antivirus scanning on the same hardware is pretty impressive! The improvement really shows, how nice! I also recognized that R71 comes with a new AV engine with has the name KSS, maybe Kaspersky?</p>
<p>This is enough performance to use modern DSL lines or direct links completely, not only partial. So I would recommend this release to everyone who still uses content scanning on an UTM-1 appliance and has performance problems.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/r71-performance-on-utm-1-appliances/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New UTM-1 Edge N-Series appliances</title>
		<link>http://blog.lachmann.org/2010/05/new-utm-1-edge-n-series-appliances/</link>
		<comments>http://blog.lachmann.org/2010/05/new-utm-1-edge-n-series-appliances/#comments</comments>
		<pubDate>Tue, 04 May 2010 15:06:23 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[UTM-1 Edge]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=258</guid>
		<description><![CDATA[Check Point is launching a new series of UTM-1 Edge appliances, the N-Series. Looks like the rumours from years ago came true and they finally build the &#8220;Edge Arrow&#8221;. Here&#8217;s the baseline from what we know by now: - 5x more firewall throughput than X-series appliances - 5x more VPN throughput than X-Series appliances - [...]]]></description>
			<content:encoded><![CDATA[<p>Check Point is launching a new series of UTM-1 Edge appliances, the N-Series. Looks like the rumours from years ago came true and they finally build the &#8220;Edge Arrow&#8221;. </p>
<p>Here&#8217;s the baseline from what we know by now:</p>
<p>- 5x more firewall throughput than X-series appliances<br />
- 5x more VPN throughput than X-Series appliances<br />
- 7x more concurrent connections than X-series appliances<br />
- GigabitEthernet-Ports instead of FastEthernet<br />
- 3G connectivity build-in<br />
- two flavours: 32 users and unlimited users, 8 users and 16 user only with X-series<br />
- 4x more VPN tunnels (SA)<br />
- unlimited Remote Access profiles<br />
- 802.11b/b/n support (UTM-1 Edge NW)<br />
- 802.11z wireless security support<br />
- no build-in ADSL-modem available<br />
- new 8.1 firmware for all models (not available by now on support pages)</p>
<p>The complete specification can be found <a href="http://www.checkpoint.com/products/utm-1_edge/index.html">here</a>.</p>
<p>An UTM-1 Edge N32 is $200 more expensive as an old X32 and costs $1400 instead of $1200, same applies to the NU which is now $2200 instead of $2000 for XU.</p>
<p>If you take in consideration how much more power you can get, the $200 more are totally fine with me.</p>
<p>Will be interesting to see how the firmware developed from 8.0.42 to 8.1. Hopefully it&#8217;s available soon.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/new-utm-1-edge-n-series-appliances/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When to use UTM-1 appliances – and when not &#8211; Part II</title>
		<link>http://blog.lachmann.org/2010/05/when-to-use-utm-1-appliances-%e2%80%93-and-when-not-part-ii/</link>
		<comments>http://blog.lachmann.org/2010/05/when-to-use-utm-1-appliances-%e2%80%93-and-when-not-part-ii/#comments</comments>
		<pubDate>Mon, 03 May 2010 18:19:56 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Software Blades]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=251</guid>
		<description><![CDATA[Last week the R71 software version was released. One of the most interesting things for me was the performance improvement they promised on appliances. The use now SecureXL to accelerate connections and state that they now can deliver up to 4 time more firewall throughput and connection rate and up to 3 times more IPS [...]]]></description>
			<content:encoded><![CDATA[<p>Last week the R71 software version was released. One of the most interesting things for me was the performance improvement they promised on appliances. </p>
<p>The use now SecureXL to accelerate connections and state that they now can deliver up to 4 time more firewall throughput and connection rate and up to 3 times more IPS throughput. Some limitations apply to SecureXL as described in the <a href="http://downloads.checkpoint.com/dc/download.htm?ID=8711">R70 Performance Optimization Guide </a> so we have to see how this works with real life rulebases.</p>
<p>But the biggest change to me is the performance enhancement with Antivirus, where Check Point speaks of up to 15! times more throughput and up to 80 times more connection rate.</p>
<p>This is done by the new Stream Detection Mode. As you may remember from my previous post, AntiVirus suffered from the bad HDD performance on UTM-1 appliances, as every file had to be downloaded to the disc, scanned and then delivered to the client. Now the inspection is done as the traffic passes through the gateway and they do a pattern matching as far as I understood. Makes perfectly sense that this way of traffic inspection improves performance. Unclear is for me at the moment how compressed content is handled. I can&#8217;t see now other way than storing the archive to disc, uncompress it and then scan the content. Not sure how they handle this &#8211; on the fly seems unlikely.</p>
<p>Anyway, I will test this in the next days to get my own results and will check the processes and disc accesses while doing so, which will hopefully gives an explanation.</p>
<p>By the way: URL Filtering is handled differently, too. Now the connections are handled in the kernel space and no longer folded into the security server. This will improve performance and will change the way we can debug this blade. </p>
<p>If Check Point can keep the promises on performance while running R71 on UTM-1 appliances, I will be deeply impressed. Remember that the appliances are sold for some years now and have less powerful hardware, compared to standard OpenServers. Would be a great thing for all of us the protect the investment in the appliances!</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/when-to-use-utm-1-appliances-%e2%80%93-and-when-not-part-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SecurePlatform and NTP</title>
		<link>http://blog.lachmann.org/2010/05/secureplatform-and-ntp/</link>
		<comments>http://blog.lachmann.org/2010/05/secureplatform-and-ntp/#comments</comments>
		<pubDate>Mon, 03 May 2010 12:01:58 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Secure Platform]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=249</guid>
		<description><![CDATA[This is an old problem, but maybe not everyone knows this: If you work with NTP servers sync on SPLAT, you should also set the timezone to get correct date/time and daylight saving. Unfortunately, this can&#8217;t be done in the WebUI. So first configure your NTP servers in the WebUI. Then access the command line [...]]]></description>
			<content:encoded><![CDATA[<p>This is an old problem, but maybe not everyone knows this:</p>
<p>If you work with NTP servers sync on SPLAT, you should also set the timezone to get correct date/time and daylight saving. Unfortunately, this can&#8217;t be done in the WebUI. So first configure your NTP servers in the WebUI. Then access the command line and execute <code>sysconfig</code>. Use option <code>4</code> to go to time settings and then option <code>1</code> for setting the <code>time zone </code>according to your location.</p>
<p>Verify that you got the correct time using the WebUI.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/secureplatform-and-ntp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Well done, Royi!</title>
		<link>http://blog.lachmann.org/2010/05/well-done-royi/</link>
		<comments>http://blog.lachmann.org/2010/05/well-done-royi/#comments</comments>
		<pubDate>Mon, 03 May 2010 10:50:44 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=246</guid>
		<description><![CDATA[Just had an amazing &#8220;support experience&#8221; with Check Point: My customer suffered from sudden loss of VPN connectivity as the SmartCenter CA died because of a database corruption. Check Point needed only 30 minutes from answering my call to providing a hotfix that solved the problem! Well done, guys! Very well done! Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>Just had an amazing &#8220;support experience&#8221; with Check Point:<br />
My customer suffered from sudden loss of VPN connectivity as the SmartCenter CA died because of a database corruption.<br />
Check Point needed only 30 minutes from answering my call to providing a hotfix that solved the problem!<br />
Well done, guys! Very well done!</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/well-done-royi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>URL Filtering update error</title>
		<link>http://blog.lachmann.org/2010/05/url-filtering-update-error/</link>
		<comments>http://blog.lachmann.org/2010/05/url-filtering-update-error/#comments</comments>
		<pubDate>Mon, 03 May 2010 09:30:22 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Content Inspection]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=239</guid>
		<description><![CDATA[When you receive continous update errors within the URL Filtering modul, maybe it&#8217;s a good idea to delete the whole database and rebuild it via the update database function in SmartDashboard. Was helpful for me several times&#8230; First change to the directory $FWDIR/uf/sc/update/incoming. Delete all the files beginning with &#8220;sfcontrol&#8221;. The file &#8220;sfcontrol&#8221; itself is [...]]]></description>
			<content:encoded><![CDATA[<p>When you receive continous update errors within the URL Filtering modul, maybe it&#8217;s a good idea to delete the whole database and rebuild it via the update database function in SmartDashboard. Was helpful for me several times&#8230;</p>
<ul>
<li>First change to the directory <code>$FWDIR/uf/sc/update/incoming</code>. </li>
<li>Delete all the files beginning with &#8220;sfcontrol&#8221;. The file &#8220;sfcontrol&#8221; itself is the database, all the others are differentials and status infos.</li>
<li>Run cpstop and cpstart for a restart of the services that controll URL Filtering. </li>
<li>Go to your SmartDashboard, change to the &#8220;Content Inspection&#8221; tab and click on &#8220;Update Databases Now&#8221;.</li>
</ul>
<p>It will take awhile to download to whole database, but you can watch this process while checking the files and sizes in the directory.</p>
<p>While debugging URL Filtering in general, you may stumble over <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk35196">sk35196</a> which describes several procedures with the <code>avsu_client </code>command and optional parameters. Please note that Check Point changed the URL Filtering provider, I think with HFA50, from SurfControl to SecureComputing. This engine change comes together with a change in the parameters when you call <code>avsu_client</code>. The application name &#8220;URL Filtering&#8221; does not provide valid output when you use the SecureComputing engine, you have to use &#8220;URL Filtering2&#8243; to get actual results from the installation.</p>
<p><code>avsu_client -app "URL Filtering" fetch<br />
 failed to fetch signature update<br />
 err_str=Failed. Message from module: "Server has no available updates".<br />
info=<br />
Local version is  date</code></p>
<p><code>avsu_client -app "URL Filtering2" fetch<br />
 signature file up to date<br />
 err_str=Succeeded. Existing signature is up-to-date.<br />
info=<br />
Local version is  date</code></p>
<p>Sadly just calling <code>avsu_client </code>gives no explanation about the changed parameters, it only lists &#8220;URL Filtering&#8221;.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/05/url-filtering-update-error/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>R71 released</title>
		<link>http://blog.lachmann.org/2010/04/r71-released/</link>
		<comments>http://blog.lachmann.org/2010/04/r71-released/#comments</comments>
		<pubDate>Fri, 30 Apr 2010 07:59:14 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Software Blades]]></category>
		<category><![CDATA[UTM-1]]></category>
		<category><![CDATA[VPN-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=237</guid>
		<description><![CDATA[The version R71 was released. See this article for details. The release notes can be found here. I will test the upgrade from R70.30 to R71 today and get back to you with more feedback. Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>The version R71 was released. See this <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk44675">article</a> for details. The release notes can be found <a href="http://supportcontent.checkpoint.com/documentation_download?id=10330">here</a>.</p>
<p>I will test the upgrade from R70.30 to R71 today and get back to you with more feedback.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/04/r71-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t shoot the messenger</title>
		<link>http://blog.lachmann.org/2010/04/imho/</link>
		<comments>http://blog.lachmann.org/2010/04/imho/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 17:26:50 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[CPUG]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=232</guid>
		<description><![CDATA[Some days ago I was informed by a friend of mine that he nearly lost his status as a Check Point partner. What has happened? Well, he was openly speaking in the Check Point User Group (CPUG) forum about the new software blade licensing and what he liked and disliked about it. Instead of appreciating [...]]]></description>
			<content:encoded><![CDATA[<p>Some days ago I was informed by a friend of mine that he nearly lost his status as a Check Point partner. </p>
<p>What has happened?</p>
<p>Well, he was openly speaking in the Check Point User Group (CPUG) forum about the new software blade licensing and what he liked and disliked about it. Instead of appreciating open feedback, Check Point got angry about this.</p>
<p>We had hard times selling the advantages of software blades to the customers and nearly no one bought the upgrade.<br />
That&#8217;s why Check Point changed the cost for upgrades in the end, because of all the negative feedback.</p>
<p>So, what&#8217;s my point about this?</p>
<p>Like <a href="http://en.wikipedia.org/wiki/Shooting_the_messenger">Shakespeare</a> said: &#8220;<a href="http://en.wikipedia.org/wiki/Shooting_the_messenger">Don&#8217;t shoot the messenger</a>!&#8221;</p>
<p>Partners and also certified professionals are brand ambassadors for Check Point in front of the customers.</p>
<p>So maybe it&#8217;s a good idea to get their feedback before major changes are announced and involve them as soon as possible in the process of development.</p>
<p>As for me, I had some really good conversations with guys from product management and development. They asked me about my customers, how they use the products and what I can and cannot sell to the customers. About the necessity of certain features and so on. And I appreciate this and I think this is the absolutely right way.</p>
<p>But unfortunately, as events have shown, this is not the way Check Point is following with everybody&#8230;. sad.</p>
<p>Tobias Lachmann</p>
<p>PS: The make the picture complete: since upgrade to software blades is free and we have great new features with the R70.x versions, we can easily argue the upgrade to the customer. </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/04/imho/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Criticial error messages and logs</title>
		<link>http://blog.lachmann.org/2010/04/criticial-error-messages-and-logs/</link>
		<comments>http://blog.lachmann.org/2010/04/criticial-error-messages-and-logs/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 15:55:48 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=230</guid>
		<description><![CDATA[Today I want to bring your attention to SecureKnowledge article sk33219, which deals with &#8220;Critical error messages and logs&#8221;. There we have a nice list of possible error messages together with a short explanation why this error occured. I&#8217;m missing hints on how to resolve the issue or to a related sk. But all in [...]]]></description>
			<content:encoded><![CDATA[<p>Today I want to bring your attention to SecureKnowledge article <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk33219">sk33219</a>, which deals with &#8220;Critical error messages and logs&#8221;.</p>
<p>There we have a nice list of possible error messages together with a short explanation why this error occured.</p>
<p>I&#8217;m missing hints on how to resolve the issue or to a related sk. But all in all a very usefull article you should bookmark for further reference.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/04/criticial-error-messages-and-logs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Abra is USB-1 is Abra</title>
		<link>http://blog.lachmann.org/2010/04/abra-is-usb-1-is-abra/</link>
		<comments>http://blog.lachmann.org/2010/04/abra-is-usb-1-is-abra/#comments</comments>
		<pubDate>Sun, 18 Apr 2010 18:32:32 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=228</guid>
		<description><![CDATA[I wrote before about the new settings in R70 relase labeled USB-1. It turns out that I was right and this is refering to a Mobile VPN/Workplace solution. This was officially announced on CPX last week. By now I got some inside info about the name, very funny. Abra was the original code name for [...]]]></description>
			<content:encoded><![CDATA[<p>I wrote before about the new settings in R70 relase labeled USB-1. It turns out that I was right and this is refering to a Mobile VPN/Workplace solution. This was officially announced on CPX last week.</p>
<p>By now I got some inside info about the name, very funny. Abra was the original code name for this project. The final product should stick with the naming convention and be a &#8220;something-1&#8243;. So it came to USB-1. This was decided by a high level authority within Check Point, so the name was brought into the GUIs. But after a while they discovered that Abra was the better name to place the product in the market and so it was allowed to stay. But at this time, it was to late to change the GUIs as they were delivered with HFA of R70.</p>
<p>Will be interesting to see how the market reacts to Abra, but I would predict good feedback for this product. Better and easier as setting up notebooks and vpn clients for users or external contractors, just give them a stick and there they go.</p>
<p>Only the import/export feature could be better. In my opinion the stick should act transparent on a PC with Endpoint Security Media Encryption installed, as normal USB sticks do. So in the company transfer data to Abra and work on them later at home. And if you loose the stick, everything is still encrypted.</p>
<p>I&#8217;m curious how the product will evolve but I&#8217;m expecting more good things to come.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/04/abra-is-usb-1-is-abra/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When to use UTM-1 appliances &#8211; and when not</title>
		<link>http://blog.lachmann.org/2010/04/when-to-use-utm-1-appliances-and-when-not/</link>
		<comments>http://blog.lachmann.org/2010/04/when-to-use-utm-1-appliances-and-when-not/#comments</comments>
		<pubDate>Sun, 18 Apr 2010 18:20:53 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=225</guid>
		<description><![CDATA[In the year 2007 Check Point introduced the UTM-1 appliances. We sold a lot of these, because they had a good value for the money and they were an easy way to quickly deploy stand-alone cluster setups. The old software license for a gateway with unlimited IP addresses was more expensive than a UTM-1, when [...]]]></description>
			<content:encoded><![CDATA[<p>In the year 2007 Check Point introduced the UTM-1 appliances. We sold a lot of these, because they had a good value for the money and they were an easy way to quickly deploy stand-alone cluster setups.<br />
The old software license for a gateway with unlimited IP addresses was more expensive than a UTM-1, when you included also the hardware to run the gateway on. And UTM-1 appliances brought more with them for free. On example is SmartDirectory to get user data out of LDAP-Directories/ADs, another is Management High-Availability to sync primary and secondary SmartCenter running on the appliances.</p>
<p>So, why did I choose this headline? Why asking the question, when not to use UTM-1 appliances?</p>
<p>Well, Check Point promoted Messaging Security at the beginning, later one the Total Security Package which offered Antispan, Antivirus and URL-Filtering. The idea to have all this functions together on one gateway that has to deal with the network traffic anyway sounded smart. And it is, believe me. What was not smart was to ability to use these functions on every gateway&#8230; which customers did.<br />
The UTM-1 270 for example has a Celeron M 60 MHz CPU in it, together with only 1 GB of RAM. The 570 series has a Celeron M with 1.5 GHz CPU and also 1 GB RAM. Could you really believe that this hardware is capable of dealing with Firewall rules, VPN, SmartCenter functions and all the Content Inspection at once? Turns out they can&#8217;t. We&#8217;ve seen enormous CPU loads in the field, together with tremendous utilisation of I/O. The installation of a policy nearly took down the systems and users experienced connection loss from that. The reason for the later seems to be that at the beginning Check Point started to many instances of the security servers for the scanning. This was fixed in a HFA and is actually no longer existing. But the bad I/O performance still remains. Well, every intercepted download has to be writen to the harddrive and scanned. If it&#8217;s compressed, it had to be uncompressed before scanning. This creates high load for sure.</p>
<p>Even the bigger UTM-1 2050 appliances had only a Pentium 4 mit 3.4 GHz and 2 GB of RAM in it. More powerful, true. But not really enough power anyway. And I/O still sucked.</p>
<p>Ok, let&#8217;s get back to the initial question. When should I use an UTM-1 appliance?</p>
<p>I think that these appliances do their best job purely as Firewall and/or VPN gateway. We like to use them in dedicated customer environments like Web Shops our web server housings. Depending on customers need and prerequisits you can deploy the appliances a single gateway or HA-cluster. Managed by a bigger SmartCenter or self-managed, together with Management HA.</p>
<p>When should I not use an UTM-1 appliance?</p>
<p>In case you want to use content inspection, stick with a software license and run it on an OpenServer. There you can increase the memory and use dual-core CPUs. You can get better harddisc performance with specialised controllers and maybe just add more discs and have a RAID 0. Since they introduced the new Multi-Core licensing where you pay for the amount of CPUs you want to use, this is getting really affordable. The SG203-U license togehter with the desired content inspection blades is the best combination, even for demanding environments.</p>
<p>Oh, I forgot one thing: when you buy an UTM-1 appliance, you have to stick with the number of network interface. On an OpenServer, just add additional network cards as needed until all slots are filled. Even GE or 10GE is no big deal.</p>
<p>So, the use of an UTM-1 appliance depends on the scenario where you want to deploy it. Carefully think about it and then choose your solution. Have in mind that an appliance may be cheaper thaen software plus OpenServer hardware. But if your users complain about the performance, handling only a few service calls can eat up the safings from an appliance.</p>
<p>Finally I want to mention some things that are unique to the UTM-1 appliances and that you loose when choosing SPLAT on OpenServer. First the image management, which is quite good. Easy to use and perfect for rollback operations after major changes in your environment. Second the ability to crash recover an appliance through the front panel and the use of a prepared USB stick to deploy the initial configuration. Very cool feature for remote locations.</p>
<p>Hopefully we&#8217;ll see performance improvements with upcoming GAIA even on single core machines through new code, so that we can use the UTM-1 appliances with all features again. Wait and see..</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/04/when-to-use-utm-1-appliances-and-when-not/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DLP = Data Loss Prevention</title>
		<link>http://blog.lachmann.org/2010/04/dlp-data-loss-prevention/</link>
		<comments>http://blog.lachmann.org/2010/04/dlp-data-loss-prevention/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 17:43:10 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=222</guid>
		<description><![CDATA[Check Point announced DLP as a product at the CPX2010. DLP stands for Data Loss Prevention and is a solution to make sure that specific data is not leaving the company &#8211; wether it&#8217;s intended or unintended. Basically it&#8217;s an extension of the gateways capability to intercept and scan emails, http and ftp traffic and [...]]]></description>
			<content:encoded><![CDATA[<p>Check Point announced DLP as a product at the CPX2010. DLP stands for Data Loss Prevention and is a solution to make sure that specific data is not leaving the company &#8211; wether it&#8217;s intended or unintended.</p>
<p>Basically it&#8217;s an extension of the gateways capability to intercept and scan emails, http and ftp traffic and react to the content found. Works kinda like the antivirus scanning that we know for some time now. So it&#8217;s transparent to the users and the mail/web servers that are part of the communication.</p>
<p>The administrator defines a policy for his content and the direction where it is send. For example you can block mails to recipients outside your organisation if an attachment to that mail derives from a template which is used for confidential content. Or the attachment or the mail itself contains some keywords that are suspicios if they are used too many times. Because of the predefined data-types, Check Point speaks of 250 by now, I found it very easy to be going with this in a short period of time.</p>
<p>The action for the rules can be just logging, prevention of sending the content or asking the user what to do. As always, Check Point has a client for Windows operating systems only by now. This clients notifies the user with a popup that something has been blocked. The user can decide to send it anyway, discard or review the incident. Also it can be configured that the user has to type a justification for sending, if the mail is caught by the policy at first.</p>
<p>If you&#8217;re not using a resident client on your machine, an email notification is the second way to notify the user. The email informs you and is offering links where you can click. The links points to an application on the gateway, reachable over a webserver. Depending on your decision, the content is released or held back. As an alternative you can reply to this notification email and add keywords to the subject. The gateway will see this keyword when the mail goes through it and follow your decision.</p>
<p>All in all I find this solution easy to configure and implement. But to be sure we have to wait until GA of DLP. Interesting will be, how good the custom configuration of data types and rules will be. DLP has the possibility to create own types by using regular expressions. But as you might know, working with RE can be a pain in the ass.</p>
<p>So, in what flavors is this DLP solution offered? Well, we have two appliances, DLP-1 2571 and DLP-1 9571. The smaller one states that it can process 70.000 messages per hour and has a througput of 700 MBit/s. The bigger one 350.000 messages ans 2.5 GBit/s. As this are marketing numbers, we should cut them in half &#8211; at least. To be sure, we should assume only 1/4 the capacity stated, judging by the experience with UTM-1 appliances and Messaging Security in the past. The smaller appliances has a price of $14990 for the first year and $7000 for the following years, the bigger $49990 for the first and $12000 for the following years.</p>
<p>Or you have your DLP solution on your normal perimeter gateway, which I find more useful. We have three blades, CPSB-DLP-500, CPSB-DLP1500 and CPSB-DLP-U. The last part stands for the number of recommended users, but I&#8217;m not sure if there&#8217;s some kind of enforcement like with ip addresses at the gateway blades. We&#8217;ll have to wait for licensing info on that topic. The 500 user blade is $3000, the 1500-blade is $7000 and unlimited users come for $12000. The DLP is a service blade, so the numbers are per year.</p>
<p>If someone want&#8217;s to use this, and I bet many companies will, I think that the best solution is to buy a software blade container together with the DLP-blade and run it on an OpenServer under SPLAT. SPLAT is the only supported platform by the way. The server is about $4000 for a HP DL360, IBM 3350 M2 or similar, $12500 for a 4 core container and $3000-$12000 for the desired blade. For the first year this is starting at $19500 and $5250 for the following years. The advantage that I see in contrast to the appliances is more performance through cores, memory and hard discs. Especially hard dics performance was the bottleneck that we saw on most appliances running other content inspection software like Messaging Security etc.</p>
<p>So, what&#8217;s the bottom line:<br />
First of all, I&#8217;m excited and think this is a good product. Unlike other new releases like SmartProvisioning, SmartWorkflow etc. I think this solution is ready to be used from the start. And second I&#8217;m curios how customers will use this solution. I think we can expect some demanding requirements for rules we havn&#8217;t even thought of by now <img src='http://blog.lachmann.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Start checking out DLP <a href="http://www.checkpoint.com/products/dlp/index.html#tabID2#top">here </a> or in the <a href="https://pricelist.checkpoint.com/pricelist/US/PLUSswblades/GeneralPL.jsp#DLP">pricelist</a>. </p>
<p>As soon as I get this to work in an live environment, I will post my findings!</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/04/dlp-data-loss-prevention/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>R70.30 is there</title>
		<link>http://blog.lachmann.org/2010/04/r70-30-is-there/</link>
		<comments>http://blog.lachmann.org/2010/04/r70-30-is-there/#comments</comments>
		<pubDate>Mon, 12 Apr 2010 20:27:27 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=220</guid>
		<description><![CDATA[Folks, the new R70.30 is available. See the release notes here All in all some minor fixes. The biggest point is the possibility to use sub-CAs for SSL-VPN, which was not possible in the past. Other improvements include Windows 7 support for SmartWorkflow and some Non-English regional formats for map visualization. Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>Folks,</p>
<p>the new R70.30 is available. See the release notes <a href="http://downloads.checkpoint.com/dc/download.htm?ID=10694">here</a><br />
All in all some minor fixes. The biggest point is the possibility to use sub-CAs for SSL-VPN, which was not possible in the past.</p>
<p>Other improvements include Windows 7 support for SmartWorkflow and some Non-English regional formats for map visualization.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/04/r70-30-is-there/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I&#8217;m back!</title>
		<link>http://blog.lachmann.org/2010/04/im-back/</link>
		<comments>http://blog.lachmann.org/2010/04/im-back/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 17:48:24 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=218</guid>
		<description><![CDATA[Hello everybody! I&#8217;m back from my parental leave, which lasted till the end of March. During that period, I spend all the time with my son but no time with this blog. Now I&#8217;m back at work and I see interesting things everyday that give me inspirations for articles, so expect new content soon. What [...]]]></description>
			<content:encoded><![CDATA[<p>Hello everybody!</p>
<p>I&#8217;m back from my parental leave, which lasted till the end of March. During that period, I spend all the time with my son but no time with this blog. </p>
<p>Now I&#8217;m back at work and I see interesting things everyday that give me inspirations for articles, so expect new content soon.</p>
<p>What also happended is that I gained the CCSE R70 certification for contributing to the new CCSE exam. Thanks Ken Finley, this is greatley appreciated! Now I&#8217;m done with re-certification until CCSE+ comes out.</p>
<p>Bye for now</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/04/im-back/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Geo Protection &#8211; new in R70.20</title>
		<link>http://blog.lachmann.org/2010/01/geo-protection-new-in-r70-20/</link>
		<comments>http://blog.lachmann.org/2010/01/geo-protection-new-in-r70-20/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 16:20:07 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=211</guid>
		<description><![CDATA[A cool feature was introduced with R70.20 which is called Geo Protection. It is part of the IPS blade and you need to have a proper IPS blade license for that. What it does is the mapping from IP addresses to countries over a database (not sure yet which database CP bought) and then block [...]]]></description>
			<content:encoded><![CDATA[<p>A cool feature was introduced with R70.20 which is called Geo Protection. It is part of the IPS blade and you need to have a proper IPS blade license for that.</p>
<p>What it does is the mapping from IP addresses to countries over a database (not sure yet which database CP bought) and then block connections by countries.</p>
<p>You can block connections TO or FROM a specific country and you can also define exceptions for that rules, like with other IPS protections. The actual policy of blocking/allowing is displayed in a world map overview and gives an easy overview.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/01/geo_protection2.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/01/geo_protection2.jpg" alt="" title="geo_protection2" width="499" height="541" class="alignnone size-full wp-image-212" /></a></p>
<p>When traffic is examined and blocked by Geo Protection, we get nice logs entries in SmartView Tracker.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/01/geo_protection.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/01/geo_protection.jpg" alt="" title="geo_protection" width="500" height="476" class="alignnone size-full wp-image-213" /></a></p>
<p>This feature is also good for logging, as you can just accept any traffic but log the connections and determine this way, what countries access the resources behind the firewall or were your users get their webpages from.</p>
<p>Only catch here is licensing: this only works with R70.20 SmartCenter und Gateways which have both proper R70 Software Blade licensing. But hey, it&#8217;s free of charge and some sort of bonus to those who converted their licenses already <img src='http://blog.lachmann.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>I hope they put more features into Geo Protection or link it to normal IPS protections and/or the rulebase. Cool scenarios we can think of&#8230;.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/01/geo-protection-new-in-r70-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Neighbour table overflow</title>
		<link>http://blog.lachmann.org/2010/01/neighbour-table-overflow/</link>
		<comments>http://blog.lachmann.org/2010/01/neighbour-table-overflow/#comments</comments>
		<pubDate>Sun, 17 Jan 2010 20:19:09 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=204</guid>
		<description><![CDATA[Under SecurePlatform you can sometimes see the following message in /var/log/messages Jan 15 13:44:08 fw1 kernel: Neighbour table overflow. This refers to the ARP cache a.k.a. Neighbour table. If you&#8217;re running a gateway with lot&#8217;s of interfaces or big subnets, you might see many nodes over Layer-2, so communication to them fills your ARP table [...]]]></description>
			<content:encoded><![CDATA[<p>Under SecurePlatform you can sometimes see the following message in /var/log/messages</p>
<blockquote><p><code>Jan 15 13:44:08 fw1 kernel: Neighbour table overflow.</code></p></blockquote>
<p>This refers to the ARP cache a.k.a. Neighbour table.</p>
<p>If you&#8217;re running a gateway with lot&#8217;s of interfaces or big subnets, you might see many nodes over Layer-2, so communication to them fills your ARP table and sometimes overflows it, which can lead to connectivity errors.</p>
<p>The ARP cache table has a maximum size, which can be displayed with <code>cat /proc/sys/net/ipv4/neigh/default/gc_thresh3</code>.<br />
You can verify the actual amount of ARP entries either with <code>arp -an | wc -</code>l or with <code>ip neighbor show |wc -l</code>. Proxy ARP entries are only displayed when using the arp command.</p>
<p>Periodically and automatically the entries in the ARP cache are verified. At a specified interval, a garbage collector is running and removes entries that are no longer used. The interval can be verified with <code>cat /proc/sys/net/ipv4/neigh/default/gc_interval</code>, by default it&#8217;s 30 seconds.</p>
<p>The garbage collector is controlled by three variables:<br />
<strong>gc_thresh1</strong>, which is the minimum number of entries in the ARP cache. If the actual number of entries are below this value, the garbage collector will not run.</p>
<p><strong>gc_thresh2</strong>, which is the soft maximum number of entries. If the actual number of entries is above this value for more than 5 seconds, the garbage collector will run.</p>
<p><strong>gc_thresh3</strong>, which is the hard maximum number of entries. If the actual number of entries is above this value, the garbage collector with immediately run.</p>
<p><strong>gc_thresh3</strong> is also the maximum value of ARP entries that can be kept in the table.</p>
<p>The default values are quite low, so you might want to increase them. </p>
<p>You can do this on the fly with the following CLI commands:</p>
<p><code>sysctl -w net.ipv4.neigh.default.gc_thresh3=4096<br />
sysctl -w net.ipv4.neigh.default.gc_thresh2=2048<br />
sysctl -w net.ipv4.neigh.default.gc_thresh1=1024</code></p>
<p>This does not survice a reboot.</p>
<p>To survive a reboot, add this lines in the <code>/etc/sysctl.conf </code>file<br />
<code><br />
net.ipv4.neigh.default.gc_thresh3 = 4096<br />
net.ipv4.neigh.default.gc_thresh2 = 2048<br />
net.ipv4.neigh.default.gc_thresh1 = 1024</code></p>
<p>Afterwards run the command <code>sysctl -p</code> for the changes to take effect and then reboot.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/01/neighbour-table-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Backup error in R70.20 SPLAT</title>
		<link>http://blog.lachmann.org/2010/01/backup-error-in-r70-splat/</link>
		<comments>http://blog.lachmann.org/2010/01/backup-error-in-r70-splat/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 15:30:03 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=201</guid>
		<description><![CDATA[Yesterday we did an inplace-upgrade of a SPLAT box to R70.20 from NGX R65. Since then, the scheduled backup was broken. When I tried to edit the settings through the WebUI, I got the message GENERAL ERROR. Fix for this was to disable the scheduled backup on the command line with backup -e off. Then [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday we did an inplace-upgrade of a SPLAT box to R70.20 from NGX R65. Since then, the scheduled backup was broken. When I tried to edit the settings through the WebUI, I got the message GENERAL ERROR.</p>
<p>Fix for this was to disable the scheduled backup on the command line with <code>backup -e off</code>.<br />
Then I was able to edit all the settings through the WebUI again and backup is working now.</p>
<p>This seems to be an error in R70.20, because we had another customer with this error who upgraded from R70.1 to R70.20 and it was working with R70.1</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/01/backup-error-in-r70-splat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USB-1 is coming</title>
		<link>http://blog.lachmann.org/2010/01/usb-1-is-coming/</link>
		<comments>http://blog.lachmann.org/2010/01/usb-1-is-coming/#comments</comments>
		<pubDate>Mon, 11 Jan 2010 11:51:25 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=195</guid>
		<description><![CDATA[I just found a new section in the Global Properties of my R70.20 SmartConsole labeled &#8220;USB-1&#8243;. Judging by the settings, this USB-1 is the SecureWorkspace/VPN-Client that comes on a secured USB stick and enables you to connect securely to your company without the need to install software on a client computer. Will be interessting to [...]]]></description>
			<content:encoded><![CDATA[<p>I just found a new section in the Global Properties of my R70.20 SmartConsole labeled &#8220;USB-1&#8243;.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/01/usb-1.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/01/usb-1.jpg" alt="" title="usb-1" width="500" height="318" class="alignnone size-full wp-image-196" /></a></p>
<p>Judging by the settings, this USB-1 is the SecureWorkspace/VPN-Client that comes on a secured USB stick and enables you to connect securely to your company without the need to install software on a client computer.</p>
<p>Will be interessting to see when this is officially released and what the feature set will look like.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/01/usb-1-is-coming/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New SK regarding error with SIC renewal in R70</title>
		<link>http://blog.lachmann.org/2010/01/new-sk-regarding-error-with-sic-renewal-in-r70/</link>
		<comments>http://blog.lachmann.org/2010/01/new-sk-regarding-error-with-sic-renewal-in-r70/#comments</comments>
		<pubDate>Sun, 10 Jan 2010 20:00:29 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=193</guid>
		<description><![CDATA[Just found the new sk43744, which describes that the automatic certificate renewal will fail in R70, R70.1 and R70.20. This is a problem when you upgraded from an older installation in-place, where the CA is kept. Since certificates are fundamental for the way Check Point software works, please take this seriously. Otherwise policy installation, log [...]]]></description>
			<content:encoded><![CDATA[<p>Just found the new sk43744, which describes that the automatic certificate renewal will fail in R70, R70.1 and R70.20. This is a problem when you upgraded from an older installation in-place, where the CA is kept. Since certificates are fundamental for the way Check Point software works, please take this seriously. Otherwise policy installation, log receiving and SmartConsole connections to SmartCenter are affected.</p>
<p>Normally SIC certificates are automatically renewd 15 month before expiration.To determine if you have a problem that needs to be fixed, verify the expiration date of your SIC certificates and follow the procedure in the sk43744.</p>
<p>Please note that the command line <code>cpca_client lscert -stat Valid -kind SIC </code> is not a valid alternative, as it produces an ouput with wrong dates, so you have to use the ICA web.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/01/new-sk-regarding-error-with-sic-renewal-in-r70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identity Logging with R70.20</title>
		<link>http://blog.lachmann.org/2010/01/identity-logging-with-r70-20/</link>
		<comments>http://blog.lachmann.org/2010/01/identity-logging-with-r70-20/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 16:51:21 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=181</guid>
		<description><![CDATA[I just installed the R70.20 update on our SmartCenter Server. We can now use the Identity Logging feature, which is very cool. It is an update of Logging &#038; Status blade and is used to associate IP addresses of workstations to users, working on this machine. It works only with Active Directory servers running on [...]]]></description>
			<content:encoded><![CDATA[<p>I just installed the R70.20 update on our SmartCenter Server. We can now use the Identity Logging feature, which is very cool. It is an update of Logging &#038; Status blade and is used to associate IP addresses of workstations to users, working on this machine. It works only with Active Directory servers running on Windows Server 2003 and 2008, but this is ok with me. SmartCenter has to run SPLAT/Linux or Windows Server 2003/2008.</p>
<p>After configuration, a table with the association of IP and user name is held on the SmartCenter and this information, if available, is displayed in the log entries on SmartView Tracker.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/01/identitylogging.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/01/identitylogging.jpg" alt="" title="SmartView Tracker entry with information from Identity Logging" width="500" height="314" class="alignnone size-full wp-image-184" /></a></p>
<p>Configuration is done an SmartCenter object -> Logs and Masters -> Identity Logging. Only a few things to fill in.</p>
<p><a href="http://blog.lachmann.org/wp-content/uploads/2010/01/id_config.jpg"><img src="http://blog.lachmann.org/wp-content/uploads/2010/01/id_config.jpg" alt="Configuration of Identity Logging in SmartCenter" title="Configuration of Identity Logging in SmartCenter" width="500" height="550" class="size-full wp-image-182" /></a></p>
<p>It&#8217;s easy, but I would have expected to find an LDAP accounting unit here, like you configure AD servers within SmartDirectory.<br />
Just for using Identity Logging, this is easy to implement. When you have already a SmartDirectory configuration, you&#8217;re doing the job twice.</p>
<p>This feature is only available with R70.20 on a SmartCenter which works with Software Blade licenses. A little incentive for those who changed to the new licenses <img src='http://blog.lachmann.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/01/identity-logging-with-r70-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Migration to Software Blades with CPVP-VCT-U license</title>
		<link>http://blog.lachmann.org/2010/01/migration-to-software-blades-with-cpvp-vct-u-license/</link>
		<comments>http://blog.lachmann.org/2010/01/migration-to-software-blades-with-cpvp-vct-u-license/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 13:01:58 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=178</guid>
		<description><![CDATA[Following the current promotion, you can trade-in your old license with no additional cost for a Software Blade license that has equivalent functionality. Now I discovered that with the CPVP-VCT-U license you&#8217;re not getting a proper equivalent, as SecureXL is missing in the new license. This error was reported to Check Point and is acknowledged. [...]]]></description>
			<content:encoded><![CDATA[<p>Following the current promotion, you can trade-in your old license with no additional cost for a Software Blade license that has equivalent functionality. Now I discovered that with the CPVP-VCT-U license you&#8217;re not getting a proper equivalent, as SecureXL is missing in the new license.</p>
<p>This error was reported to Check Point and is acknowledged. They will fix it in the next days and publish new Upgrade calculator and Upgrade matrix.</p>
<p>No big deal really, as you always get CoreXL accelleration with R70. SecureXL might no be necessary for most users, taking the aspect of performance.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/01/migration-to-software-blades-with-cpvp-vct-u-license/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Determine UTM-1 appliance series from CLI</title>
		<link>http://blog.lachmann.org/2010/01/determine-utm-1-appliance-series-from-cli/</link>
		<comments>http://blog.lachmann.org/2010/01/determine-utm-1-appliance-series-from-cli/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 11:14:16 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=172</guid>
		<description><![CDATA[If you want to know which appliance series you have, you can use a command line tool to determine this information. Just run /usr/sbin/dmidecode &#124; grep "Product Name" Sample output: [Expert@xxx-fw1]# /usr/sbin/dmidecode &#124; grep "Product Name" Product Name: U-30-00 Product Name: [Expert@yyy-cp1]# /usr/sbin/dmidecode &#124; grep "Product Name" Product Name: C6P_UTM Product Name: NSA-1086 Here are [...]]]></description>
			<content:encoded><![CDATA[<p>If you want to know which appliance series you have, you can use a command line tool to determine this information.</p>
<p>Just run <code>/usr/sbin/dmidecode | grep "Product Name"</code></p>
<p>Sample output:</p>
<blockquote><p><code>[Expert@xxx-fw1]# /usr/sbin/dmidecode | grep "Product Name"<br />
                Product Name: U-30-00<br />
                Product Name:</code></p></blockquote>
<blockquote><p><code>[Expert@yyy-cp1]# /usr/sbin/dmidecode | grep "Product Name"<br />
                Product Name: C6P_UTM<br />
                Product Name: NSA-1086</code></p></blockquote>
<p>Here are the translation for the information under the field Product Name:</p>
<ul>
<li>P-20-00 -> Power-1 9070 Appliance</li>
<li>P-10-00 -> Power-1 5070 Appliance</li>
<li>U-40-00 -> UTM-1 3070 Appliance</li>
<li>U-30-00 -> UTM-1 2070 Appliance</li>
<li>U-20-00 -> UTM-1 1070 Appliance</li>
<li>U-15-00 -> UTM-1 570 Appliance</li>
<li>U-10-00 -> UTM-1 270 Appliance</li>
<li>U-5-00 -> UTM-1 130 Appliance</li>
<li>C6P_UTM -> UTM-1 2050 Appliance</li>
<li>C6_UTM  -> UTM-1 1050 Appliance</li>
<li>C2_UTM  -> UTM-1 450 Appliance</li>
</ul>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/01/determine-utm-1-appliance-series-from-cli/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Check Point is listening!</title>
		<link>http://blog.lachmann.org/2010/01/check-point-is-listening/</link>
		<comments>http://blog.lachmann.org/2010/01/check-point-is-listening/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 16:16:54 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=169</guid>
		<description><![CDATA[On December 21st I wrote about my latest experience with Software Blade licenses, a couple of days later I received an email from Check Point about this posting. They asked me if I would be willing to share my experience with this incident and licensing in general with them to generate some improvement in the [...]]]></description>
			<content:encoded><![CDATA[<p>On December 21st I wrote about my latest experience with Software Blade licenses, a couple of days later I received an email from Check Point about this posting. They asked me if I would be willing to share my experience with this incident and licensing in general with them to generate some improvement in the process. Today we had a long phone conference with a very good and productive discussion and I can see the effort at Check Point in improving.</p>
<p>I also had a couple a phone calls with developers and product managers in the past month, were they wanted me to share my experience with specific products and also my opinion about new products and recent changes with them.</p>
<p>So you can really say: Check Point is listening!</p>
<p>I&#8217;m really glad they&#8217;re doing this and I think this is the right way to be more sucessful &#8211; side by side with the partners and customers, listening to their needs.</p>
<p>Check Point: keep on with the good work!</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/01/check-point-is-listening/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enlarging UTM-1 partitions</title>
		<link>http://blog.lachmann.org/2010/01/enlarging-utm-1-partitions/</link>
		<comments>http://blog.lachmann.org/2010/01/enlarging-utm-1-partitions/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 21:49:37 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=164</guid>
		<description><![CDATA[Some users may experience problems with full partitions on Check Point UTM-1 appliances, most likely with the partition holding the log files as this partition is small, especially at the first appliance series. When you install SecurePlatform, all partitions have fixed sizes except for /var which gets the remaining free space after the creation of [...]]]></description>
			<content:encoded><![CDATA[<p>Some users may experience problems with full partitions on Check Point UTM-1 appliances, most likely with the partition holding the log files as this partition is small, especially at the first appliance series.</p>
<p>When you install SecurePlatform, all partitions have fixed sizes except for <code>/var </code>which gets the remaining free space after the creation of the other partitions. Because logs are stored in <code>/var/opt/CPsuite-R70/fw1/log</code>, there&#8217;s rarely trouble with disc space.</p>
<p>The UTM-1 appliance work different as they use the Logical Volume Manager (LVM) for handling the partitions. The LVM is assigning the hard disc space to the partitions and allows resizing of partitions.</p>
<p>However, the filesystem is untouched when you resize a partition. So following <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk33179">sk33179 </a> doesn&#8217;t give you additional space for your logs.</p>
<p>To achieve this goal you first have to resize the partitions:</p>
<ol>
<li>View the name of the log partition with <code>lvdisplay</code>, most likely, this name is <code>/dev/vg_splat/lv_log</code>.</li>
<li>Then resize with<br />
<code>lvresize -L 30GB /dev/vg_splat/lv_log</code>.<br />
 In this example the partition is resized to 30GB.</li>
</ol>
<p>Reboot the appliance with serial console attached. Access the boot menu by pressing a key when prompted and boot into maintenance mode.</p>
<p>Then execute this commands:</p>
<p><code>umount /dev/mapper/vg_splat-lv_log<br />
e2fsck -f /dev/mapper/vg_splat-lv_log<br />
resize2fs /dev/mapper/vg_splat-lv_log</code></p>
<p>This modifies the filesystem and brings it to the new partition size.<br />
Reboot the appliance afterwards and verify with the <code>df -h</code> command that you accomplished the resizing of partition and filesystem correctly.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/01/enlarging-utm-1-partitions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Great R70 Performance Optimization Guide</title>
		<link>http://blog.lachmann.org/2010/01/great-r70-performance-optimization-guide/</link>
		<comments>http://blog.lachmann.org/2010/01/great-r70-performance-optimization-guide/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 21:13:51 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=162</guid>
		<description><![CDATA[Check Point has a great Performance Optimization Guide that describes the technology of SecureXL, CoreXL and ClusterXL. It also gives good explanations and hints on how to improve performance. Highly recommended for reading. Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>Check Point has a great <a href="http://downloads.checkpoint.com/dc/download.htm?ID=8711">Performance Optimization Guide </a>that describes the technology of SecureXL, CoreXL and ClusterXL. It also gives good explanations and hints on how to improve performance. Highly recommended for reading.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2010/01/great-r70-performance-optimization-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Inside Check Point licensing</title>
		<link>http://blog.lachmann.org/2009/12/inside-check-point-licensing/</link>
		<comments>http://blog.lachmann.org/2009/12/inside-check-point-licensing/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 21:26:21 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Software Blades]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=152</guid>
		<description><![CDATA[One of our customer bought a new UTM-1 2070 appliance. This device comes with 3 managed sites. Now he wants to manage more sites and brought up the question, if he can use a SmartCenter unlimited license he already owns. Just purchasing normal support for SCT-U is cheaper than buying an SXA license and the [...]]]></description>
			<content:encoded><![CDATA[<p>One of our customer bought a new UTM-1 2070 appliance. This device comes with 3 managed sites.</p>
<p>Now he wants to manage more sites and brought up the question, if he can use a SmartCenter unlimited license he already owns. Just purchasing normal support for SCT-U is cheaper than buying an SXA license and the needed support for this license.</p>
<p>I don&#8217;t know if Check Point license policy is allowing that use, but from a technical point of view we can verify if this works.<br />
For that reason, we have to take a look inside the cp.macro file. This file has all the definitions of features and licenses.<br />
On SecurePlatform, you find this file under<code> /var/opt/CPshrd-R70/conf/cp.macro</code></p>
<p>If we look in the license for an UTM-1 2070, we find these two strings: <code>CPMP-UAPP-1-NGX CPXP-SXA-2-NGX</code><br />
The first is for the appliance itself, the second is the management extension for two additional sites.</p>
<p>Let&#8217;s break down the first one:<br />
For <code>CPMP-UAPP-1-NGX</code>, we have the following relevant entry:<br />
<code>MACRO ::CPMP-UAPP-1-NGX CPMP-UAPP-module-base-NGX CPMP-UAPP-management-base-NGX CPVP-UAPP-1-NGX</code></p>
<p>That means that actually the string is a macro itself and consists of <code>CPMP-UAPP-module-base-NGX</code>, <code>CPMP-UAPP-management-base-NGX</code> and <code>CPVP-UAPP-1-NGX</code>. </p>
<p>Let&#8217;s focus on <code>CPMP-UAPP-management-base-NGX</code>:<br />
<code>cp.macro</code> has this definition for it:<br />
<code>MACRO ::CPMP-UAPP-management-base-NGX  CPMP-SCT-1-NGX CPFW-AM-U-NGX CPMP-HA-MGMT-NGX CPMP-SMPO-NGX CPMP-EVRX-U-NGX</code></p>
<p>So this is another macro for the SmartCenter (CPMP-SCT-1), SmartDirectory (CPFW-AM-U), Management-HA (CPMP-HA-MGMT), SmartPortal (CPMP-SMPO) and Eventia Reporter (CPMP-EVRX-U).</p>
<p>We go for the SmartCenter part:<br />
<code>MACRO   ::CPMP-SCT-1-NGX        CPMP-EMC-1-NGX</code></p>
<p>Again a macro, so we need to investigate CPMP-EMC-1-NGX:<br />
<code>MACRO   ::CPMP-EMC-1-NGX        fw1:6.0:lcontrol fw1:6.0:vpnmgmt fw1:6.0:vpnstrong fw1:6.0:remote1 fw1:6.0:cluster-u</code></p>
<p>Now we&#8217;re close to the final answers <img src='http://blog.lachmann.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>The macro <code>fw1:6.0:lcontrol</code> has this definitions:<br />
<code>MACRO fw1:6.0:lcontrol  mgmtcore fwmgmt cpui qosmgmt cmpmgmt dbvr_unlimit cluster-u</code><br />
This breaks down to:</p>
<p><code>MACRO fw1:6.0:mgmtcore  cmd<br />
+--#DESCRIPT#fw1:6.0:cmd#Saving a file from the log viewer</p>
<p>MACRO fw1:6.0:fwmgmt    fwc filter<br />
+--#DESCRIPT#fw1:6.0:fwc#INSPECT compiler<br />
+--#DESCRIPT#fw1:6.0:filter#INSPECT code generation</p>
<p>MACRO fw1:6.0:cpui      policyui lvui sstui rtmui<br />
+--MACRO fw1:6.0:policyui  ui<br />
+--#DESCRIPT#fw1:6.0:ui#Policy User Interface<br />
+--MACRO fw1:6.0:lvui      fwlv<br />
+--#DESCRIPT#fw1:6.0:fwlv#FireWall-1 Log Viewer<br />
+#DESCRIPT#fw1:6.0:sstui#System Status User Interface<br />
+#DESCRIPT#fw1:6.0:rtmui#RTM User Interface  </p>
<p>MACRO fw1:6.0:qosmgmt   fgmgmt rtmmgmt<br />
+--#DESCRIPT#fw1:6.0:fgmgmt#FloodGate-1 Management<br />
+--#DESCRIPT#fw1:6.0:rtmmgmt#RTM Management</p>
<p>MACRO etm:6.0:cmpmgmt<br />
+--#DESCRIPT#etm:6.0:cmpmgmt#Compression management</p>
<p>dbvr_unlimit<br />
+--#DESCRIPT#fw1:6.0:dbvr_unlimit#Policy Versioning</p>
<p>cluster-u<br />
+--#DESCRIPT#fw1:6.0:cluster-u#Unlimited number of clusters for HA</code></p>
<p>Finally, we have found out the management related features hidden in the license:</p>
<ol>
Policy User Interface<br />
FireWall-1 Log Viewer<br />
Saving a file from the log viewer<br />
System Status User Interface<br />
RTM User Interface<br />
INSPECT code generation<br />
INSPECT compiler<br />
Policy Versioning<br />
Compression management<br />
Unlimited number of clusters for HA</ol>
<p>But it is not said, how many sites can be managed.<br />
This information is in the last &#8220;big&#8221; macro <code>CPMP-EMC-1-NGX</code>, coded in<br />
<code>fw1:6.0:remote1<br />
#DESCRIPT#fw1:6.0:remote#Allows remote management</code></p>
<p>So you can manage one site with this license, e.g. the UTM-1 appliance can manage itself.<br />
But the UTM-1 2070 comes with a 3 managed sites license.</p>
<p>This is defined in the <code>CPXP-SXA-2-NGX</code> addition to the UTM-1 license:<br />
<code>MACRO   ::CPXP-SXA-2-NGX                        fw1:6.0:remote2 fw1:6.0:cpxmgmt<br />
#DESCRIPT#CPXP-SXA-2-NGX#SmartCenter Extension for 2 additional sites; version: NGX;  3DES</code></p>
<p>We have remote1 and remote2, which comes to the count of 3 managed sites.</p>
<p>So, back to the initial question: can we use a SCT-U license for extending the managed sites of an UTM-1?</p>
<p><code>MACRO   ::CPMP-SCT-U-NGX        CPMP-EMC-U-NGX<br />
#DESCRIPT#CPMP-SCT-U-NGX#SmartCenter for an unlimited number of gateways;version: NGX;  3DES</code></p>
<p>Again, look into the next macro <code>CPMP-EMC-U-NGX</code></p>
<p><code>MACRO   ::CPMP-EMC-U-NGX        fw1:6.0:controlx                                fw1:6.0:vpnstrong<br />
#DESCRIPT#CPMP-EMC-U-NGX#Enterprise Management Console for an unlimited number of gateways; version: NGX;  3DES</code></p>
<p>From there we go into fw1:6.0:controlx:</p>
<p><code>MACRO fw1:6.0:controlx  control vpnmgmt</code></p>
<p>And further onto control:</p>
<p><code>MACRO fw1:6.0:control   remote lcontrol </code></p>
<p>We know the &#8220;lcontrol&#8221; macro from our investigation before, also the &#8220;remote&#8221; keyword.</p>
<p><code>#DESCRIPT#fw1:6.0:remote#Allows remote management</code><br />
As &#8220;remote&#8221; comes without any number, this means unlimited management.</p>
<p>To answer the question we began with: YES, you can use an unlimited SmartCenter license as an extension of the management capabilities of an UTM-1 appliance.<br />
From a technial point of view.</p>
<p>I will open a call with Check Point to make sure that this is actually permitted within the license regulations.</p>
<p>As you can see, licensing within Check Point products is complicated through the use of so many macros, but in the end it comes to a limited number of features that are encoded in the licenses.</p>
<p>If you will, you can chase down also the new Software Blade licenses with this scheme to see, what is actually enforced.</p>
<p>Tobias Lachmann</p>
<p><strong>UPDATE: Check Point just confirmed that the use of a SmartCenter license on a UTM-1 appliance is not permitted to extend the amount of managed sites. You have to stick with the SXA extensions or build up a separate SmartCenter.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/12/inside-check-point-licensing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;It&#8217;s Christmas, Theo. It&#8217;s the time of miracles, so be of good cheer&#8230;&#8221; &#8211; Hans Gruber in Die Hard</title>
		<link>http://blog.lachmann.org/2009/12/its-christmas-theo-its-the-time-of-miracles-so-be-of-good-cheer-hans-gruber-in-die-hard/</link>
		<comments>http://blog.lachmann.org/2009/12/its-christmas-theo-its-the-time-of-miracles-so-be-of-good-cheer-hans-gruber-in-die-hard/#comments</comments>
		<pubDate>Wed, 23 Dec 2009 20:40:35 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Software Blades]]></category>
		<category><![CDATA[VPN-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=141</guid>
		<description><![CDATA[Since Christmas is the time for kids making their wishlists, I will also give it a try and make my personal wishlist to Check Point. And as Christmas is also the time for miracles, maybe some of my wishes will come true in the next year&#8230;. we&#8217;ll see. SecurePlatform Image Management / Snapshots Well, we [...]]]></description>
			<content:encoded><![CDATA[<p>Since Christmas is the time for kids making their wishlists, I will also give it a try and make my personal wishlist to Check Point. And as Christmas is also the time for miracles, maybe some of my wishes will come true in the next year&#8230;. we&#8217;ll see.</p>
<p><strong>SecurePlatform</strong><br />
<em>Image Management / Snapshots</em><br />
Well, we have Gaia coming sooner or later. What I really would like to see in there is the Image Management of the UTM-1 Appliances. Better to handle as Snapshots for most tasks. A really great evolution would be a combination of both. Being able to create and store images locally, as well as taking snaphots/images and storing them over the net using SSH.<br />
Could make data recovery even more easy.<br />
Why not add a dialog during SPLAT installation, where you can choose to use Image Management with LVM or stay with the old partitioning. If Image Management is chosen, you should decide for yourself, how the space should be divided between /var and the image partition.</p>
<p><em>Time and Date settings</em><br />
Why can I set NTP parameters together with the GMT in the WebUI, but need to go to the CLI to set time zone?<br />
This should also appear in the WebUI.</p>
<p><em>Administrator Accounts</em><br />
I&#8217;d like to choose on creation which shell the accounts should use (bash or cpshell) and what the idle timeout of a session should be. Also the ability to scp something to the box using this account should be an option to enable here.</p>
<p><em>SNMP</em><br />
The SNMP settings should be configured using the WebUI. Also I&#8217;d like to have a download link to the current MIB on the box.</p>
<p><strong>SmartConsole</strong><br />
<em>Adding objects</em><br />
The new icon with the &#8220;+&#8221; sign on each cell is very helpful for quick-adding of objects. I&#8217;d like to have the opportunity to add a new object, too</p>
<p><em>Window resizing</em><br />
Some dialog boxes can&#8217;t be resized. Normally these fixed size dialog boxes have too much content and you must use scroll bars to see the content. Examples: Global Properties, Firewall object page, network object page. All windows should be resizable.</p>
<p><em>Gateway Topology </em><br />
I have to maintain a gateway cluster with more then 150 interfaces. Whenever I need to make a change to the interface configuration, I have to scroll to the entire list to find the right entry, since the list is unsorted. Not funny.<br />
I&#8217;d like to have the ability to sort the list by clicking on the column header.</p>
<p><strong>Troubleshooting</strong><br />
<em>InfoView</em><br />
We really need a more up to date and stable version of InfoView. Normally I need to try 2-3 times before I can open a cpinfo file because the tool crashes. As far as I known it&#8217;s not maintained any longer, but all support partner really need this!</p>
<p><strong>Endpoint Security</strong><br />
<em>SecureClient / Endpoint Connect</em><br />
Endpoint Connect should be the successor of SecureClient, but it isn&#8217;t really. EC lacks the personal firewall feature. For most SME customers the old SecureClient Desktop Policy feature was all they needed. Check Point should understand that Endpoint Security is not the answer to all demands.</p>
<p><em>Licensing</em><br />
Check Point does not offer a maintained, up to date VPN client without any costs. For using Endpoint Connect, a Endpoint Security Secure Access license is necessary if you want to use OfficeMode.<br />
Like Cisco, also Check Point should give away a full blown VPN-Client for free!</p>
<p><em>OS support</em><br />
Parts of Endpoint Security run on Windows 7? Congratulations. But why do we still have to struggle with VPN clients for MacOS or Linux? Why do we have to use an actual OS like Snow Leopard with a very, very old VPN client like SecureClient?<br />
I think that before integrating new features into Endpoint Security and all other products that have to be installed on clients, you should make sure that you have support for all common OS. Windows XP, Vista, 7 as well as MacOS 10.4, 10.5 and 10.6. Also a client for Linux (Debian, RedHat/CentOS, Ubuntu) should be available. </p>
<p><em>Version numbering</em><br />
I nearly lost it with the Endpoint Security version numbers, since it&#8217;s not any longer corresponding to the other products. Keep the version numbering more simple.</p>
<p>That&#8217;s it for now, but for sure I will extend my wish list in the next days&#8230; so much things CP needs to take care of.</p>
<p>Happy XMAS, everybody.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/12/its-christmas-theo-its-the-time-of-miracles-so-be-of-good-cheer-hans-gruber-in-die-hard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My trouble with Software Blade licenses</title>
		<link>http://blog.lachmann.org/2009/12/my-trouble-with-software-blade-licenses/</link>
		<comments>http://blog.lachmann.org/2009/12/my-trouble-with-software-blade-licenses/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 20:43:08 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=144</guid>
		<description><![CDATA[My latest experience was with our first customer that used all R70 licenses, instead of just upgrading to R70 but sticking with NGX licenses. Ok, what happened? In the User Center I found a container and some blades. I checked the container and licensed it by assigning an IP address to the container. Then I [...]]]></description>
			<content:encoded><![CDATA[<p>My latest experience was with our first customer that used all R70 licenses, instead of just upgrading to R70 but sticking with NGX licenses.</p>
<p>Ok, what happened? In the User Center I found a container and some blades. I checked the container and licensed it by assigning an IP address to the container. Then I attached the blades to the container. Afterwards I clicked on &#8220;Get license&#8221; and had my license file. I also got my contract file, too.</p>
<p>Then the nightmare happened when I installed the license to the customer system during our installation. Nothing worked! And by saying &#8220;nothing&#8221;, I mean &#8220;nothing&#8221;. Not even firewall was working! A total disaster, we had to rollback the whole stuff.</p>
<p>After spending 3 days with Support and Account Services from Check Point we found the error: through my procedure I had just licensed a container, without any blades. Attaching blade to a container and issuing &#8220;Get license&#8221; does nothing to the license. You have to attach the blades to the container and then license the whole package. Only this creates an valid license. </p>
<p>At the moment I haven&#8217;t made up my mind completely. Was it my fault? Am I to stupid to understand how to produce a correct license? Or is the User Center just working unexpected? </p>
<p>By the way: Total Security licenses are a total mess, too. We had several cases were (using NGX licenses) the AntiSpam, AntiVirus or URL Filtering module stopped working or updating because of license issues. The sad part is here, that all customers bought proper licenses and the User Center displayed all items correctly. </p>
<p>I really wish they will fix that&#8230;.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/12/my-trouble-with-software-blade-licenses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Check Point R70.20 is now available</title>
		<link>http://blog.lachmann.org/2009/12/check-point-r70-20-is-now-available/</link>
		<comments>http://blog.lachmann.org/2009/12/check-point-r70-20-is-now-available/#comments</comments>
		<pubDate>Sun, 20 Dec 2009 18:45:49 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Software Blades]]></category>
		<category><![CDATA[UTM-1]]></category>
		<category><![CDATA[VPN-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=137</guid>
		<description><![CDATA[The release R70.20 is now available. I checked the documentation and found that it contains many important fixes as well as new features. Especially it takes care of the new multicore licensing scheme, that has been introduced by Check Point. Check out the What&#8217;s new page, the Release Notes, the Known Limitations and the Resolved [...]]]></description>
			<content:encoded><![CDATA[<p>The release R70.20 is now available. I checked the documentation and found that it contains many important fixes as well as new features. Especially it takes care of the new multicore licensing scheme, that has been introduced by Check Point.</p>
<p>Check out the <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk43168">What&#8217;s new</a> page, the <a href="http://supportcontent.checkpoint.com/documentation_download?ID=10515">Release Notes</a>, the <a href="https://supportcenter.checkpoint.com/supportcenter/portal?solutionid=sk43166">Known Limitations</a> and the <a href="https://supportcenter.checkpoint.com/supportcenter/portal?solutionid=sk43167">Resolved Issues</a>.  </p>
<p>R70.20 is like the HFA60 for NGX R65 from the bugfixing side plus some added features.<br />
Highly recommended for installation.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/12/check-point-r70-20-is-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Short article about CPUGCON 2009</title>
		<link>http://blog.lachmann.org/2009/12/short-article-about-cpugcon-2009/</link>
		<comments>http://blog.lachmann.org/2009/12/short-article-about-cpugcon-2009/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 21:33:41 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[CPUG]]></category>
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=135</guid>
		<description><![CDATA[My employer released the new customer magazin recently. We have a short article about the CPUG conference 2009 and my presentations. Writen in german. Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>My employer released the new customer magazin recently.<br />
We have a short <a href="http://www.mcs.de/_downloads/mcs_magazine/MCS-2-2009.pdf#page=12">article</a> about the CPUG conference 2009 and my presentations. Writen in german.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/12/short-article-about-cpugcon-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Re-Certification R70</title>
		<link>http://blog.lachmann.org/2009/12/re-certification-r70/</link>
		<comments>http://blog.lachmann.org/2009/12/re-certification-r70/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 21:26:27 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=129</guid>
		<description><![CDATA[Today I passed the first part of my re-certification. Since the R70 CCSA exam is now available, I started with this one and will later on go for CCSE and CCSE+. I took the Accelerated CCSE exam once, wasn&#8217;t funny. I&#8217;m not going to do that again with R70! The R70 exam is under NDA [...]]]></description>
			<content:encoded><![CDATA[<p>Today I passed the first part of my re-certification. Since the R70 CCSA exam is now available, I started with this one and will later on go for CCSE and CCSE+. I took the Accelerated CCSE exam once, wasn&#8217;t funny. I&#8217;m not going to do that again with R70!</p>
<p>The R70 exam is under NDA restriction, so I can&#8217;t go into detail or tell you about specific question.</p>
<p>But some general things can be said:</p>
<p>- we now have a tough time frame &#8211; 130 questions in 120 minutes!<br />
- the questions are now more detailed and have good pictures which help a lot; but the scenarios are more complex<br />
- you actually have real live questions which occur in the daily work<br />
- all <a href="http://www.checkpoint.com/services/education/training/courses/ccsa-r70.html#tabID3">topics</a> from the course are covered and you have to know more details about the product and general security methods<br />
- it&#8217;s not like to old CCSA exam, it&#8217;s more like the CCSE actually</p>
<p>Sadly, some things haven&#8217;t changed:</p>
<p>- still questions that can&#8217;t be answered correctly<br />
- questions with two! answers that have the same text -> which one will be judged as correct?<br />
- answers like &#8220;1,2 and 4 are correct&#8221; -> here I found that no answer had the number X in it, which is also correct; kind of misleading<br />
- lot&#8217;s of questions that need to be re-phrased to make sense; especially for non-native speakers some of them are very hard to understand</p>
<p>I took the exam without practicing and passed. But this is truly not recommended! At least you should buy the student handbook from the training courses to know all the topics. Remember, the course has now 5 days instead of the 2 it had before.</p>
<p>Will be interesting to see, how the CCSE goes.<br />
I submitted some questions for this exam to Check Point. If I&#8217;m lucky, they will accept some of this questions. The promised reward was gaining the CCSE R70 certification.<br />
If this works, I&#8217;m of the hook <img src='http://blog.lachmann.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/12/re-certification-r70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Project Gaia &#8211; the new Check Point OS</title>
		<link>http://blog.lachmann.org/2009/12/project-gaia-the-new-check-point-os/</link>
		<comments>http://blog.lachmann.org/2009/12/project-gaia-the-new-check-point-os/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 21:11:54 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Secure Platform]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=123</guid>
		<description><![CDATA[Check Point will come up with a new OS platform that will succeed Secure Platform (SPLAT) and IPSO. Judging by the features that are shown on the project page, it will be based on Linux / SPLAT and many features of the Nokia Voyager will the transfered to the WebUI. I was able to get [...]]]></description>
			<content:encoded><![CDATA[<p>Check Point will come up with a new OS platform that will succeed Secure Platform (SPLAT) and IPSO.</p>
<p>Judging by the features that are shown on the <a href="http://www.checkpoint.com/products/gaia/index.html">project page</a>, it will be based on Linux / SPLAT and many features of the Nokia Voyager will the transfered to the WebUI.<br />
I was able to get some rumours from Check Point, that acknowledge this guess.</p>
<p>At the moment there&#8217;s no code available for customers or partners, but I&#8217;ll keep you posted as things develop in the next month.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/12/project-gaia-the-new-check-point-os/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CPUG On Tour &#8211; One day Check Point User Conferences</title>
		<link>http://blog.lachmann.org/2009/12/cpug-on-tour-one-day-check-point-user-conferences/</link>
		<comments>http://blog.lachmann.org/2009/12/cpug-on-tour-one-day-check-point-user-conferences/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 19:55:32 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[CPUG]]></category>
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=116</guid>
		<description><![CDATA[Barry Stiefel, founder of Check Point User Group CPUG, is putting together a tour of one day conferences in the US. These are kind of &#8220;small&#8221; CPUGCON events for all the folks from the states that couldn&#8217;t make their way to Switzerland in september. I thing this is very cool indeed and everyone should considering [...]]]></description>
			<content:encoded><![CDATA[<p>Barry Stiefel, founder of Check Point User Group CPUG, is putting together a tour of one day conferences in the US. These are kind of &#8220;small&#8221; CPUGCON events for all the folks from the states that couldn&#8217;t make their way to Switzerland in september.</p>
<p>I thing this is very cool indeed and everyone should considering visiting one of the events, either in Atlanta, New York City or Chicago.</p>
<p>Find more details on the conference website: <a href="http://www.cpugontour.com/">CPUG On Tour</a></p>
<p>Tobias Lachmann</p>
<p>PS: Barry, thanks for having my picture on the frontpage. I like the caption of the photo <img src='http://blog.lachmann.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/12/cpug-on-tour-one-day-check-point-user-conferences/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update: Hardware Monitoring on UTM-1 appliances</title>
		<link>http://blog.lachmann.org/2009/12/update-hardware-monitoring-on-utm-1-appliances/</link>
		<comments>http://blog.lachmann.org/2009/12/update-hardware-monitoring-on-utm-1-appliances/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 09:13:05 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=108</guid>
		<description><![CDATA[Check Point found the error and described it as follows: While installing NGX R65 HFA50, the net-snmp packages are updates to 5.3.1.0 version. When upgrading to R70.1, it tries to upgrade to net-snmp-5.0.9 version, which fails since newer packages are installed. Check Point provided me with a new R70.1 upgrade package which I will test [...]]]></description>
			<content:encoded><![CDATA[<p>Check Point found the error and described it as follows:<br />
While installing NGX R65 HFA50, the net-snmp packages are updates to 5.3.1.0 version. When upgrading to R70.1, it tries to upgrade to net-snmp-5.0.9 version, which fails since newer packages are installed.</p>
<p>Check Point provided me with a new R70.1 upgrade package which I will test in the next days. Sadly, the updated package hasn&#8217;t made it to the download page so far, there you can still get the old -buggy- version.</p>
<p>Hopefully they re-relase this upgrade package soon.</p>
<p>If they don&#8217;t and you experience problems while upgrading, please ask support for the fix and refer to SR 11-72334871.</p>
<p><strong>UPDATE: Check Point released a SecureKnowledge article for this issue: sk43340</strong> </p>
<p><strong>UPDATE 2: Today I spoke to the support guys again. I convinced them that this fix is interesting for everybody with a UTM-1 installation and HFA50 out there, which are quite a lot people, I guess. Now they&#8217;re thinking about changing the SK entry and adding a direct download link to the fixed packet.</strong></p>
<p><strong>UPDATE 3: Support will release a new article for this issue including the download links: sk43350. At the moment the sk is not publicly available</strong></p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/12/update-hardware-monitoring-on-utm-1-appliances/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NGX R65 HFA60 available</title>
		<link>http://blog.lachmann.org/2009/12/ngx-r65-hfa60-available/</link>
		<comments>http://blog.lachmann.org/2009/12/ngx-r65-hfa60-available/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 09:08:27 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=106</guid>
		<description><![CDATA[The latest Hotfix Accumulator, HFA60 for NGX R65 is available. At the moment only for Check Point partner, but public release will follow shortly. The release notes show a huge amount of fixed issues, including some content scanning problems I&#8217;ve seen before in the wild. So the installation of HFA60 is greatly recommended! Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>The latest Hotfix Accumulator, HFA60 for NGX R65 is available.<br />
At the moment only for Check Point partner, but public release will follow shortly.<br />
The <a href="http://downloads.checkpoint.com/dc/download.htm?ID=10306">release notes </a>show a huge amount of fixed issues, including some content scanning problems I&#8217;ve seen before in the wild.<br />
So the installation of HFA60 is greatly recommended!</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/12/ngx-r65-hfa60-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disconnect after one hour when using UTM-1 Edge build-in DSL Modem</title>
		<link>http://blog.lachmann.org/2009/11/disconnect-after-one-hour-when-using-utm-1-edge-build-in-dsl-modem/</link>
		<comments>http://blog.lachmann.org/2009/11/disconnect-after-one-hour-when-using-utm-1-edge-build-in-dsl-modem/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 17:29:01 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[UTM-1 Edge]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=104</guid>
		<description><![CDATA[This is an old one, but still valid: When you use the build-in ADSL modem in an UTM-1 Edge, it will disconnect approx. after one hour. To avoid this, connect to the command line of the appliance and issue set port adsl auto-sra mode disabled. Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>This is an old one, but still valid:<br />
When you use the build-in ADSL modem in an UTM-1 Edge, it will disconnect approx. after one hour.<br />
To avoid this, connect to the command line of the appliance and issue <code>set port adsl auto-sra mode disabled</code>.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/11/disconnect-after-one-hour-when-using-utm-1-edge-build-in-dsl-modem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Instabil SPLAT system after upgrading to R70</title>
		<link>http://blog.lachmann.org/2009/11/instabil-splat-system-after-upgrading-to-r70/</link>
		<comments>http://blog.lachmann.org/2009/11/instabil-splat-system-after-upgrading-to-r70/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 07:06:48 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=101</guid>
		<description><![CDATA[Check Point released an important new article in SecureKnowledge, sk43247. This article states that in SPLAT there&#8217;s a recursive soft link (/opt/CPsuite-R65/fw1/PA/conf/PA/PA) after installing two of the following HFAs to the machine: HFA30, HFA40 or HFA50. When upgrading to R70, this softlink causes the error leading the software to become instable. The solution is to [...]]]></description>
			<content:encoded><![CDATA[<p>Check Point released an important new article in SecureKnowledge, <a href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&#038;solutionid=sk43247">sk43247</a>.</p>
<p>This article states that in SPLAT there&#8217;s a recursive soft link (<code>/opt/CPsuite-R65/fw1/PA/conf/PA/PA</code>) after installing two of the following HFAs to the machine: HFA30, HFA40 or HFA50.</p>
<p>When upgrading to R70, this softlink causes the error leading the software to become instable.<br />
The solution is to delete the link before upgrading to R70 (<code>rm -f /opt/CPsuite-R65/fw1/PA/conf/PA/PA</code>).</p>
<p>Please have that in mind when you plan to upgrade to R70.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/11/instabil-splat-system-after-upgrading-to-r70/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hardware Monitoring on UTM-1 appliances</title>
		<link>http://blog.lachmann.org/2009/11/hardware-monitoring-on-utm-1-appliances/</link>
		<comments>http://blog.lachmann.org/2009/11/hardware-monitoring-on-utm-1-appliances/#comments</comments>
		<pubDate>Sun, 22 Nov 2009 20:09:20 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=98</guid>
		<description><![CDATA[The hardware monitoring feature on UTM-1 appliances, available since R70.1, is missing when upgrading the appliance from NGX R65 with Messaging Security HFA50. Check Point just confirmed this and stated, that some rpm packages are not updated which produces the error. When you upgrade directly from NGX R65 with Messaging Security, the error is not [...]]]></description>
			<content:encoded><![CDATA[<p>The hardware monitoring feature on UTM-1 appliances, available since R70.1, is missing when upgrading the appliance from NGX R65 with Messaging Security HFA50.</p>
<p>Check Point just confirmed this and stated, that some rpm packages are not updated which produces the error.<br />
When you upgrade directly from NGX R65 with Messaging Security, the error is not occuring.</p>
<p>We&#8217;ll see what the solution from the developers for this problem will be. Since this is a general problem, I hope for new upgrade packages instead of some fixes to be applied afterwards. Seems cleaner to me&#8230;.</p>
<p>I keep you informed</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/11/hardware-monitoring-on-utm-1-appliances/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My favorite troubleshooting command</title>
		<link>http://blog.lachmann.org/2009/11/my-favorite-troubleshooting-command/</link>
		<comments>http://blog.lachmann.org/2009/11/my-favorite-troubleshooting-command/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 19:43:51 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=93</guid>
		<description><![CDATA[Do you know how to troubleshoot connection issues the easy way? Instead of looking into SmartView Tracker for the reason of a connection drop, just enter the shell. Then issue fw ctl zdebug drop and you&#8217;ll see the dropped packet in realtime with the reason for the drop. This is an undocumented command, which is [...]]]></description>
			<content:encoded><![CDATA[<p>Do you know how to troubleshoot connection issues the easy way? Instead of looking into SmartView Tracker for the reason of a connection drop, just enter the shell. Then issue<strong><code> fw ctl zdebug drop </code></strong>and you&#8217;ll see the dropped packet in realtime with the reason for the drop. This is an undocumented command, which is actually a shortcut for a couple of debugging commands. A developer from Check Point was to tired of typing the needed debug lines again and again and so he introduced the zdebug command. His first name began with the letter Z, so this is why the command is zdebug.</p>
<p>The output is very nice, shows the reason for the drop and can easily be filtered with the grep command for IP addresses:</p>
<p><code>fw_log_drop: Packet proto=17 10.255.253.21:20031 -> 10.255.253.255:20031 dropped by fw_antispoof_log Reason: Address spoofing</p>
<p>fw_log_drop: Packet proto=17 192.243.100.205:58999 -> 224.0.0.1:9996 dropped by fw_handle_first_packet Reason: Rulebase drop - rule 243</p>
<p>fw_log_drop: Packet proto=1 10.68.111.2:1281 -> 10.68.111.5:1669 dropped by fw_icmp_stateless_checks Reason: ICMP redirect packets are not allowed</p>
<p>fw_log_drop: Packet proto=6 192.243.119.238:80 -> 91.96.46.174:49543 dropped by fw_first_packet_state_checks Reason: First packet isn't SYN</code></p>
<p>Since this is realtime debug output, you need to have live traffic through the firewall to see if a packet is dropped. When you try to investigate the reason for a drop of an older connection, you have to go the SmartView Tracker.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/11/my-favorite-troubleshooting-command/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Edge disconnect while using embedded ADSL modem</title>
		<link>http://blog.lachmann.org/2009/11/edge-disconnect-while-using-embedded-adsl-modem/</link>
		<comments>http://blog.lachmann.org/2009/11/edge-disconnect-while-using-embedded-adsl-modem/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 21:45:23 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[UTM-1 Edge]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=91</guid>
		<description><![CDATA[The UTM-1 Edge appliance may show the error that the Internet connections is continuously disconnected after about an hour when the embedded DSL modem is used. There&#8217;s an easy way to solve this problem. Just issue the command set port adsl auto-sra mode disable on the CLI or over the WebUI following Setup->Tools->Command. BTW: after [...]]]></description>
			<content:encoded><![CDATA[<p>The UTM-1 Edge appliance may show the error that the Internet connections is continuously disconnected after about an hour when the embedded DSL modem is used.</p>
<p>There&#8217;s an easy way to solve this problem. Just issue the command <code>set port adsl auto-sra mode disable </code>on the CLI or over the WebUI following <code>Setup->Tools->Command</code>.</p>
<p>BTW: after updating the DSL firmware, it is recommended to totally disconnect the appliance from power instead of just rebooting.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/11/edge-disconnect-while-using-embedded-adsl-modem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Idle Timeouts in SPLAT</title>
		<link>http://blog.lachmann.org/2009/11/idle-timeouts-in-splat/</link>
		<comments>http://blog.lachmann.org/2009/11/idle-timeouts-in-splat/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 21:37:05 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Secure Platform]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=87</guid>
		<description><![CDATA[Ever wondered, how to get a longer timeout when working on SPLAT CLI? If you use the CPshell as login shell, the command is IDLE 999 When you are in expert mode or changed the login shell to bash, the command is UNSET TMOUT The first command sets the timeout to 999 seconds, the second [...]]]></description>
			<content:encoded><![CDATA[<p>Ever wondered, how to get a longer timeout when working on SPLAT CLI?</p>
<p>If you use the CPshell as login shell, the command is </p>
<p><code>IDLE 999</code></p>
<p>When you are in expert mode or changed the login shell to bash, the command is</p>
<p><code>UNSET TMOUT</code></p>
<p>The first command sets the timeout to 999 seconds, the second one disables the timeout.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/11/idle-timeouts-in-splat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Capazity Optimization</title>
		<link>http://blog.lachmann.org/2009/10/capazity-optimization/</link>
		<comments>http://blog.lachmann.org/2009/10/capazity-optimization/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 19:26:28 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=76</guid>
		<description><![CDATA[Because one of my customers run recently in this problem, maybe it&#8217;s a good idea to mention this again. The firewall has a limit for it&#8217;s maximum concurrent connections. This is necessary to limit the amount of memory allocated. But if you reach the limit, the firewall stops to accept new connections. You may experience [...]]]></description>
			<content:encoded><![CDATA[<p>Because one of my customers run recently in this problem, maybe it&#8217;s a good idea to mention this again.</p>
<p>The firewall has a limit for it&#8217;s maximum concurrent connections. This is necessary to limit the amount of memory allocated.</p>
<p>But if you reach the limit, the firewall stops to accept new connections. You may experience this as a partial loss of connectivity.</p>
<p>To check the number of actual connections and the peak value, run<strong> fw tab -t connections -s</strong> on the command line</p>
<p><strong><code>[Expert@fw1]# fw tab -t connections -s<br />
HOST                  NAME                  ID #VALS #PEAK #SLINKS<br />
localhost             connections           8158 108437 166360  378754</code></strong></p>
<p>The memory allocation and use of connections can also be shown with <strong>fw ctl pstat</strong>.</p>
<p><strong><code>[Expert@fw1]# fw ctl pstat</p>
<p>Machine Capacity Summary:<br />
  Memory used: 12% (203MB out of 1604MB) - below low watermark<br />
  Concurrent Connections: 15% (79242 out of 499900) - below low watermark<br />
  Aggressive Aging is not active</code></strong></p>
<p>If your concurrent connections are near the limit, you can increase the number using the SmartDashboard. Just edit the properties of the gateway object under capacity optimization and set a higher value. Please note that the memory allocation will also increase when you change something here, so make sure you&#8217;ve got enough free memory.</p>
<p><img class="alignnone size-full wp-image-79" title="capacity_optimization" src="http://blog.lachmann.org/wp-content/uploads/2009/10/capacity_optimization.jpg" alt="capacity_optimization" width="500" height="453" /></p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/10/capazity-optimization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UMTS / HSDPA connection with UTM-1 Edge Appliance an T-D1 SIM card</title>
		<link>http://blog.lachmann.org/2009/10/umts-hsdpa-connection-with-utm-1-edge-appliance/</link>
		<comments>http://blog.lachmann.org/2009/10/umts-hsdpa-connection-with-utm-1-edge-appliance/#comments</comments>
		<pubDate>Mon, 26 Oct 2009 12:28:20 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[UTM-1 Edge]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=39</guid>
		<description><![CDATA[A nice feature that comes with the UTM-1 Edge Appliances is the ability to establish an internet connection trough an USB modem. I bought a used Huawei E220 from eBay and connected it the the box. Then you go to the WebUI and choose Network -&#62; Ports. There you can see that a USB device [...]]]></description>
			<content:encoded><![CDATA[<p>A nice feature that comes with the UTM-1 Edge Appliances is the ability to establish an internet connection trough an USB modem.</p>
<p>I bought a used Huawei E220 from eBay and connected it the the box.</p>
<p><img class="alignnone size-full wp-image-38" title="usb_modem_overview" src="http://blog.lachmann.org/wp-content/uploads/2009/10/usb_modem_overview.jpg" alt="usb_modem_overview" width="480" height="360" /></p>
<p><img class="alignnone size-full wp-image-37" title="usb_modem" src="http://blog.lachmann.org/wp-content/uploads/2009/10/usb_modem.jpg" alt="usb_modem" width="480" height="360" /></p>
<p>Then you go to the WebUI and choose Network -&gt; Ports. There you can see that a USB device is connected to the UTM-1 Edge Appliance.</p>
<p><img class="alignnone size-full wp-image-42" title="1network_ports" src="http://blog.lachmann.org/wp-content/uploads/2009/10/1network_ports.jpg" alt="1network_ports" width="480" height="358" /></p>
<p>Click on Edit.</p>
<p>Now you can verify that the modem is recognized.</p>
<p><img class="alignnone size-full wp-image-63" title="2network_ports_usb_devices" src="http://blog.lachmann.org/wp-content/uploads/2009/10/2network_ports_usb_devices.jpg" alt="2network_ports_usb_devices" width="499" height="124" /></p>
<p>Click on Edit again to get to the properties of the USB modem.</p>
<p>Choose the right modem type from the Drop-Down menu. A list of all supported modem can be found <a title="List of supported USB modems" href="http://server.iad.liveperson.net/hc/s-9995810/cmd/kbresource/kb-729066512208761205/!DOWNLOAD?entryid=355218&amp;attachid=32124" target="_blank">here</a>.</p>
<p>The APN is specific for the telecom provider you&#8217;re using, in this example it&#8217;s Deutsche Telekom T-D1 and the value is &#8220;internet.t-d1.de&#8221;</p>
<p>The PIN is specific for the SIM card that you&#8217;re using.</p>
<p><img class="alignnone size-full wp-image-64" title="3usb_modem_setup" src="http://blog.lachmann.org/wp-content/uploads/2009/10/3usb_modem_setup.jpg" alt="3usb_modem_setup" width="500" height="314" /></p>
<p>After applying the settings to the USB modem, you configure the device as primary Internet Connection.</p>
<p>The username for T-D1 is &#8220;t-d1&#8243;.</p>
<p>The password is also &#8220;t-d1&#8243;.</p>
<p>The number to be dialed is *99#</p>
<p><img class="alignnone size-full wp-image-65" title="4internet_setup" src="http://blog.lachmann.org/wp-content/uploads/2009/10/4internet_setup.jpg" alt="4internet_setup" width="499" height="379" /></p>
<p>After a few seconds the box has logged into the internet through the USB modem and you can use the connection like any other internet access.</p>
<p><img class="alignnone size-full wp-image-66" title="5network_internet_connected" src="http://blog.lachmann.org/wp-content/uploads/2009/10/5network_internet_connected.jpg" alt="5network_internet_connected" width="500" height="126" /></p>
<p>I find this very useful, for example for temporay access on an exhibition or for home users where no DSL is available.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/10/umts-hsdpa-connection-with-utm-1-edge-appliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VSX R65 NGX HFA10 to be released</title>
		<link>http://blog.lachmann.org/2009/10/vsx-r65-ngx-hfa10-to-be-released/</link>
		<comments>http://blog.lachmann.org/2009/10/vsx-r65-ngx-hfa10-to-be-released/#comments</comments>
		<pubDate>Fri, 23 Oct 2009 20:38:58 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=35</guid>
		<description><![CDATA[Just received notice that the VSX NGX R65 HFA10 will be released soon. See the release notes for detailed infos. Since it includes many fixed issues, it should be considered worth installing. Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>Just received notice that the VSX NGX R65 HFA10 will be released soon. See the<a title="VSX NGX R65 HFA10 Release Notes" href="http://downloads.checkpoint.com/dc/download.htm?ID=10363" target="_blank"> release notes </a>for detailed infos.</p>
<p>Since it includes many fixed issues, it should be considered worth installing.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/10/vsx-r65-ngx-hfa10-to-be-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Some stuff posted in MCS customer mag</title>
		<link>http://blog.lachmann.org/2009/10/some-stuff-posted-in-mcs-customer-mag/</link>
		<comments>http://blog.lachmann.org/2009/10/some-stuff-posted-in-mcs-customer-mag/#comments</comments>
		<pubDate>Fri, 23 Oct 2009 20:33:49 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=31</guid>
		<description><![CDATA[My employer MCS Moorbek Computer Systeme GmbH publishes a customer magazine on a regular basis. I had same articles about Check Point topics in this magazine, written in german: SecurePlattform auf der Kommandzeile Check Point Firewall Troubleshooting Really basic stuff, actually, but worth noticing. I&#8217;ve you&#8217;re into Solaris or MySQL, check out the &#8220;Admin Tipps [...]]]></description>
			<content:encoded><![CDATA[<p>My employer <a title="MCS Moorbek Computer Systeme Homepage" href="http://www.mcs.de">MCS Moorbek Computer Systeme GmbH </a>publishes a <a title="MCS customer magazine" href="http://www.mcs.de/de/magazin/archiv/index.php" target="_blank">customer magazine </a>on a regular basis.</p>
<p>I had same articles about Check Point topics in this magazine, written in german:</p>
<ul>
<li><a title="SecurePlatform auf der Kommandozeile" href="http://www.mcs.de/_downloads/mcs_magazine/MCS-3-2008.pdf#page=14" target="_blank">SecurePlattform auf der Kommandzeile</a></li>
<li><a title="Check Point Firewall Troubleshooting" href="http://www.mcs.de/_downloads/mcs_magazine/MCS-1-2008.pdf#page=14" target="_blank">Check Point Firewall Troubleshooting</a></li>
</ul>
<p>Really basic stuff, actually, but worth noticing.</p>
<p>I&#8217;ve you&#8217;re into Solaris or MySQL, check out the &#8220;Admin Tipps &amp; Tricks&#8221; in the other issues of the magazine. Usually they&#8217;re located on the last pages. Use the link above to access current and older magazines.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/10/some-stuff-posted-in-mcs-customer-mag/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ETA for NGX R65 HFA60</title>
		<link>http://blog.lachmann.org/2009/10/eta-for-ngx-r65-hfa60/</link>
		<comments>http://blog.lachmann.org/2009/10/eta-for-ngx-r65-hfa60/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 13:14:28 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[VPN-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=26</guid>
		<description><![CDATA[Today I was informed that HFA60 for NGX R65 will be available at the end of this quarter. I expected this HFA earlier, but for some reasons the deployment was postponed again Tobias Lachmann]]></description>
			<content:encoded><![CDATA[<p>Today I was informed that HFA60 for NGX R65 will be available at the end of this quarter.</p>
<p>I expected this HFA earlier, but for some reasons the deployment was postponed again <img src='http://blog.lachmann.org/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/10/eta-for-ngx-r65-hfa60/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Error in upgrade process from NGX R65 to R70.1 on UTM-1</title>
		<link>http://blog.lachmann.org/2009/10/error-in-upgrade-process-from-ngx-r65-to-r70-1-on-utm-1/</link>
		<comments>http://blog.lachmann.org/2009/10/error-in-upgrade-process-from-ngx-r65-to-r70-1-on-utm-1/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 13:12:33 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[UTM-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=23</guid>
		<description><![CDATA[Today I got the confirmation that Check Point was able to reproduce an error reported by me. With R70.1 the new feature of hardware monitoring for appliances was introduced. The was missing for so long and I&#8217;m glad is had been build into the WebUI now. But unfortunately this is only working when you do [...]]]></description>
			<content:encoded><![CDATA[<p>Today I got the confirmation that Check Point was able to reproduce an error reported by me.</p>
<p>With R70.1 the new feature of hardware monitoring for appliances was introduced. The was missing for so long and I&#8217;m glad is had been build into the WebUI now. But unfortunately this is only working when you do a completely new installation.</p>
<p>When you upgrade a NXG R65 installation on a UTM-1 to R70 and then onwards to R70.1 some files get corrupted.</p>
<p>Support is currently working on this, I&#8217;ll keep you posted.</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/10/error-in-upgrade-process-from-ngx-r65-to-r70-1-on-utm-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Presentations from Check Point User Group Conference (CPUGCON) 2009</title>
		<link>http://blog.lachmann.org/2009/10/presentations-from-check-point-user-group-conference-cpugcon-2009/</link>
		<comments>http://blog.lachmann.org/2009/10/presentations-from-check-point-user-group-conference-cpugcon-2009/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 22:06:04 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[CPUG]]></category>
		<category><![CDATA[Secure Platform]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[UTM-1]]></category>
		<category><![CDATA[UTM-1 Edge]]></category>
		<category><![CDATA[VPN-1]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=9</guid>
		<description><![CDATA[I think I get started with this blog by posting links to the presentations I held on the Check Point User Group Conference in Chur, Switzerland. The first presentation is purely for beginners:  Troubleshooting in the Check Point environment, Part I The second one, which was more liked by the crowd at CPUGCON, is really advanced troubleshooting: [...]]]></description>
			<content:encoded><![CDATA[<p>I think I get started with this blog by posting links to the presentations I held on the Check Point User Group Conference in Chur, Switzerland.</p>
<p>The first presentation is purely for beginners:  <a title="Troubleshooting in the Check Point environment, Part I" href="http://www.cpugcon.com/2009-CPUG-CON-EUROPE/presentations/2009-CPUG-CON-Tobias-Lachmann-Troubleshooting-In-The-Check-Point-Environment-Part-I-2009-09-09.ppt" target="_blank">Troubleshooting in the Check Point environment, Part I</a></p>
<p>The second one, which was more liked by the crowd at CPUGCON, is really advanced troubleshooting: <a title="Troubleshooting in the Check Point Environment - Part II" href="http://www.cpugcon.com/2009-CPUG-CON-EUROPE/presentations/2009-CPUG-CON-Tobias-Lachmann-Troubleshooting-In-The-Check-Point-Environment-Part-II-2009-09-09.pdf" target="_blank">Troubleshooting in the Check Point environment, Part II</a></p>
<p>I benefit from my daily work with a Check Point Collaborative Support Provider (CCSP) for these two presentations, as they reflect the things I&#8217;m constantly facing.</p>
<p>From the project side, I did lot&#8217;s of migrations from distributed Check Point installations to Check Point UTM-1 Full-Cluster. This means that the firewall / vpn part is working in active/standby cluster and we have also Management High Availability with the two SmartCenters. This is described in the presentation: <a title="Migration from a distributed Environment to a UTM-1 cluster" href="http://www.cpugcon.com/2009-CPUG-CON-EUROPE/presentations/2009-CPUG-CON-Tobias-Lachmann-Migration-From-A-Distributed-Environment-To-A-UTM-1-Cluster-2009-09-09.ppt" target="_blank">Migration from a Distributed Environment to a UTM-1 Cluster</a></p>
<p>Best regards</p>
<p>Tobias Lachmann</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/10/presentations-from-check-point-user-group-conference-cpugcon-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Welcome to my Check Point blog!</title>
		<link>http://blog.lachmann.org/2009/10/welcome-to-my-check-point-blog/</link>
		<comments>http://blog.lachmann.org/2009/10/welcome-to-my-check-point-blog/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 21:54:32 +0000</pubDate>
		<dc:creator>Tobias Lachmann</dc:creator>
				<category><![CDATA[CPUG]]></category>
		<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://blog.lachmann.org/?p=6</guid>
		<description><![CDATA[Hello everyone! After spending more than 8 years working with Check Point products, I thought it may be a good idea to let the world know my findings from time to time. Becoming an expert means making errors and trying out things&#8230; but who says that two persons need to make the same (bad) experience? [...]]]></description>
			<content:encoded><![CDATA[<p>Hello everyone!</p>
<p>After spending more than 8 years working with Check Point products, I thought it may be a good idea to let the world know my findings from time to time.</p>
<p>Becoming an expert means making errors and trying out things&#8230; but who says that two persons need to make the same (bad) experience? Maybe someone can just read this blog and find the solution he&#8217;s looking for&#8230;.</p>
<p>For more information about myself, check out the <a title="Bio Tobias Lachmann" href="http://www.cpugcon.com/bios/bio-tobias-lachmann.htm" target="_blank">speakers</a> page on CPUGCON website.</p>
<p>Tobias Lachmann</p>
<p><img src="http://blog.lachmann.org/wp-content/uploads/2009/12/tobias-430x300.jpg" alt="Me at Check Point User Group Conference 2009" title="Me at Check Point User Group Conference 2009" width="430" height="300" class="alignnone size-full wp-image-121" /><br />
Me at Check Point User Group Conference 2009</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.lachmann.org/2009/10/welcome-to-my-check-point-blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
