Press "Enter" to skip to content

Checkpoint Domain Object


Was thinking to use Domain Object as a source in our firewall rule. After consulted with checkpoint support, it seems impossible if your domain object represented multiple ip addresses. SK42128 Symptoms     Rules containing a Domain object will only resolve to one of the associated IP addresses, causing request for a site not to return a web page.  Cause A Domain object resolves a domain name by the first IP Address that appears when…

Add static route in Smoothwall


Add static route in Smoothwall Firstly, edit the file /etc/rc.d/rc.netaddress.up Above the 'echo "setting up firewall ……."', add: /sbin route add -net destination netmask subnetmask gw gateway devdeviceinterface ————————————– Edit /etc/rc.d/rc.firewall.up After the section on "# Allow packets that we know about through …" Add: # Allow packets from green to green /sbin/iptables -A FORWARD -i $GREEN_DEV -o $GREEN_DEV -j ACCEPT

no response when ping MS Cluster’s ip address – Solution


There is a Citrix cluster deployed in our environment. But cluster ip not working from an outside network, although working fine in same network. Checked MS doc – troubleshooting NLB, foud following cause: There is no response when you use ping to access the cluster's IP address from an outside network. Verify that you can use ping to access the dedicated IP addresses for the cluster hosts from a computer outside the router. If this test fails, and…

SecureXL Vs CoreXL Vs ClusterXL (Some Checkpoint Terms)


From Checkpoint Sites: “SecureXL: Security acceleration Patented SecureXL is a technology interface that accelerates multiple, intensive security operations, including operations that are carried out by Check Point’s Stateful Inspection firewall. Using SecureXL, the firewall offloads operations to a performance-optimized software or hardware device, dramatically increasing throughput. More details from this post. CoreXL: Multicore acceleration As the first security technology to fully leverage general-purpose multi-core processors, CoreXL introduces advanced core-level load balancing that increases throughput for…

Steps to Set up Juniper Secure Access (SA) / SSL Virtual Appliance


This products looks similar as UAC products. 1. Download file SPE Virtual Appliance                                                                                Service Provider Edition (SPE) Demonstration & Training Edition (DTE) 2. Convert to VMWare Workstation Version OVFtool Download page: C:Program FilesVMwareVMware OVF Tool>ovftool.exe…