Check Point community forum
February 07, 2012, 10:04:55 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News:
 
  Home   Forum   Help Search Login Register   **
Welcome, Guest. Please login or register.
Did you miss your activation email?
February 07, 2012, 10:04:55 PM

Login with username, password and session length
Pages: [1]
  Print  
Author Topic: R65 - what have I done...!?!?  (Read 955 times)
trikki69
Newbie
*
Posts: 1


« on: November 13, 2009, 01:39:22 PM »

Hi, first post and already asking a question!!  Wink
I've just upgraded my border firewall from R55 to R65 SPLAT and found the transition problematic to say the least.
It looks as though R65 is interfering with all kinds of traffic going through the gateway, I had to disable Smart Defense yesterday to try and get some control over what it was doing.
I've had problems with nntp, http, https  and peer-to-peer to list a few.
I never had ANY problems with R55, rules that were defined in the rule base worked and worked very well, the firewall didn't interfere with anything unless I told it to.
I have a test host on my network that runs emule and nntp (Forte Agent) I use these apps to obtain difficult to find documents and software for testing purposes. I cannot get emule to connect properly no matter what the rule base says - I have also completely disabled Smart Defense on the gateway to no avail.
All ports and addresses are correctly defined in the policy, this worked fine with R55 (the R55 and R65 policies are identical)

Is there any way to get control over what it is actually doing and to get nntp and emule working correctly? If not I may have to go down the Cisco ASA or Sonic Wall route.  Cry

Thankfully I'm running on an eval, I'm pleased I tried before I bought!!  Undecided
Logged
juve
Administrator
Jr. Member
*****
Posts: 92


« Reply #1 on: November 13, 2009, 04:47:38 PM »

What are the error messages in the logs? Does it drop on a real rule, a fake rule number or anything else?

Also, why not check out R70? SmartDefense wasn't the best of the best and its replacement (IPS) has been rewritten completely, plus the logs are a lot clearer on what happens. Only thing is you can't upgrade directly from R55, you have to pass over R65 first.
Logged
Pages: [1]
  Print  
 
Jump to:  

Recent
[December 20, 2011, 07:35:00 AM]

[August 11, 2011, 07:07:19 AM]
Members
Total Members: 226
Latest: mkouzuma
Stats
Total Posts: 183
Total Topics: 76
Online Today: 10
Online Ever: 21
(February 06, 2009, 02:31:43 PM)
Users Online
Users: 0
Guests: 10
Total: 10
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
TinyPortal v0.9.8 © Bloc
Valid XHTML 1.0! Valid CSS!