Questions tagged [checkpoint]
network security components including Firewall
67 questions
0 votes
0 answers
39 views
Podman Based Containers Integration Scope
Is containers created using podman have integration scope with checkpoint firewall? Is containers created using podman have integration scope with cisco sdn?
1 vote
2 answers
483 views
Reduce DNS queries sent to Cisco Umbrella
We are exceeding the Cisco Umbrella DNS query limit of 5,000 queries per user per day by 3x due to all DNS traffic, internal and external, is sent to Umbrella. Umbrella then forwards internal DNS ...
1 vote
1 answer
162 views
Change Cisco Management VLAN
I currently have the following configuration. A Checkpoint firewall (which is the router) and 12 Cisco 9200 switches. SW1 is connected to the firewall. I need to change the MGMT VLAN from VLAN20 to ...
1 vote
2 answers
2k views
Syslog-ng multiple filters
I am fairly new to syslog-ng and I have the following issue. I have a Checkpoint firewall that sends the logs to a Splunk server. Due to the huge amount of data sent by the firewall, I tried to filter ...
0 votes
0 answers
68 views
firewall resources saturation because of huge downloads by users
My Check Point company firewall which serves about 150 client/servers, is experiencing loading problems and saturates all cpu resources, which brings to a web interface fall down and unability to ...
1 vote
0 answers
433 views
Recover files from Hyper-V VM checkpoints
this is my first time posting here, so apologize in advance if I am doing something wrong. Here is our environment Hyper V host server windows server 2019 standard HP ProLiant DL380p Gen8 2x Xeon E5-...
2 votes
0 answers
2k views
Using strongswan to connect a checkpoint vpn gateway using Ikev1 and xauth-hybrid
I try to connect to a r81.10 gateway using a linux distribution with strongswan. Gateway accepts user:password only. Tested with Windows Version of Checkpoint Endpoint Software. Have to use ikev1. The ...
1 vote
0 answers
727 views
Configuring Checkpoint VPN MacOS without Checkpoint client
Is there a way to connect to a Checkpoint VPN on a Mac without installing their client software? I'm on OSX Ventura 13.0.1 with an M2 chipset. Their latest client E86.50 doesn't support Apple Silicon, ...
0 votes
1 answer
221 views
When you Checkpoint a VM, at what point is the state saved?
In Hyper-V, if you create a Standard Checkpoint on a VM, is the disk and memory state frozen when you start creating the checkpoint, or when the checkpoint has finished saving, or at some other point ...
0 votes
0 answers
3k views
Hyper-V did not merge .avhdx after delete checkpoint
I have a Windows 10 laptop that has a Hyper-V host login and that has a VM that I use to native boot to a vhdx file. I hardly ever log into the Hyper-V host but did today to backup the vhdx file and ...
1 vote
0 answers
224 views
SIP traffic and firewall rules
We have Cisco Expressway-Edge devices handling videoconferencing traffic with the outside world. This all goes through a Checkpoint firewall. The intention is that the inside endpoints can initiate ...
0 votes
0 answers
166 views
Using a VPN inside a VM over SOCKS
At work my PC is ubuntu based, and we are migrating to a VPN that only comes with a client for windows based machines. It seems almost impossible to hack the client to work on Linux (or it will ...
2 votes
1 answer
3k views
Checkpoint Hide NAT feature and dynamic source port selection
Checkpoint firewall have two NAT modes: Static NAT (1-to-1 internal IP to external IP) and Hide NAT, which is called "overload" in the Cisco and so on. It is not being said in clear, but it seems ...
0 votes
1 answer
1k views
Check Point: ISP Redundancy Link Interface Cannot Be Created
While setting up ISP Redundancy on a Check Point cluster I ran into an issue preventing me from proceeding with my configuration. I was eventually able to resolve this and felt that I would share ...
2 votes
3 answers
21k views
Azure VPN Site-to-site connected but host not reachable
Using Azure gateway VPN I created a site to site connection with another vpn device (checkpoint) over which I have no control (customer endpoint). I created the connection, using their public ip, ...
2 votes
1 answer
438 views
Win Server 2016 Hyper-V checkpoints - using them in production
Sysadmins have known for a long time that snapshots, or as they are now called, "Checkpoints" are excellent for dev / testing, but not suitable for use in production as they require a chain of VHDX ...
1 vote
0 answers
235 views
Is there a way to tell what process changed a route in Windows 7?
I have a situation where our Windows 7 clients (Windows 10 works ok) are having intermittent connectivity issues when connecting over our Checkpoint Endpoint Connect VPN. The issue manifests itself as ...
0 votes
0 answers
57 views
Simple 7 computers network - 1 computer is suffering from internet disconnections (but not LAN)
We have a simple office network with the following structure: DSL Modem -> Checkpoint 620 -> TP-LINK TL-SG1016 -> Ethernet ports around the office -> Computers & Printers. The CP620 also have Wi-...
0 votes
1 answer
273 views
How to add internal user to one of the rules in Check Point's Mobile Access blade
I want to add an internal user to one of the rules in Check Point's Mobile Access blade. How can I do that?
1 vote
1 answer
1k views
Hyper-V 2012 R2 windows backup lingering checkpoints
I have a Windows 2012 R2 Hyper-V server that has two virtual machines running. I have Windows backup configured to do a full bare metal backup of the Hyper-V server to USB disk. Every few weeks the ...
0 votes
1 answer
228 views
Checkpoint - Automatic NAT
I have a checkpoint firewall (R75, Splat) that has a server published with Automatic NAT enabled, however I'm unable to connect to external websites. Traffic leaves the firewall ok but the Internet ...
4 votes
1 answer
2k views
Windows - Log services access to certificate store
I have a software which run as a service (Checkpoint Identity Awareness) which connects to a server and verifies its identity (actually a checkpoint firewall) by checking its certificate, like any ...
1 vote
0 answers
981 views
Fresh install of CheckPoint Gaia r77 on VMware Workstation, no internet?
Hi I'm a complete noob to CP, Gaia and Firewalls. I installed Gaia on VMware Workstation 12. I added 2 NIC on it: First NIC is 10.34.x.x Custom network and I seem to be able to manage Gaia through a ...
0 votes
1 answer
165 views
Nexus 1000v Port Channel to Virtual Machine
Is it possible to setup a Port-Channel between a Nexus 1000v Switch and a ESX Virtual Machine? Context: I am running a Checkpoint Firewall cluster as Virtual Machines on an ESX server. I want to ...
2 votes
1 answer
46k views
How to find Check Point firewall version from command line
On Check Point firewall's command line, how can I find its version? Major version, minor version and optionally build number.
0 votes
1 answer
1k views
Setup a very Basic DMZ for WordPress
We are thinking of switching our corporate website from externally hosted and designed, to an internal WordPress server. This is so we can maintain direct control, as well as run our own traffic ...
0 votes
0 answers
2k views
Will the Linux Open VPNC Client connect to checkpoint or nortel VPN gateways?
Site: http://www.oucs.ox.ac.uk/network/vpn/linux-solaris/index.xml?ID=VPNC What is open VPNC: VPNC is an open-source VPN client for Linux and other Unix systems which is compatible with the OUCS VPN ...
0 votes
1 answer
3k views
VPN Between Checkpoint R75.20 and AWS VPC
I have been trying for a long time now to configure a site-to-site VPN connection between Amazon and a Checkpoint R75.20 (previously i tried with Azure) unsuccessfully. I have tried everything and ...
1 vote
1 answer
132 views
Opening in Checkpoint firewall
I have a server with address 80.39.X.X that I want to give access to another server range in my network: 10.1.16.0/24. They are both in my network, behind a Checkpoint firewall. When I try to reach ...
0 votes
1 answer
2k views
Memory usage on my firewall [duplicate]
I have a memory usage problem with my Checkpoint Firewall (it's a physical firewall). On my monitoring software OPManager I can see that 94% of my memory is used. In SSH, when i enter this command : ...
1 vote
0 answers
806 views
CheckPoint Firewall R71: Is it possible to reserve an IP for a specific MAC address on a VPN session?
My Checkpoint firewall is configured to allow users to open the GUI (Smart Dashboard) only if their IP is on the allowed list. Whenever I work from home (I use the CheckPoint SNX client on an Ubuntu ...
0 votes
1 answer
1k views
CheckPoint/Amazon VPC VPN tunnel working inconsistently
First time poster, so please be gentle and correct me if there's Server Fault etiquette I'm missing. We have two CheckPoint edge devices at sites A & B, independently managed, connecting to two ...
1 vote
1 answer
447 views
Checkpoint - Wifi Bridge mode kills round trip requests?
I'm fairly sure this is either a NAT or routing question, but it's one that continually has me stumped. The hardware is a Checkpoint Safe@Office firewall. The default mode of operation is that wired ...
1 vote
0 answers
770 views
Checkpoint NGX FW1 Routing Between Networks
We have an old Checkpoint NGX FW1 firewall which we have to maintain. For the most part we leave it alone and it just chuggs away and works. The person who originally set it up left years ago and we'...
2 votes
3 answers
4k views
Tracking changes to firewall configs?
Myself and one other indivdual will be taking over some of the daily firewall management duties soon and I'm looking for a way to track changes on our firewall configurations for auditing purposes and ...
7 votes
1 answer
24k views
Checkpoint VPN on Linux
I need to setup a Checkpoint VPN client with a customer who gave me these settings: Authentication Type: P12 certificate Password: ***** Peer Site: IP_ADDRESS They tell me the VPN server is: IPSO 6.2 ...
0 votes
1 answer
191 views
Identify Deprecated Rules on Checkpoint Firewall
I've been asked to find the deprecated rules among the thousands of rules in our Checkpoint firewall. I could do it by writing a perl program to analyze the log and lists of objects & rules, but ...
1 vote
1 answer
269 views
Ideal VPN setup for multiplatform and geo distributed network of servers and clients
As per subject. To give you an idea of what type of devices and client OSes. Servers/network devices: Windows, Linux servers; Juniper, Cisco, Checkpoint Routers/Firewalls Clients: Windows, Linux, ...
3 votes
0 answers
1k views
Can I replace CheckPoint's SSL Network Extender (client) with some vanilla linux software?
I used to run CheckPoint's SSL Network Extender to connect to a customer's network, but it looks like 64bit support for Linux is nowhere in sight. Could I use something else to connect, e.g. OpenVPN?
2 votes
1 answer
397 views
Will a Checkpoint Safe@Office 500WP Respond to Site to Site VPN (IPSec) on WAN2?
Pretty simple - if I have two WANs, will the site-to-site VPN work if I specify the WAN2 IP address? (It currently works with the WAN1 IP.)
1 vote
2 answers
6k views
Can't ping gateway once VPN established
I have two servers: Checkpoint Safe@Office 500 with ip x.x.x.x and local network a.a.a.a/24 Cisco ASA5505 with ip y.y.y.y and local network b.b.b.b/28 Before setting up a vpn I was able to ping y.y.y....
1 vote
2 answers
2k views
Checkpoint R75 Security Gateway without default route
I've set up a virtual lab network in vmware with two networks. vmnet2 (192.168.100.0/24) and vmnet3 (192.168.200.0/24). My R75 is having the ip addresses 192.168.100.1 and 192.168.200.1, and is the ...
2 votes
2 answers
3k views
L2TP VPN routing issue with iphone/ipad
I am able to connect to our company's VPN with L2TP on the iphone and ipad, however, I can only get to certain resources in our company network but not others. After looking at the iOS device logs ...
0 votes
1 answer
14k views
VPN from ASA5505-Checkpoint failing after one hour
I have an IPsec site-site VPN set up and working, however I'm having problems once the connection has been established for over an hour. After an hour ASDM still thinks the VPN is connected and the ...
1 vote
2 answers
181 views
Strange Firewall Issue
We have put a web server in place on a network, it was recently moved from a testing environment in another subnet to a different office. Now that we have the server in place, we can access it via its ...
2 votes
1 answer
2k views
SQL Server 2008 process list - Is this normal?
I'm very new to SQL Server, and just wondered if anyone could tell me if this process list is normal. Wait Time | Last Wait Type | dbid 55372252 | ONDEMAND_TASK_QUEUE | 1 55371504 | ...
1 vote
1 answer
860 views
checkpoint utm-1 edge concurrent users
I am considering to buy a UTM-1 firewall. However, I didnt get exactly what concurrent users mean. There are three models for Concurrent Users 16/32 or Unlimited. What does this mean ? How is ...
0 votes
2 answers
6k views
CheckPoint Endpoint Security VPN client co-existing with Windows VPN
Hey guys, I work as a consultant for a firm with a Checkpoint firewall. I have downloaded and installed the Checkpoint Endpoint Security VPN client. During the installation, I answered no to any ...
0 votes
1 answer
3k views
Checkpoint VPN-1 R60 and Windows 7 64 Bit Client
As per my knowledge of checkpoint VPN-1. My company is using checkpoint VPN-1 R 60 ( I guess as I dont know how to check server version) Firewall(VPN Server). Now the problem is that I installed ...
1 vote
2 answers
572 views
Checkpoint - Routing into the tunnel
I have a simple question for my checkpoint infrastructure. Do i have to route a net which i wanna access over a configured firewall VPN Tunnel. Explanation: I have two firewalls connected over a ...