I do a lot of work with Provider-1 customers and this question comes up every once in a while. They are usually going through the process of cleaning up their objects and policies. It is during this process that they
VPN-1 Power VSX Appliances Released
Back in early December ’08 Check Point quietly released three new appliances for VSX. A quick note to those not familiar with VSX: it is Check Point’s virtual firewall product and has been around for almost ten years. VSX started
Provider-1 R65 SNX License Change in HFA30
Here’s a quick one: In a previous posting I explained how when using SNX in a Provider-1 environment, you needed to license SNX to the IP of the MDS (Multi-Domain Server). Apparently this has now changed. When using Provider-1 R65
Check Point Receives High Marks for Value from CIOs
This was an interesting article. According to CIO Insight, out of 40 technology companies (security and non-security) Check Point finished 3rd behind EMC and Google for “value and reliability.” In fact out of the four categories listed, Check Point finished
HFA 30 Released for R65
This was kind of a quiet HFA release, but HFA 30 for R65 was officially posted on Sept. 14th. Previous to HFA30, there was HFA02 and HFA25 (for messaging security). There are some interesting fixes in HFA30: The Dshield certificate
Mitigating CVE-2008-1447…DNS Cache Poisoning Pt.2
Still some confusion out there as to what conditions need to exist for the latest DNS cache poisoning vulnerability. Many people are thinking that once they patch their DNS servers that the risk has been mitigated. However I am finding
Mitigating CVE-2008-1447…DNS Cache Poisoning
There is a huge issue that was raised a few weeks ago about a vulnerability in DNS and how a DNS server’s cache can be poisoned. There is a lot of information out there describing this latest vulnerability. Basically what
Enabling SPlat Pro after installation
Had a question from a customer last week. They had a bunch of R65 SPlat gateways out in the field. In past they were just passing BGP and OSPF, and they now wanted some of them to participate in dynamic
Eventia Compliance Reports Matrix
In previous Eventia postings I discussed the new Compliance Reports available for Reporter, and presented information on how to install them. These are the new reports that directly reference ISO 17799, COBIT, PCI-DSS, SOX, and HIPAA. Looks like Check Point
Can I view my ASA logs in Tracker?
This was a question I had in a recent meeting with a large Fortune 100 company. They were traditionally a strong Check Point customer, but a shift in upper management forced them to take on 50+ Cisco ASAs. This was
