NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [FW1] FTP Problems 4.1SP3



Title: RE: [FW1] FTP Problems 4.1SP3

John, under almost all circumstances you do this just on the management console.  When you compile and push the new policy the changes takes to the firewall.  A few things though, keep in mind any changes you make to the base.def will happen on all the enforcement points that the respective management console controls.  In addition, make a backup copy of the file before you edit it, it is a sensitive file as I have proven in screwing around with it a while back for the same issue.  The fix mentioned in the resolution does indeed work.  And lastly, when you upgrade again to the next SP, you will need to 're-do' the change, as the service packs put a new base.def in appropriate to the new CheckPoint version.

Anyone else out there know how great the security ramifications of this change actually is?  It seems quite negligible and appears to simply mean the coder of the program that is failing didn't properly follow RFC standards for FTP in terms of ending lines or something like that.  Any thoughts?

Jarrett

-----Original Message-----
From: John Warren [mailto:[email protected]]
Sent: Saturday, April 14, 2001 21:12
To: [email protected]
Subject: [FW1] FTP Problems 4.1SP3



My ftp from internal hosts to my DMZ, as well as inbound ftp was working
fine until I upgraded from SP2 to SP3 (IPSO).

I've got a distributed install (inspection module and management module on
separate systems), and am a little confused on the help article about the
\r\n fix done on the base.def file.

Do I do this on the firewall system, the management system, or both?

The way the article reads, I'm supposed to do it on the management station,
then push the policy.  Does the base.def get built into the "new" policy?

FTP behavior is once a ftp session is initiated, a connect is seen, and then
it hangs.  Both ftp options in the properties tab are checked.

Thanks,
John
_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.