NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW-1] Policy problem


  • To: [email protected]
  • Subject: [FW-1] Policy problem
  • From: Eric Appelboom <[email protected]>
  • Date: Tue, 13 Nov 2001 08:57:29 +0200
  • Reply-to: Mailing list for discussion of Firewall-1 <[email protected]>
  • Sender: Mailing list for discussion of Firewall-1 <[email protected]>
  • Thread-index: AcFsDYHBwdPN/n8GQWeb0whlTniLEAAAKh2wAACQMzA=
  • Thread-topic: Policy problem

Hi All
I have a CP4.1 problem relating to the installation of a policy.
I redid putkeys between management and fwm and both adknowledge new key
after fwstop\fwstart
I use a fw fetch to management and a policy is copied with a recent
timestamp.

However the rulebase changes are not applied. The old rulebase remains
active.
I have checked object.C rules.C on the fwm but the rules are old but the
timestamp is new.
I have also done a fw unload on fwm issuing a fw fetch which retrieves
fine.
I understand that the policy gets complied when clicking install in
policy editor which it does.
It copys the policyname.W to policyname.pf but why doesnt the fw fetch
get the correct one?
I run fw fetch x.x.x.x (management) and it does get any.all@policyname.

I don't think it is authentication problem cause fw fetch works fine.
We use a fw fetch because the policy editor GUI's authentication problem
between the nodes.
Not sure if this is the cause here? (putkeys I know but it donsnt fix
this)

Help?
Thanx


Eric Appelboom
Office: (+27)Mobile: (+27)*** Disclaimer: The information in this email is confidential and is
intended solely for the addressee(s). Access to this email by anyone
else is unauthorised. If you are not an intended recipient, you must not
read, forward, print, use or disseminate the information contained in
the email. Any representations (contractual or otherwise), views or
opinions presented are solely those of the author and do not necessarily
represent those of the employer or any of its affiliates.

===============================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
===============================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.