NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] FW-1 and AceServer 5.0.1



Well,
in rev. 4.x they recommended an entry in /etc/services like this
securid    5500/udp

as of 5.0.x in their list of ad ons to /etc/services there are numerous
entries like
securidprop_00    5505/tcp
securidprop_01    5506/tcp
...
and so on. The  entry concerning securid 5500/udp is not recommended in the
docs any more. Maybe they thought there is no need to mention because it is
already there, maybe they droped 5500/udp .  I do not know.

Fact is that i.e. the filter module tries to reach the server via 550n/udp
and gets back icmp unreachable. by setting the service with sdconfig you can
force it to Port 5500/udp, but even with this ... you get back icmp
unreachable from the server.

--Joerg


-----Original Message-----
From: Zeltser, Roman
To: [email protected]
Sent: 1/28/02 8:18 PM
Subject: Re: [FW-1] FW-1 and AceServer 5.0.1

>>AceServer 5.0 seems to have changed
authenticaten services from 5500/udp to 550n/tcp.

Do have any proof of it?
**********************************
Roman Zeltser,
@National Computer Center,
RSIS & DNE



-----Original Message-----
From: Joerg Fritsch [mailto:[email protected]]
Sent: Monday, January 28, 2002 12:43 PM
To: [email protected]
Subject: [FW-1] FW-1 and AceServer 5.0.1


Hello,

I have kind of rediculous problem. AceServer 5.0 seems to have changed
authenticaten services from 5500/udp to 550n/tcp.  I can generate all
types
of "customized" sdconf.rec files and transfer them to my filters.
Regrettably the FirewallModule always trys to reach the AceServer via
udp
... and since there is no service listening any more the fw gets back
ICMP
unreachable.

Has anyone ever fixed that ?

--Joerg

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.