Pages

Friday, December 14, 2012

Set Ping/Telnet/SSH/Traceroute source IP address for Cisco router

1. SSH
ip ssh source-interface <interface to use>

2. Telnet
ip telnet source-interface <interface to use>


R1#telnet 10.9.38.3 22 /source-interface l0
Trying 10.9.38.3, 22 ... Open
SSH-2.0-1.36 sshlib: GlobalScape


3. ping
ping <ip address> source <ip address / interface to use>

4. Traceroute 

using extended traceroute:

R1#traceroute
Protocol [ip]:
Target IP address: 10.10.10.10
Source address: 10.11.11.11
Numeric display [n]:
Timeout in seconds [3]:
Probe count [3]:
Minimum Time to Live [1]:
Maximum Time to Live [30]:
Port Number [33434]:
Loose, Strict, Record, Timestamp, Verbose[none]:
Type escape sequence to abort.
Tracing the route to 10.10.10.10
VRF info: (vrf in name/id, vrf out name/id)
  1  *  *  *

Tuesday, December 11, 2012

Cisco ASDM-IDM not able to be installed because of Java Runtime Environment is not installed

Environment:
ASA5510
ASA version 8.0(4)
ASDM version 6.2(5)53
OS: windows 2008 R2

Situation:
Use Google Chrome access ASA5510, download ASDM-IDM package. Filename is dm-launcher.exe.
Double click got following error message.



Error Message shows Java Runtime Environment is not installed on this machine.
Actually when using browser to open http://www.java.com/en/download/testjava.jsp page, Java info on this computer has shown up. It is running on SE 7 U9.

Solution:
After did lots of google research, found one perfect solution here. Deinstall version 7 and install latest 6 version of java  from http://www.filehippo.com/download_jre_32/12538/

That works for me.

Friday, October 12, 2012

How to gracefully shutdown network devices

1. Checkpoint Firewall
a. Gaia
command line : halt
b. SPLAT
shutdown

2. Avocent Console Server
a. ACS5000
login as root user with default password avocent
then halt

b. ACS6000


3. Juniper SRX firewalls
request system pwer-off

4. Cisco Switches and Routers
If there is power switch, just turn it off. Or unplug power cord.

Monday, October 1, 2012

NSM Server shows warning when Disk is getting full

Today, when click server status by accident, it shows warning on status. It gives me some worrying about NSM situation. server_1 status is warning on Disk Usage 91%. After checked the system, I found it might relate to Disk since there is another warning on disk column.


Actually it is quite easy to eliminate this warning message on status. Go to Servers tab on the left panel. Double click server_1 and select Disk and Log Management. Change disk limit to make sure 10% minimum disk left before purging. Default setting is only 1G before purging. Potential risk is if current day log is larger than 1G , then server_1 will be shut down automatically since current day log won't be purged.


After applied the changes, wait a couple fo minutes, it shows normal ok status.


The disadvantage for this method is you probably lose some storage (about 25g Hard drive space). If your auditor has requirement to maintain log longer than what your NSM can store, you may has to setup another syslog server or archive it to remote linux box with trusted relationship. More details please refer to the following kb:

KB 22026
KB 9642

Palo Alto for NGFW facts from Checkpoint view

Compare Palo Alto with Checkpoint from Checkpoint website based on NSS Labs results:

Palo AltoCheck Point
NSS Labs Results - Protects Against HTML Evasions*33%100%
NSS Labs Results - Overall Protection**93%98%
File Sharing Applications170531
Total Applications1,5114,733
Application Social Network Widgets0240,000+
URL Filtering20 million on box100 million cloud based
Data Loss Prevention9 file types and regular expression match532 file types plus file attributes, document templates, dictionaries, keywords and scripting language match
Anti-Bot< 1 million protections (signatures/ DNS/ URLs/ IPs)250 million addresses analyzed for bot discovery
Reputation based protectionUnique multi-tier detection engine (reputation, signatures, mail activity and behavior based) with real-time security intelligence through ThreatCloud

* NSS Labs NGFW Test, 2012
** NSS Labs IPS Test, 2012

-------------------------------------------------------------------------------------------------------------------------------------------------
Palo Alto Networks ignores Standard OSI Model - focused on the application layer

PAN is focused on the
application layer

The seven layers of the Open Systems Interconnection model divide networking and security into discrete manageable components. The SANS Institute and other leading security organizations realize that we must comprehend all layers to deliver complete security.
Palo Alto Networks' focus on the application layer can lead to more security exposures for their customers. Check Point's balanced approach recognizes the importance of considering both the application and networks layers to assess all risks and deliver strong security.

It is only when we can see our networks as individual
components that we can adequately secure these levels.

SANS Institute













----------------------------------------------------------------------------------------------------------------------------------------------------------
Palo Alto Networks defaults to open ports, leaving organizations exposed to attacks
Palo Alto Networks' single pass architecture defaults to open all ports, leaving organizations exposed to attacks. Why? Because its App-ID needs to interact with the application so it can be identified and classified. For security, this is a big problem.
Why would you want to provide attackers an advantage as they prepare a targeted attack? Attackers scan ports to discover vulnerabilities. Because of Palo Alto's focus on application inspection and App-ID, it must first allow a connection to identify the application to enforce policy. This insecurity allows a port scan to divulge details to the attacker about your configurations, devices and security. App-ID focuses on identifying the application first, so it risks unnecessary security exposures.
The Palo Alto approach requires that traffic be allowed to determine the application, something the Network World Clear Choice test noted "could easily result in unintended consequences and insecure configurations – a valid concern."

--------------------------------------------------------------------------------------------------------------------------------
Palto Alto Networks may cause you to blow your PCI audit
Palo Alto Networks' focus on its next generation firewall and the application layer also raises a serious issue for compliance with the PCI Data Security Standard. Organizations spend enormous resources preparing for pass-or-fail PCI audits. One of the clearly stated requirements in the PCI DSS specification is for the organization to deploy "stateful inspection" in the firewall. According to Palo Alto, stateful inspection is being replaced with what they call "new core technology called App-ID." It would be very unfortunate for an organization to fail a PCI audit because it made a bad firewall choice.
PCI DSS RequirementsTesting Procedures
1.3.6 Implement stateful inspection, also known as dynamic packet filtering. (That is, only "established" connections are allowed into the network.)1.3.6 Verify that the firewall performs stateful inspection (dynamic packet filtering). (Only established connections should be allowed in, and only if they are associated with a perviously established session.)


Stateful inspection is being replaced with our new core technology called App-ID, which identifies and classifies applications on the network regardless of port, protocol, evasive tactic or SSL encryption.

CTO, Palo Alto Networks



























-----------------------------------------------------------------------------------------------------------------------------
How Palo Alto Networks can be bypassed with cache poisoning
SIP traffic gets past PAN FW as HTTP traffic
Palo Alto Networks is vulnerable to cache poisoning. For example, a Session Initiation Protocol (SIP) or any other protocol connection can be used as a channel for attacking a company's internal networks. The SIP session could initially be blocked accurately, but by taking advantage of the cache poisoning vulnerability, the SIP session could bypass a Palo Alto firewall. The vulnerability could be exploited as follows:
  1. HTTP is allowed with firewall policy
  2. Opening a SIP session typically used with VoIP communications is correctly blocked
  3. Generating HTTP traffic that causes the cache to hit its threshold – meaning traffic continues going through the cache but is no longer inspected by the firewall
  4. Switching the HTTP connection to SIP, which is then allowed – and exposes you to risk
Strong security products do not allow cache poisoning, and a strong firewall will never stop inspecting network traffic.
Source:
Defcon 2011, Brad Woodberg, Juniper Networks


































---------------------------------------------------------------------------------------------------------------------------

Check Point protects against 100% of evasion techniques tested by NSS Labs
ProductIP Packet FragmentationTCP Stream SegmentationRPC FragmentationURL ObfuscationHTML EvasionFTP EvasionTotal
Check Point100%100%100%100%100%100%100%
Source: NSS Labs NGFW Test, 2012

ProductClient ProtectionServer ProtectionOverall Protection
Check Point99%97%98.3%
Source: NSS Labs IPS Test, 2012
NSS Labs has released the results of its 2012 IPS Group Test that reviewed Intrusion Prevention System products from eight vendors. Once again, the Check Point IPS performed exceptionally well in the tests, demonstrating top-ranked IPS protection. The Check Point 12600 Appliance IPS protected against 100% of the evasion techniques attempted by NSS Labs.
"Resistance to known evasion techniques was perfect... IP fragmentation, TCP stream segmentation, RPC fragmentation, URL obfuscation, HTML Evasion and FTP evasion all failed to trick the product into ignoring valid attacks. Not only were the fragmented and obfuscated attacks blocked successfully, but all of them were also decoded accurately."
The Check Point IPS scored an overall protection rating of 98.3%, improving its 97.3% overall protection rating from the 2011 NSS Labs IPS test.
Highlights of Check Point's performance in the NSS IPS Group Test include:
  • Superior Security
  • Top of the pack with overall protection score of 98.3%
  • Strong security with 100% coverage of evasion techniques
  • A top score for server protection, 97%
  • Best in Class management system that is robust and granular

-------------------------------------------------------------------------------------------------------------------------
The App Gap
  • Check Point tracks more than 531 file sharing apps (a critical application category for enterprises), Palo Alto tracks 170.
  • Check Point tracks more than 4,733 total apps, Palo Alto tracks 1,511.
  • Check Point tracks almost a quarter million widgets, Palo Alto tracks 0.
Check Point tracks more apps, and provides extra granularity of protection because attacks on widgets and configurations go after the individual or specific capabilities of some applications. Palo Alto is supposed to be an "application security expert," so wouldn't you expect its focus on the application layer to provide a complete solution? Consider three prominent examples, such as Poison Ivy, Access Remote PC and Anyplace Control. Check Point has application controls for all three; Palo Alto has none.
The numbers tell the story. Unfortunately, business owners using Palo Alto are left on their own to figure out what to do with untracked apps.
Palo Alto's limited application coverage is a visibility and security issue.

















--------------------------------------------------------------------------------------------------------------------------

Palo Alto Networks has limited visibility of risk
NO examination of data in PDF—only 9 file formats are supported
NO identification of non-English characters in .docx (Office 2007 and above documents)
NO protection for customer list or any dictionary larger than 350 items
NO protection for personally identifiable information other than US SSN & CCN
NO protection for HIPAA, GLBA, SEC filings
NO protection for source code, CAD-CAM, ASIC or FPGA designs, patent filings
NO validation for IBAN, tax numbers, service request numbers, etc.
The Palo Alto solution provides incomplete visibility for protecting information and inspecting content. Its technology has limited abilities to deeply inspect a variety of file formats and data types beyond the basics. Why risk your critical corporate data or intellectual property with Palo Alto Networks? Check Point provides you with complete visibility and comprehensive protection.


We found that the file blocking was easily fooled. For example, putting a file into a zip archive effectively hid the file type, as did changing the first few bytes of the file (by adding blank lines) and, in one case, changing the filename—which we didn't expect to work.

 August 2011


PAN's promised functionality does not translate to reality in real-world deployments.

Leading Online Investment Firm


PAN's solution is full of holes.

International Film School





































--------------------------------------------------------------------------------------------------------------------------

Palo Alto Networks has weak management capabilities

Palo Alto Networks has no built-in central monitoring tools for VPN configuration.
With Palo Alto Networks, each tunnel is configured separately.
A mesh of 30 gateways requires manual set-up of 870 tunnels!

Here's one example of a gap in Palo Alto's security management: its configuration and management of Virtual Private Networks. When setting up VPNs, tunnels must be defined for the VPN connectivity. When configuring Palo Alto VPNs, you are required to manually configure gateways for each tunnel. For 30 security gateways, this would require 870 tunnels. You would need to manually configure each one and develop scripts to stitch them together. Palo Alto does not have built-in centralized monitoring tools for VPN configuration.
Obviously, the manual effort required by Palo Alto will make large deployments very difficult. As noted in its latest Next Generation Firewall product review by Network World: "Large VPN deployments will not want to move to Palo Alto…any large deployment would have to be built entirely by hand".
Check Point offers 1-click VPN configuration, which automates the process and improves your productivity. With Check Point, there is no need to manually build and configure 870 individual VPN tunnels! And our SmartView Monitor provides complete visibility into online tunnel status and VPN counters.


Large VPN deployments will not want to move to Palo Alto... any large deployment would have to be built entirely by hand.

NetworkWorld August 2011


Palo Alto Networks doesn't have anything comparable to Check Point Multi-Domain Management.

Major Energy Company



































Wednesday, September 26, 2012

Checkpoint Gaia FW Lost Connection to Management after a reboot


After rebooted one of cluster member, I found it lost the connection to Management Server for somehow. SIC, SSH, GUI all are not working anymore. Through Console, I could log into firewall and found this:

[Expert@CP-FW-2]# cpconfig
cpinst Error: Host name resolution for CP-FW-2 failed.
                   Local host name resolution is required for normal Check Point Security Gateway operation
                   Please correct this error and run cpstart again:
                   Add an entry for CP-FW-2 in /etc/hosts


Since it mentioned /etc/hosts file, based on previous experience, I opened the hosts file to check.

[Expert@CP-FW-2]# cat /etc/hosts
#  This file was AUTOMATICALLY GENERATED
#  Generated by /bin/hosts_xlate on Wed Sep 26 09:27:03 2012
#
#  DO NOT EDIT
#
192.168.1.1 CP-FW-2.gddd.com
127.0.0.1 localhost
::1 localhost

I  added a new line into hosts file:
192.168.1.1 CP-FW-2 

then did cpstop and cpstart. Everything comes back. Policy loaded and firewall connected back to management server. But this change doesn't survive a reboot. Since we are using Gaia version R75.40, Gaia doesn't support manually configuration of hosts file. What we can do is using following method to change hosts file:

from clish: set host name <hostname> ipv4-address <interface IP>
save config

Tested with a reboot, the change is kept in hosts file this time. Issue resolved.


Tuesday, September 25, 2012

ASA Memory Leak

Today, I got a problem when tried to save the configuration. There is no memory available on my switch.


Symptom:

CFWP2001/act/pri# sh startup-config | i 216.66.216.11
CFWP2001/act/pri# wr
Building configuration...
No memory available

Error executing command
[FAILED]




GDCM-CFWP2001/act/pri# show proc mem

--------------------------------------------------------------
Allocs   Allocated       Frees         Freed           Process
          (bytes)                      (bytes)
--------------------------------------------------------------
873      4214872         18            4874            *System Main*
0        0               0             0               557mcfix
0        0               0             0               uauth_urlb clean
2146071  102943376       14400         1057944         CTM message handler
14242    690750          14217         673810          ssh
0        0               0             0               udp_timer
0        0               0             0               block_diag
0        0               0             0               emweb/cifs_timer
1        24              0             0               EAPoUDP-sock
0        0               0             0               SSL
221      5243972         99            3759040         rtcli async executor process
135      13838116        81            13876196        fover_health_monitoring_thread
0        0               0             0               Chunk Manager
29       18622           4             2178            ci/console
0        0               0             0               557statspoll
0        0               2             8324            pm_timer_thread
1157     134548          807           105416          NAT security-level reconfiguration
0        0               0             0               Reload Control Thread
0        0               0             0               CTCP Timer process
2        8324            0             0               netfs_mount_handler
6596     295976          9287          324941          vpnfol_thread_msg
0        0               0             0               EAPoUDP
0        0               0             0               SMTP
0        0               0             0               IP Thread
4        744             0             0               Quack process
2        64              0             0               ha_trans_ctl_tx
1        2097188         6             49548           PIX Garbage Collector
0        0               0             0               fover_rx
74       202752          0             0               fover_thread
0        0               0             0               IKE Timekeeper
0        0               0             0               ICMP event handler
90452    24930580        126690        25945244        aaa
0        0               0             0               L2TP data daemon
1974343  1479368994      2836452       3275479804      Dispatch Unit
2        24              105           186716          arp_timer
30344027213811737332     303440278     13811762304     vpnfol_thread_timer
222235   258504990       207479        94589760        Unicorn Admin Thread
26370094510427148804     263379444     9994667952      snmp
20       30384           5             2560            Logger
126      8436            1             140             ARP Thread
12847    7297096         0             0               Session Manager
1        32              0             0               ha_trans_data_tx
0        0               0             0               IP Address Assign
0        0               0             0               fover_tx
26       830367          0             0               netfs_thread_init
5        40687           0             0               lu_ctl
30938955837329974751     335636985     39473080635     IKE Daemon
0        0               0             0               dbgtrace
0        0               0             0               IP Background
0        0               0             0               L2TP mgmt daemon
2        152             0             0               CF OIR
0        0               0             0               arp_forward_thread
60       233112          4             40              vpnfol_thread_sync
2        8324            0             0               vpnlb_thread
0        0               2             8324            Thread Logger
9        388             0             0               icmp_thread
3        15119           0             0               uauth
1415     196303          522           55651           fover_FSM_thread
0        0               0             0               QoS Support Module
37       33976           0             0               fover_ip
33       5902888         32            5902848         update_cpu_usage
0        0               0             0               RADIUS Proxy Event Daemon
0        0               4224          180889          ssh/timer
4094714  245920836       4326427       274889652       tmatch compile thread
0        0               32            329792          CMGR Server Process
0        0               13            51315           ppp_timer_thread
0        0               0             0               lina_int
0        0               0             0               Lic TMR
0        0               0             0               vpnfol_thread_unsent
25004575 1706655016      0             0               IKE Receiver
0        0               0             0               udp_thread
0        0               0             0               Uauth_Proxy
2712     43436           0             0               lu_rx
0        0               0             0               vPif_stats_cleaner
0        0               0             0               Client Update Task
1323     1523422         1310          1520510         fover_rep
0        0               189           745632          qos_metric_daemon
4        4160            0             0               RADIUS Proxy Listener
0        0               0             0               Crypto PKI RECV
0        0               16            123936          CMGR Timer Process
0        0               0             0               vpnlb_timer_thread
0        0               0             0               tcp_fast
0        0               0             0               Integrity Fw Timer Thread
69224    288110288       34694         555104          listen/ssh
0        0               0             0               tcp_thread
3        544             0             0               lu_dynamic_sync
0        0               15            84261           Checkheaps
5        168             13            41764           fover_parse
157      16740           125           497624          NIC status poll
0        0               0             0               RADIUS Proxy Time Keeper
948      2083467         1659          2255766         Crypto CA
882337   86854298        821197        62093512        IPsec message handler
0        0               5681          32292209        ssm4ge_cfg_poll_thread
0        0               0             0               tcp_slow
0        0               0             0               netfs_vnode_reclaim
0        0               0             0               TLS Proxy Inspector
5        264             62            479228          NTP
34612    553792          34612         830688          npshim_thread
617364   23581602        707494        24661886        SNMP Notify Thread
0        0               0             0               fover_ifc_test
6        14112           0             0               Integrity FW Task


CFWP2001/act/pri# show version

Cisco Adaptive Security Appliance Software Version 8.0(4) 
Device Manager Version 6.2(5)53

Compiled on Thu 07-Aug-08 20:53 by builders
System image file is "disk0:/asa804-k8.bin"
Config file at boot was "startup-config"

GDCM-CFWP2001 up 1 year 190 days
failover cluster up 1 year 190 days

Hardware:   ASA5510, 256 MB RAM, CPU Pentium 4 Celeron 1600 MHz
Internal ATA Compact Flash, 256MB
BIOS Flash M50FW080 @ 0xffe00000, 1024KB

Encryption hardware device : Cisco ASA-55x0 on-board accelerator (revision 0x0)
                             Boot microcode   : CN1000-MC-BOOT-2.00
                             SSL/IKE microcode: CNLite-MC-SSLm-PLUS-2.03
                             IPSec microcode  : CNlite-MC-IPSECm-MAIN-2.05
 0: Ext: Ethernet0/0         : address is 001b.53ff.057c, irq 9
 1: Ext: Ethernet0/1         : address is 001b.53ff.057d, irq 9
 2: Ext: Ethernet0/2         : address is 001b.53ff.057e, irq 9
 3: Ext: Ethernet0/3         : address is 001b.53ff.057f, irq 9
 4: Ext: Management0/0       : address is 001b.53ff.0580, irq 11
 5: Int: Internal-Data0/0    : address is 0000.0001.0002, irq 11
 6: Int: Not used            : irq 5
 7: Ext: GigabitEthernet1/0  : address is 001b.d5e8.cf25, irq 255
 8: Ext: GigabitEthernet1/1  : address is 001b.d5e8.cf26, irq 255
 9: Ext: GigabitEthernet1/2  : address is 001b.d5e8.cf27, irq 255
10: Ext: GigabitEthernet1/3  : address is 001b.d5e8.cf28, irq 255
11: Int: Internal-Data1/0    : address is 0000.0003.0002, irq 255

Licensed features for this platform:
Maximum Physical Interfaces  : Unlimited
Maximum VLANs                : 100    
Inside Hosts                 : Unlimited
Failover                     : Active/Active
VPN-DES                      : Enabled
VPN-3DES-AES                 : Enabled
Security Contexts            : 2      
GTP/GPRS                     : Disabled
VPN Peers                    : 250    
WebVPN Peers                 : 2      
AnyConnect for Mobile        : Disabled
AnyConnect for Linksys phone : Disabled
Advanced Endpoint Assessment : Disabled
UC Proxy Sessions            : 2      

This platform has an ASA 5510 Security Plus license.

Serial Number: JX1122L1L
Running Activation Key: 0x71104d4b 0xc5ae630 0x0c001bc 0x800e80c 0x85198d88
Configuration register is 0x1
Configuration last modified by enable_15 at 16:00:39.588 EDT Tue Sep 25 2012

-------------------------------------------------------------------------------

Resolution:

Fix problem with this command : 


CFWP2001/act/pri(config)# clear configure threat-detection 
CFWP2001/act/pri(config)# wr
Building configuration...
Cryptochecksum: 06eb770b 405ddedd bf93338e 2456bded

68557 bytes copied in 3.430 secs (22852 bytes/sec)
[OK]
GDCM-CFWP2001/act/pri(config)#



Wednesday, July 18, 2012

"GRE over IPSec" or "IPSec over GRE" ?


I was confusing IPSec over GRE this term before. Spent some hours to google Internet. Found out lots of people doesnot really understanding what are difference between them. Eventually found this answer at http://onlinestudylist.com/archives/ccie_security/2009-August/018744.html


"

There is no terminology as IPSec over GRE. It is always GREoIPSec.

But the question, do you want to put the IPSec into GRE or GRE into IPSec.
It all depends on your configuration.

GREoIPSec is mostly used, when we need encryption but the traffic is not
IPSec compatible. For example, multicast or non IP traffic can't be
encapsulated directly into IPSec. Hence first we encapsulate using GRE and then place it in IPSec.


When you apply crypto map directly on the GRE tunnel interface, IPSec
encapulates the interesting traffic and then this IPSec packet is placed
into GRE.

interface Tunnel0
ip address 10.20.30.40
tunnel source FastEthernet1/0
tunnel destination 10.20.30.43
crypto map vpn ----------------> IPSec over GRE


or

interface Tunnel0
ip address 10.20.30.40
tunnel source FastEthernet1/0
tunnel destination 10.20.30.43
tunnel protection ipsec profile mine ----------->
IPSec over GRE
When you apply crypto map on the physical interface to which the GRE tunnel
is sourced and have interesting traffic as GRE, then the GRE traffic is placed into IPSec.

interface Tunnel0
ip address 10.20.30.40 255.255.255.0
tunnel source FastEthernet1/0
tunnel destination 10.20.30.43

int FastEthernet1/0
crypto map vpn
-------------------> GRE over IPsec

" 

Tuesday, June 12, 2012

Configuring Polycom Video Conference System - HDX 8000


My company is using Polycom solution to provide video conference for all branches. Recently there is a issue which one way video and audio from my site. What I found trick part is the firewall settings on Polycom.

I would like to go through main configurations on our Device first:

1. On system settings page, set up name and other basic properties.
2. Network Configuration:

Do not forget to put DNS servers in it, else your time server test will be failure. Default time server is ntp.polycom.com

3. Other additional settings, such as snmp, multiple camera, multiple screen support, multipoint support. Some of them may need license to support it.

4. Since we are using Internal IP address, this device definitely is behind firewall or other security devices. During testing, we found we could not get video and audio but other site can see and hear us. After searched some documents and played a little bit, we found trick part is NAT configuration on HDX 8000.

5. Test sites from Polycom Support Page


US Test Numbers

Andover, MA

  
  • System Type: VSX 8000 #1
  • Network Interface: PRI ISDN
  • Capabilities: Up to 1472K @ 60fps
  • Test Numbers:
    ISDN: (978) 292-2853
    LAN/IP: 140.242.250.200
 
  • System Type: VSX 8000 #2
  • Network Interface: PRI ISDN
  • Capabilities: Up to 1472K @ 60fps
  • Test Numbers:
    ISDN: (978) 292-2854
    LAN/IP: 140.242.250.204
 
  • System Type: VS 4000 #1
  • Network Interface: PRI ISDN
  • Capabilities: Up to 1472K @ 60fps
  • Test Numbers:
    ISDN: (978) 292-2855
    LAN/IP: 140.242.250.202
  
  
  
  • System Type: VS 4000 #2
  • Network Interface: PRI ISDN
  • Capabilities: Up to 1472K @ 60fps
  • Test Numbers:
    ISDN: (978) 292-2840
    LAN/IP: 140.242.250.203
 
  • System Type TPX 300
  • Network Interface IP Only
  • Capabilities Up to 2Mbs (Per codec)
  • Test Numbers:
    Codec 1 IP: 140.242.250.223 Codec 2 IP: 140.242.250.224 Codec 3 IP: 140.242.250.225
 
  • System Type: HDX 8000
  • Network Interface: IP Only
  • Capabilities: Up to 1920 @ 60fps
  • Test Numbers:
    LAN/IP: 140.242.250.205
6. Enable Remote Monitoring
By default, we could not see camera snapshot from remote website. There is no option you can enable it from GUI. 
Another trick is to do it from Physical Device by remote controller at meeting room. 
after enabled Video over the web, you will see near end video or you will see both near and far end in a call. Also you can control pan left, right, close, further etc.

Tuesday, June 5, 2012

Enable SCP user on R75.40 Management Server


Enable SCP for SPLAT Smart-1 R75.40 Management Server

1) Login with the admin account

2) Enter Expert mode

3) Type adduser username
adduser scpuser

4) Enter the password when prompted

[Expert@CP-Management]# adduser scpuser
Enter password: 
Enter password (again): 
User 'scpuser' was added successfully


5) Type vi /etc/passwd

6) Change the end of the line with the username from /bin/cpshell to /bin/bash
It should look like this... username:x:0:0::/home/username:/bin/bash

[Expert@CP-Management]# vi /etc/passwd


root:x:0:0:root:/root:/bin/bash
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
nobody:x:99:99:Nobody:/:/sbin/nologin
vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
rpm:x:37:37::/var/lib/rpm:/sbin/nologin
pcap:x:77:77::/var/arpwatch:/sbin/nologin
admin:x:0:0::/home/admin:/bin/cpshell
postfix:*:1001:1001:postfix:/no/where:/bin/false
cp_postgres:x:1002:0::/home/cp_postgres:/bin/sh
scpuser:x:0:0::/home/scpuser:/bin/bash   
~



7) Type vi /etc/group

8) Add the username to the root group
It should look like this? root:x:0:root,username

[Expert@CP-Management]# vi /etc/group

root:x:0:root,scpuser
bin:x:1:root,cp_postgres
daemon:x:2:root
sys:x:3:root
adm:x:4:root
tty:x:5:
disk:x:6:root
mem:x:8:
kmem:x:9:
wheel:x:10:root
man:x:15:
dip:x:40:
lock:x:54:
nobody:x:99:
users:x:100:
floppy:x:19:
vcsa:x:69:
ntp:x:38:
rpm:x:37:
utmp:x:22:
pcap:x:77:
postdrop:*:1007:


9) It works right away.

10) Configure winscp to log into Mgmt server
Change protocol from sftp to scp
11. Thats all.


9) Type vi /etc/scpusers 

10) Add the username on one line within this file


11) Reboot the firewall or restart sshd service

Enable Hidden 3D Report Tool on R75.40 SmartEvent Tool

What is 3D Report Tool?


It analyze your network and provide a comprehensive security analysis report – exposing security risks and suggesting remediation.
  • All security threats in one single report (High risk application and web sites, intrusions attempts, sensitive data loss, bandwidth hogging and more…)
  • Easy-to-read graphical reports
  • This service is free of charge
  • No risk to your network environment
more comments :
"The 3D Security Reporting tool was originally intended to be a sales tool of sorts for our sales teams. We also released it to partners via Partner Map. 

In R75.20, we released a separate version of the 3D Security Reporting tool. It required some minor changes to the SmartEvent server and updated SmartConsole apps.

In R75.40, we included the 3D Security Reporting tool in the regular R75.40, but it is hidden with a registry hack (as noted in the thread). We are updating the tool independently of our regular releases (at the moment) and are periodically releasing updated SmartConsole apps and SmartEvent server fixes. 

The 3D Security Report requires that MS Office be installed on the machine that the SmartConsole apps are loaded on.
"

At Partner Portal 3D Report Kit has been upgraded to R75.40.

For R75.20, Direct Download Link:
https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=13231

Actually, 3D Report tool has been integrated into R75.40 SmartEvent. You just need a registry change to enable a button:

[HKEY_CURRENT_USER\Software\Checkpoint\Management Clients\6.2.5\GA\Eventia Analyzer Client] "GenerateReportsAvailable"=dword:00000001 


Actually, it will need Microsoft Office installed. Now you can check if your SmartEvent has this button or not. 

More screenshot from 3D report kit:

Templates screen: