Search the web
Sign In
New User? Sign Up
sidewinder-users · Sidewinder Firewall Users
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want to share photos of your group with the world? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 202 - 231 of 231   Newest  |  < Newer  |  Older >  |  Oldest
Messages: Show Message Summaries   (Group by Topic) Sort by Date v  
#231 From: "mikropsoft" <mikropsoft@...>
Date: Tue Dec 16, 2008 10:08 am
Subject: Branch locked by user root
mikropsoft
Offline Offline
Send Email Send Email
 

Hi All,

My fw send me the audit log below via e-mail 200-500 per day.

what could be the cause for this error?

Thanks for the supports..


For a complete listing of the events that triggered this alarm please execute the following command (All on one line):

 

___BEGIN_CMD___

acat -a -e "type AUDIT_T_CFG_CHANGE

and stime 20081215093300 and etime 20081215093300" /var/log/audit.raw ___END_CMD___

 

Note: Due to rounding error and network traffic patterns, the above command

      may produce more events than were included in this alarm.

 

The following are the last 1 events seen:

 

Dec 15 09:33:00 2008 EET  f_system a_general_area t_cfg_change p_major

pid: 10502 ruid: 0 euid: 0 pgid: 10501 fid: 0 logid: 0 cmd: 'cf'

domain: CARW edomain: CARW hostname: fw.local admin: root

information: Branch  locked by user root


#230 From: "scott_debaets" <scott_debaets@...>
Date: Tue Sep 9, 2008 1:31 pm
Subject: Maximum Route Table with GateD - Sidewinder V7
scott_debaets
Offline Offline
Send Email Send Email
 
Hi

I am trying to find information on the maximum route table entry/size
for a sidewinder 2150e running v7.  Looking to run OSPF with approx
2000 routes.

Secure Computing has only said there is no Hard Cap but I haven't been
able to get anymore information other than that.

Any help would be appreciated.

#229 From: fosgood <fosgood_007@...>
Date: Mon May 19, 2008 9:10 am
Subject: Tepol error on 110d and 210d models
fosgood_007
Online Now Online Now
Send Email Send Email
 
All,

I recently ran into an error that support has never heard of.  If you power down a Sidewinder 7 running on this hardware and don't do it properly (shutdown -r now, shutdown -h now, etc..)
the system boots and freezes on the following error:

tepol version 1: 4 dg (128 members) 141 domains (3 secondary 131 primary)
         318 dits 2067 subtype 4556 ddts

The numbers in question, (128, 141, 3, etc.) change with every reboot, but the error is generally the same. 

If I choose option 4(boot from serial console) I can get to a prompt where I would generally run an fsck command or something, but that does work, even with the switches.

I get this same error when I choose the Emergency Mode option.

Any ideas here?  I would rather learn what causes this and how to fix it.  I know I can always re=install.

Thx,

 - fosgood




#228 From: sidewinder-users@yahoogroups.com
Date: Tue Apr 29, 2008 6:29 pm
Subject: New file uploaded to sidewinder-users
sidewinder-users@yahoogroups.com
Send Email Send Email
 
Hello,

This email message is a notification to let you know that
a file has been uploaded to the Files area of the sidewinder-users
group.

   File        : /Scripts/sef-parser-beta1.pl.gz.uu
   Uploaded by : ace5657388 <ace5657388@...>
   Description : Perl BETA script to parse SEF remote syslog events

You can access this file at the URL:
http://groups.yahoo.com/group/sidewinder-users/files/Scripts/sef-parser-beta1.pl\
.gz.uu

To learn more about file sharing for your group, please visit:
http://help.yahoo.com/l/us/yahoo/groups/original/members/web/index.htmlfiles

Regards,

ace5657388 <ace5657388@...>

#227 From: fosgood <fosgood_007@...>
Date: Tue Apr 29, 2008 4:44 pm
Subject: RE: (unknown)
fosgood_007
Online Now Online Now
Send Email Send Email
 

Don't forget "cf nss"
This gives you all of the server and ipfilter information as well.


I believe that in Sidewinder 7 "cf acl q" has been replaced with "cf policy q" as well.


- fosgood

#226 From: "James Morales" <jamesmmorales@...>
Date: Sun Apr 27, 2008 3:33 am
Subject: RE: (unknown)
jamesmmorales
Offline Offline
Send Email Send Email
 

 Better yet, just do cf acl export type=active_rules > /tmp/active.rules.txt

Then import them into Excel

You may want to get the network objects and proxies while you are at it.

Network objects, cf acl export type=net_objects > /tmp/network.objects.txt

Proxies, cf proxy query > /tmp/proxies.txt

 

Good luck!

Remember that the man cf pages give a lot of information and if you want to look at anything in particular regarding cf, then just do man cf_server or whatever the convention or area is.

 

From: sidewinder-users@yahoogroups.com [mailto:sidewinder-users@yahoogroups.com] On Behalf Of Mike Swier
Sent: Friday, April 25, 2008 7:10 PM
To: sidewinder-users@yahoogroups.com
Subject: Re: [sidewinder-users] (unknown)

 

 

cf acl query > acl.query

info_sec_consultant <info_sec_consultant@...> wrote:

I am looking for a way to get the policies (firewall/vpn rules or more)
out of the box to do offline analysis. Is there any way to get those --
like saving to a file or accessing from database if they are maining in
db or any other way I did not think of.. CheckPoint supports CMPI
connection to get the firewall policies out of the box for further
analysis or reporting. I am looking for similar ways for Sidewinder
also. Does any one done any similar work before.. please let me know
new ways to do this...

Thanks & Regards,

Sridhar P



------------------------------------

Yahoo! Groups Links

<*> To visit your group on the web, go to:
http://groups.yahoo.com/group/sidewinder-users/

<*> Your email settings:
Individual Email | Traditional

<*> To change settings online go to:
http://groups.yahoo.com/group/sidewinder-users/join
(Yahoo! ID required)

<*> To change settings via email:
mailto:sidewinder-users-digest@yahoogroups.com
mailto:sidewinder-users-fullfeatured@yahoogroups.com

<*> To unsubscribe from this group, send an email to:
sidewinder-users-unsubscribe@yahoogroups.com

<*> Your use of Yahoo! Groups is subject to:
http://docs.yahoo.com/info/terms/

 


#225 From: Mike Swier <mswier@...>
Date: Fri Apr 25, 2008 11:09 pm
Subject: Re: (unknown)
mswier
Offline Offline
Send Email Send Email
 
 
cf acl query > acl.query

info_sec_consultant <info_sec_consultant@...> wrote:
I am looking for a way to get the policies (firewall/vpn rules or more)
out of the box to do offline analysis. Is there any way to get those --
like saving to a file or accessing from database if they are maining in
db or any other way I did not think of.. CheckPoint supports CMPI
connection to get the firewall policies out of the box for further
analysis or reporting. I am looking for similar ways for Sidewinder
also. Does any one done any similar work before.. please let me know
new ways to do this...

Thanks & Regards,

Sridhar P



------------------------------------

Yahoo! Groups Links

<*> To visit your group on the web, go to:
http://groups.yahoo.com/group/sidewinder-users/

<*> Your email settings:
Individual Email | Traditional

<*> To change settings online go to:
http://groups.yahoo.com/group/sidewinder-users/join
(Yahoo! ID required)

<*> To change settings via email:
mailto:sidewinder-users-digest@yahoogroups.com
mailto:sidewinder-users-fullfeatured@yahoogroups.com

<*> To unsubscribe from this group, send an email to:
sidewinder-users-unsubscribe@yahoogroups.com

<*> Your use of Yahoo! Groups is subject to:
http://docs.yahoo.com/info/terms/



#224 From: "info_sec_consultant" <info_sec_consultant@...>
Date: Fri Apr 25, 2008 6:30 pm
Subject: (No subject)
info_sec_con...
Offline Offline
Send Email Send Email
 
I am looking for a way to get the policies (firewall/vpn rules or more)
out of the box to do offline analysis. Is there any way to get those --
like saving to a file or accessing from database if they are maining in
db or any other way I did not think of.. CheckPoint supports CMPI
connection to get the firewall policies out of the box for further
analysis or reporting. I am looking for similar ways for Sidewinder
also. Does any one done any similar work before.. please let me know
new ways to do this...

Thanks & Regards,

Sridhar P

#223 From: "fosgood_007" <fosgood_007@...>
Date: Tue Feb 5, 2008 2:29 am
Subject: Re: Does Sidewinder 4150 G2 supports IPX
fosgood_007
Online Now Online Now
Send Email Send Email
 
Sidewinder 4.0 had Xeyes.


--- In sidewinder-users@yahoogroups.com, "K K" <kkadow@...> wrote:
>
> On 2/3/08, Justin Beeler (JBEELER.COM) <justin@...> wrote:
> > Scott is there any plan on a web interface for the Sidewinder GUI?
> > or are you guys sticking with a strickly Winblowz interface?
>
> Personally, I'm not a fan of web-based firewall management.
>
> OTOH, I miss the old X cobra client.
>
>
> Kevin
>

#222 From: Scott Montgomery <scottyva@...>
Date: Mon Feb 4, 2008 6:45 pm
Subject: Re: Re: Does Sidewinder 4150 G2 supports IPX
ScottyVA
Offline Offline
Send Email Send Email
 
np, sorry it couldn't be more positive...next time...


fakhruddin_seth <fakhruddin_seth@...> wrote:
hi scott,
thanks for you answer.

--- In sidewinder-users@yahoogroups.com, Scott Montgomery
<scottyva@...> wrote:
>
> No IPX support is available on any Sidewinder appliance of any
version.
>
> S
>
> fakhruddin_seth <fakhruddin_seth@...>
wrote: Hi Guys,
> Can any one share info about IPX support in Sidewinder 4150 G2
> Appliance, is it available or not?
> thanks in advance.
>
>
>
>
>
>
> ---------------------------------
> Looking for last minute shopping deals? Find them fast with Yahoo!
Search.
>



Looking for last minute shopping deals? Find them fast with Yahoo! Search.

#221 From: "fakhruddin_seth" <fakhruddin_seth@...>
Date: Mon Feb 4, 2008 6:10 pm
Subject: Re: Does Sidewinder 4150 G2 supports IPX
fakhruddin_seth
Offline Offline
Send Email Send Email
 
hi scott,
thanks for you answer.


--- In sidewinder-users@yahoogroups.com, Scott Montgomery
<scottyva@...> wrote:
>
> No IPX support is available on any Sidewinder appliance of any
version.
>
> S
>
> fakhruddin_seth <fakhruddin_seth@...>
wrote:                               Hi Guys,
>  Can any one share info about IPX support in Sidewinder 4150 G2
>  Appliance, is it available or not?
>  thanks in advance.
>
>
>
>
>
>
> ---------------------------------
> Looking for last minute shopping deals?  Find them fast with Yahoo!
Search.
>

#220 From: "K K" <kkadow@...>
Date: Mon Feb 4, 2008 4:18 am
Subject: Re: Does Sidewinder 4150 G2 supports IPX
kevinkadow
Offline Offline
Send Email Send Email
 
On 2/3/08, Justin Beeler (JBEELER.COM) <justin@...> wrote:
> Scott is there any plan on a web interface for the Sidewinder GUI?
> or are you guys sticking with a strickly Winblowz interface?

Personally, I'm not a fan of web-based firewall management.

OTOH, I miss the old X cobra client.


Kevin

#219 From: "Justin Beeler (JBEELER.COM)" <justin@...>
Date: Mon Feb 4, 2008 12:25 am
Subject: Re: Does Sidewinder 4150 G2 supports IPX
ljs442
Offline Offline
Send Email Send Email
 
Scott is there any plan on a web interface for the Sidewinder GUI? or are you guys sticking with a strickly Winblowz interface?

Justin Beeler GS-12
USAF/AFTAC

Scott Montgomery wrote:

No IPX support is available on any Sidewinder appliance of any version.

S

fakhruddin_seth <fakhruddin_seth@yahoo.co.in> wrote:

Hi Guys,
Can any one share info about IPX support in Sidewinder 4150 G2
Appliance, is it available or not?
thanks in advance.



Looking for last minute shopping deals? Find them fast with Yahoo! Search.

-- ----------------------------------------------------------------------
Justin Beeler (JBEELER.COM)
Website URL: http://www.jbeeler.com
- UNIX IS user friendly.....it's just picky about who it chooses to be friends with.
"The day Microsoft makes something that doesn't suck is probably the day they start making vacuum cleaners." -Ernst Jan Plugge.
----------------------------------------------------------------------

#218 From: Scott Montgomery <scottyva@...>
Date: Mon Feb 4, 2008 12:21 am
Subject: Re: Does Sidewinder 4150 G2 supports IPX
ScottyVA
Offline Offline
Send Email Send Email
 
No IPX support is available on any Sidewinder appliance of any version.

S

fakhruddin_seth <fakhruddin_seth@...> wrote:
Hi Guys,
Can any one share info about IPX support in Sidewinder 4150 G2
Appliance, is it available or not?
thanks in advance.



Looking for last minute shopping deals? Find them fast with Yahoo! Search.

#217 From: "fakhruddin_seth" <fakhruddin_seth@...>
Date: Sun Feb 3, 2008 6:04 pm
Subject: Does Sidewinder 4150 G2 supports IPX
fakhruddin_seth
Offline Offline
Send Email Send Email
 
Hi Guys,
Can any one share info about IPX support in Sidewinder 4150 G2
Appliance, is it available or not?
thanks in advance.

#216 From: "Fiamingo, Frank" <fiamingf@...>
Date: Tue Dec 4, 2007 7:49 pm
Subject: RE: Citrix Proxy Status
fgfiamingo
Offline Offline
Send Email Send Email
 
I forgot to mention - we're currently running version 6.1.2.03.
 
    Frank


From: sidewinder-users@yahoogroups.com [mailto:sidewinder-users@yahoogroups.com] On Behalf Of Fiamingo, Frank
Sent: Tuesday, December 04, 2007 11:48 AM
To: sidewinder-users@yahoogroups.com
Subject: [sidewinder-users] Citrix Proxy Status

Sometime ago after an upgrade to Sidewinder G2 the Citrix proxy no longer worked properly, and we had to improvise with a with a generic TCP proxy and UDP filter to allow the traffic to pass properly. 

Has the Citrix proxy been fixed?  Does it now work properly for both the TCP and UDP connections?

        Thanks,
        Frank


#215 From: "Fiamingo, Frank" <fiamingf@...>
Date: Tue Dec 4, 2007 4:47 pm
Subject: Citrix Proxy Status
fgfiamingo
Offline Offline
Send Email Send Email
 

Sometime ago after an upgrade to Sidewinder G2 the Citrix proxy no longer worked properly, and we had to improvise with a with a generic TCP proxy and UDP filter to allow the traffic to pass properly. 

Has the Citrix proxy been fixed?  Does it now work properly for both the TCP and UDP connections?

        Thanks,
        Frank


#214 From: "Mike" <ramses_the_1st@...>
Date: Wed Nov 7, 2007 9:25 pm
Subject: Re: Using cron for config backup - found it
ramses_the_1st
Offline Offline
Send Email Send Email
 
I missed the part in the crontab man page the you need to escape the
% with a \ so now it works.

Mike


-- In sidewinder-users@yahoogroups.com, "Mike" <ramses_the_1st@...>
wrote:
>
> I am trying to get a cron job going to do a config backup of my EM
> server and I am running into a strange issue. Here is the beginning
of
> the command:
>
> /usr/sbin/cf config backup loc=remote filename=fwbackup`date +%y%m%
d`
> directory=/data/fwbackup/
>
> The job will run just fine from the command line, but when run from
> cron it blows up using the date function. The cron log looks like
this:
>
> /usr/sbin/cf config backup loc=remote filename=fwbackup`date +)
>
> Is there a know issue with using the date function in cron? It just
> seems odd that it will work from the cli but not in cron.
>
> Mike
>

#213 From: "Mike" <ramses_the_1st@...>
Date: Wed Nov 7, 2007 9:13 pm
Subject: Using cron for config backup
ramses_the_1st
Offline Offline
Send Email Send Email
 
I am trying to get a cron job going to do a config backup of my EM
server and I am running into a strange issue. Here is the beginning of
the command:

/usr/sbin/cf config backup loc=remote filename=fwbackup`date +%y%m%d`
directory=/data/fwbackup/

The job will run just fine from the command line, but when run from
cron it blows up using the date function. The cron log looks like this:

/usr/sbin/cf config backup loc=remote filename=fwbackup`date +)

Is there a know issue with using the date function in cron? It just
seems odd that it will work from the cli but not in cron.

Mike

#212 From: Scott Montgomery <scottyva@...>
Date: Tue Oct 30, 2007 5:57 pm
Subject: Re: Packet-level capture
ScottyVA
Offline Offline
Send Email Send Email
 
There is some discussion afoot about adding this capability to UI utilizing freeware such as Ethereal.

S

fosgood <fosgood_007@...> wrote:
tcpdump -npi [ifname, exp0 for example] -X -s220

You can throw other parameters in such as:

host 100.2.3.4 and port 80

There are some other commands that you can use to
filter it down to a specific stream as well if that
isn't good enough.

If I am looking for something specific, I will
redirect it to a file with:

> /home/dump.txt

for example and then grep for whatever I am looking
for.

- F

--- Eric Pancer <epancer@gmail.com> wrote:

> On 10/26/07, Matthew <matthew.harvey@usdoj.gov>
> wrote:
>
> > Does anyone know how to perform a packet-level
> capture on an interface
> > on a G2? To create a PCAP or similar file, that
> is.
>
> This is pretty easy. You can use tcpdump to monitor
> interfaces.
>
> Just `man tcpdump`.
>

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com


#211 From: fosgood <fosgood_007@...>
Date: Tue Oct 30, 2007 9:52 am
Subject: Re: Packet-level capture
fosgood_007
Online Now Online Now
Send Email Send Email
 
tcpdump -npi [ifname, exp0 for example] -X -s220

You can throw other parameters in such as:

host 100.2.3.4 and port 80

There are some other commands that you can use to
filter it down to a specific stream as well if that
isn't good enough.

If I am looking for something specific, I will
redirect it to a file with:

  > /home/dump.txt

for example and then grep for whatever I am looking
for.

   - F



--- Eric Pancer <epancer@...> wrote:

> On 10/26/07, Matthew <matthew.harvey@...>
> wrote:
>
> > Does anyone know how to perform a packet-level
> capture on an interface
> >  on a G2? To create a PCAP or similar file, that
> is.
>
> This is pretty easy. You can use tcpdump to monitor
> interfaces.
>
> Just `man tcpdump`.
>


__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

#210 From: "cjsather" <cjsather@...>
Date: Mon Oct 29, 2007 8:00 pm
Subject: Re: Packet-level capture
cjsather
Offline Offline
Send Email Send Email
 
As mentioned before, use tcpdump.  If you would like to write the
capture to a file, for viewing at a later time with tcpdump or
wireshark, simply use the -w flag.

#209 From: "Eric Pancer" <epancer@...>
Date: Fri Oct 26, 2007 5:57 pm
Subject: Re: Packet-level capture
vxla
Offline Offline
Send Email Send Email
 
On 10/26/07, Matthew <matthew.harvey@...> wrote:

> Does anyone know how to perform a packet-level capture on an interface
>  on a G2? To create a PCAP or similar file, that is.

This is pretty easy. You can use tcpdump to monitor interfaces.

Just `man tcpdump`.

#208 From: "Matthew" <matthew.harvey@...>
Date: Fri Oct 26, 2007 2:40 pm
Subject: Packet-level capture
matman1115
Offline Offline
Send Email Send Email
 
Does anyone know how to perform a packet-level capture on an interface
on a G2? To create a PCAP or similar file, that is.

#207 From: fosgood <fosgood_007@...>
Date: Thu Oct 25, 2007 8:22 am
Subject: Re: What is the Future?
fosgood_007
Online Now Online Now
Send Email Send Email
 
You can have up to 14 interfaces on the mid models and
go up to 26 on the big boxes.


Since the Sidewinder O.S. [secure o.s.] is extremely
locked down, all hardware drivers have to be added to
the O.S.  It's not like you can just add your own
drivers.

What this meant is that many, many, time someone would
buy a server that had components that were not on the
HCL.

What this meant was down time for the firewall and
also hours and hours of support calls to try and
troubleshoot problems for hours to track down a bad
nic card, etc.

With the appliance, all of that down time goes away
because you know it will just work.  I did an install
once and the server came with 3com 905-c's which were
not supported.  The model that did work was the 905-b,
which didn't have netbios blasts built into the nic.

Had to burn two days waiting for the right part to
show up.


--- Daniel Sichel <daniels@...> wrote:

> I have not yet seen version 7, but it sounds pretty
> good. I hear the GUI
> is or soon will be Java based which makes me
> hesitant,  Java always
> seems slow and kludgy with lots of annoying bugs in
> user interfaces.  I
> complained bitterly for years over the  PHP issues,
> and now in 6.1x they
> have it really well executed IMHO.   I do have one
> question, what is the
> maximum number of interfaces in one of their
> appliances? I have eight
> interfaces on my appliance, all in use, and it
> looks like I will soon
> be needing a ninth.  If they supported more
> interfaces that would be a
> compelling reason to upgrade.
>
>
>
> Thanks for all the comments about this.  I am not
> really sure how I feel
> about the end of life issue. On the one hand I
> understand Secure needs
> to generate revenue and control costs which dictates
> older issue
> equipment going end of  life, but on the other hand,
> this type of
> upgrade is expensive and disruptive, and  I wonder
> about what is owed
> the end user who drops tens of thousands of dollars
> into a firewall then
> pays support too. As I often have said, it's one
> thing when I pay $79
> bucks for an off the shelf device at Best Buy and
> call support, but
> totally another when I pay these prices.  This is
> why I WON"T USE
> SYMANTEC PRODUCTS.  I guess I feel like Secure
> support is generally
> very, very good but their product policies leave
> something to be
> desired. It's like Winston Churchill's description
> of democracy,
> "...It's the worst form of government in the world
> -except all the
> others."
>
>
>
> Daniel Sichel, CCNP, MCSE
>
> Network Engineer
>
> Ponderosa Telephone (559) 868-6367
>
>


__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

#206 From: "Justin Beeler (JBEELER.COM)" <justin@...>
Date: Tue Oct 23, 2007 6:30 pm
Subject: Re: What is the Future?
ljs442
Offline Offline
Send Email Send Email
 
One very nice think about them using a Java based GUI is that those of us that detest Windows can go back to administrating our "*NIX firewall" with a *NIX box!  That has been a huge thorn in our side since we switched from Gauntlet to Sidewinder G2.  Kudos on SCC for doing this!

Justin

Daniel Sichel wrote:

I have not yet seen version 7, but it sounds pretty good. I hear the GUI is or soon will be Java based which makes me hesitant,  Java always seems slow and kludgy with lots of annoying bugs in user interfaces.  I complained bitterly for years over the  PHP issues, and now in 6.1x they have it really well executed IMHO.   I do have one question, what is the maximum number of interfaces in one of their appliances? I have eight interfaces on my appliance, all in use, and it  looks like I will soon be needing a ninth.  If they supported more interfaces that would be a compelling reason to upgrade.

 

Thanks for all the comments about this.  I am not really sure how I feel about the end of life issue. On the one hand I understand Secure needs to generate revenue and control costs which dictates older issue equipment going end of  life, but on the other hand, this type of upgrade is expensive and disruptive, and  I wonder about what is owed the end user who drops tens of thousands of dollars into a firewall then pays support too. As I often have said, it’s one thing when I pay $79 bucks for an off the shelf device at Best Buy and call support, but totally another when I pay these prices.  This is why I WON”T USE SYMANTEC PRODUCTS.  I guess I feel like Secure support is generally very, very good but their product policies leave something to be desired. It’s like Winston Churchill’s description of democracy, “…It’s the worst form of government in the world –except all the others.”

 

Daniel Sichel, CCNP, MCSE

Network Engineer

Ponderosa Telephone (559) 868-6367


#205 From: "Daniel Sichel" <daniels@...>
Date: Tue Oct 23, 2007 6:01 pm
Subject: What is the Future?
flitcraft66
Offline Offline
Send Email Send Email
 

I have not yet seen version 7, but it sounds pretty good. I hear the GUI is or soon will be Java based which makes me hesitant,  Java always seems slow and kludgy with lots of annoying bugs in user interfaces.  I complained bitterly for years over the  PHP issues, and now in 6.1x they have it really well executed IMHO.   I do have one question, what is the maximum number of interfaces in one of their appliances? I have eight interfaces on my appliance, all in use, and it  looks like I will soon be needing a ninth.  If they supported more interfaces that would be a compelling reason to upgrade.

 

Thanks for all the comments about this.  I am not really sure how I feel about the end of life issue. On the one hand I understand Secure needs to generate revenue and control costs which dictates older issue equipment going end of  life, but on the other hand, this type of upgrade is expensive and disruptive, and  I wonder about what is owed the end user who drops tens of thousands of dollars into a firewall then pays support too. As I often have said, it’s one thing when I pay $79 bucks for an off the shelf device at Best Buy and call support, but totally another when I pay these prices.  This is why I WON”T USE SYMANTEC PRODUCTS.  I guess I feel like Secure support is generally very, very good but their product policies leave something to be desired. It’s like Winston Churchill’s description of democracy, “…It’s the worst form of government in the world –except all the others.”

 

Daniel Sichel, CCNP, MCSE

Network Engineer

Ponderosa Telephone (559) 868-6367


#204 From: "fosgood_007" <fosgood_007@...>
Date: Mon Oct 22, 2007 6:40 pm
Subject: Re: What is the future
fosgood_007
Online Now Online Now
Send Email Send Email
 
Dan,

Have you seen Sidewinder v. 7?  That is what's running on the new
appliances.  The single panel rule screen is awesome and your proxies
and ip filters are all in a single rule set.  Also, you do not have
to run and turn a proxy on before making the acl.  Simply creating
the rule opens the proxy/server that you trying to control.

  - F







--- In sidewinder-users@yahoogroups.com, "Justin Beeler
(JBEELER.COM)" <justin@...> wrote:
>
> Dan,
>
> Stick with 6.1.2x and your current server(s).  If what you have
works
> for you then stick with it!  Since a Sidewinder has "never been
> breached" then you have nothing to worry about.  Of course you
won't be
> able to get upgrades or anything, but you'll still be very well
> protected.  The 6.1.2.x platform is very stable, very reliable, and
very
> secure.  The old saying "if it ain't broke, don't fix it" comes to
> mind.  I'm sure SCC will dislike my response, but it is what it is
my
> friend.  I know of several Sidewinder 5.x boxes and even Gauntlet
5.x
> and 6.0 boxes still alive, well, and doing a very good job at
security.
>
> Justin Beeler
>
> Scott Montgomery wrote:
> > Hi, Dan:
> >
> > Unfortunately there are only two real options here today.  One is
to
> > run without support, but I can't really advise it.  The kb, phone
> > support, upgrade discounts, access to patches and updated
versions,
> > etc is tied to a current support agreement.  The other is a
migration
> > to a newer appliance.  The cost is far less than list price on
the
> > appropriately sized appliance (we basically give you some
hardware
> > credit for your existing device).
> >
> > We are exploring the viability of a VMWare-enabled appliance
version
> > (basically a 'software appliance' on a CD), but it's more a
research
> > project right now than anything else.  There's no commitment to a
> > delivery yet, and I have no idea what
pricing/SKU/warranty/details
> > might be like.  It's basically just something we're noodling on.
> >
> > If you're happy with the Sidewinders I'd talk to sales about the
> > migration/upgrade costs - it's the best way to stay plugged into
new
> > versions and features as well as support.
> >
> > Scott
> > scott_montgomery@...
> > <mailto:scott_montgomery@...>
> >
> >
> >
> >
> >
> > */flitcraft66 <daniels@...>/* wrote:
> >
> >     I have a pair of Sidwewinder 250 appliances (really they are
Dell
> >     servers with a Secure Computing ROM) that aren't supported
for 7.0.
> >     So, I am wondering what the future is. These appliances are
more than
> >     adequate for our needs for the indefinite future and I would
hate to
> >     have to retire them in 2009. So, I am wondering if somebody
from
> >     product development or marketing could let us know what to
expect.
> >
> >     Thanks
> >
> >     Dan Sichel
> >
> >
> > ------------------------------------------------------------------
------
> > Shape Yahoo! in your own image. Join our Network Research Panel
today!
> >
<http://us.rd.yahoo.com/evt=48517/*http://surveylink.yahoo.com/gmrs/ya
hoo_panel_invite.asp?a=7>
> >
> >
>
> --
> --------------------------------------------------------------------
--
> Justin Beeler (JBEELER.COM)
> Website URL: http://www.jbeeler.com
>
> - UNIX IS user friendly.....it's just picky about who it
> chooses to be friends with.
>
> "The day Microsoft makes something that doesn't suck is probably
> the day they start making vacuum cleaners." -Ernst Jan Plugge.
>
> --------------------------------------------------------------------
--
>

#203 From: "Justin Beeler (JBEELER.COM)" <justin@...>
Date: Fri Oct 19, 2007 12:17 am
Subject: Re: What is the future
ljs442
Offline Offline
Send Email Send Email
 
Dan,

Stick with 6.1.2x and your current server(s).  If what you have works for you then stick with it!  Since a Sidewinder has "never been breached" then you have nothing to worry about.  Of course you won't be able to get upgrades or anything, but you'll still be very well protected.  The 6.1.2.x platform is very stable, very reliable, and very secure.  The old saying "if it ain't broke, don't fix it" comes to mind.  I'm sure SCC will dislike my response, but it is what it is my friend.  I know of several Sidewinder 5.x boxes and even Gauntlet 5.x and 6.0 boxes still alive, well, and doing a very good job at security.

Justin Beeler

Scott Montgomery wrote:
Hi, Dan:
 
Unfortunately there are only two real options here today.  One is to run without support, but I can't really advise it.  The kb, phone support, upgrade discounts, access to patches and updated versions, etc is tied to a current support agreement.  The other is a migration to a newer appliance.  The cost is far less than list price on the appropriately sized appliance (we basically give you some hardware credit for your existing device).
 
We are exploring the viability of a VMWare-enabled appliance version (basically a 'software appliance' on a CD), but it's more a research project right now than anything else.  There's no commitment to a delivery yet, and I have no idea what pricing/SKU/warranty/details might be like.  It's basically just something we're noodling on.
 
If you're happy with the Sidewinders I'd talk to sales about the migration/upgrade costs - it's the best way to stay plugged into new versions and features as well as support.
 
Scott
 
 
 


flitcraft66 <daniels@ponderosatel.com> wrote:
I have a pair of Sidwewinder 250 appliances (really they are Dell
servers with a Secure Computing ROM) that aren't supported for 7.0.
So, I am wondering what the future is. These appliances are more than
adequate for our needs for the indefinite future and I would hate to
have to retire them in 2009. So, I am wondering if somebody from
product development or marketing could let us know what to expect.

Thanks

Dan Sichel



Shape Yahoo! in your own image. Join our Network Research Panel today!

-- ----------------------------------------------------------------------
Justin Beeler (JBEELER.COM)
Website URL: http://www.jbeeler.com
- UNIX IS user friendly.....it's just picky about who it chooses to be friends with.
"The day Microsoft makes something that doesn't suck is probably the day they start making vacuum cleaners." -Ernst Jan Plugge.
----------------------------------------------------------------------

#202 From: Scott Montgomery <scottyva@...>
Date: Thu Oct 18, 2007 8:09 pm
Subject: Re: What is the future
ScottyVA
Offline Offline
Send Email Send Email
 
Hi, Dan:
 
Unfortunately there are only two real options here today.  One is to run without support, but I can't really advise it.  The kb, phone support, upgrade discounts, access to patches and updated versions, etc is tied to a current support agreement.  The other is a migration to a newer appliance.  The cost is far less than list price on the appropriately sized appliance (we basically give you some hardware credit for your existing device).
 
We are exploring the viability of a VMWare-enabled appliance version (basically a 'software appliance' on a CD), but it's more a research project right now than anything else.  There's no commitment to a delivery yet, and I have no idea what pricing/SKU/warranty/details might be like.  It's basically just something we're noodling on.
 
If you're happy with the Sidewinders I'd talk to sales about the migration/upgrade costs - it's the best way to stay plugged into new versions and features as well as support.
 
Scott
 
 
 


flitcraft66 <daniels@...> wrote:
I have a pair of Sidwewinder 250 appliances (really they are Dell
servers with a Secure Computing ROM) that aren't supported for 7.0.
So, I am wondering what the future is. These appliances are more than
adequate for our needs for the indefinite future and I would hate to
have to retire them in 2009. So, I am wondering if somebody from
product development or marketing could let us know what to expect.

Thanks

Dan Sichel



Shape Yahoo! in your own image. Join our Network Research Panel today!

Messages 202 - 231 of 231   Newest  |  < Newer  |  Older >  |  Oldest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help