Firewall-1

Re: [FW-1] How to kill a vpn tunnel

Subject: Re: [FW-1] How to kill a vpn tunnel
From: Mitchell Jerry - Nashville <Jerry.Mitchell2 AT HCAHEALTHCARE DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Mon, 27 Dec 2004 09:58:09 -0600
If I remember correctly, I believe you can use

vpn drv off
Or
vpn drv on

This kills or starts the entire vpn module. This will take down ALL vpns
though.
 _____________________________________________

Yes. Imbed the following commands in your script at some point; you will
need the IP of the originating tunnel. I'm not a script kiddie, but I'll
give you the basic outline.

send it the FW command line command: vpn tu at this point a text GUI usually
comes up, send it to null and sleep for a few seconds) send it the keystroke
"6", send the text to null, and sleep for a second or two send it the IP
address of the origination tunnel sleep for 15-30 seconds send the script an
<enter> finally, exit out by sending an "a"

My suggestion is to possibly send all the output to a log file instead of
null, but null would be the fastest way. sed/awk would work, as would a
regular shell script, probably.

Good luck.

Regards,
Matt Goddard
Security Information Team
Schneider National, Inc.
"To find out what one is fitted to do and to secure an opportunity to do so
is the key to happiness."
__________________________________________________________________________


Hi everybody,

Is it possible to kill a vpn tunnel with a script in order to kill it
everyday for example.

Tanks

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>