Firewall-1

Re: [FW-1] Nokia and Checkpoint TAC supports are the worst in the busine

Subject: Re: [FW-1] Nokia and Checkpoint TAC supports are the worst in the business?
From: Hal Dorsman <hdorsman AT RMEF DOT ORG>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Fri, 22 Apr 2005 09:02:03 -0600
I concur.  I've been using Checkpoint (no experience with Nokia)
ever since 3.0 came out on AIX.  Early on their support was pretty
good, but after a few years support calls became more frustation
than fruitful. I discontinued support a few years ago because it
just wasn't worth the cost.  I have two stable firewalls so I don't
mess with them.  I get far more useful information from this list
than I ever did from CP. (thanks everyone)

However, giving credit where credit is due, the product is one of
the best on the market, is extremely stable at some of the earlier
releases (recall the approaches to upgrades thread?), and with
adequate training and experience in most cases you really don't
need the support.

Oh, but BTW, <looking around> you do know Checkpoint monitors this
list right?  <slowly backng away, looking for helicopters>



Hal

> -----Original Message-----
> From: cisco4ng [mailto:cisco4ng AT YAHOO DOT COM]
> Sent: Friday, April 22, 2005 6:06 AM
> To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
> Subject: [FW-1] Nokia and Checkpoint TAC supports are the
> worst in the business?
>
>
> Hi All,
>
> Is it just me or everyone shares the same feeling I have
> that both Checkpoint and Nokia TAC are absolutely horrible.
> Everytime I open a TAC case with Nokia, here are the typical
> response that I get from Nokia TAC engineer:
>
> 1) Please provide an output of the ipsoinfo.  When I told the
> TAC engineer that the firewall has very high cpu usage,
> running ipsoinfo will crash the firewall, he assured me that
> it will not and kept insisting that I ran ipsoinfo.  Guess
> what, it crashed the production firewall.
>
> 2) There is a bug in the currently release of ipso that
> you're running, please upgrade to the latest version.  We,
> Nokia, don't know if it will fix the problem but you can try.
>  Do I really need to call Nokia for this crap?
>
> 3) The currently checkpoint release you are using is not
> up-to-date.  Please upgrade.  Not sure if it will fix the problem.
>
> 4) The Nokia resolution is NOT correct.
>
> 5) We need cpinfo output from the management server but we
> don't know how to do this so you're on your own.
>
> Here are a typical response from Checkpoint TAC:
>
> 1) Please do some very dangerous on your Provider-1
> production environment.  We're not sure if it will fix the problem.
>
> We've NOT tested it yet but we think it will fix the problem.
> 2) You can have a open checkpoint TAC case and the engineer
> will work on it whenever he/she feels like it.
>
> 3) Checkpoint TAC engineers are absolutely horrible (with the
> exception of Rajeev Gupta.  It is unfortunate that Rajeev no
> longer works there.  Rajeev was the superstar of Checkpoint TAC).
>
> As someone who has worked with Checkpoint Firewalls for
> almost 5 years and Cisco IOS, Pix, and VPN concentrator for
> the past 7 years, I can tell you that Cisco Pix firewall is
> not as good as Checkpoint but Cisco TAC engineer is the best
> in the business.  Cisco will throw all resources available so
> that they can solve the problem and make customer happy.
>
> I helped someone in this group to setup a site-to-site vpn
> between cisco Pix and Checkpoint and that person told me
> Checkpoint TAC will charge his company $500US for every hour
> of tech support with NO GUARANTEE that they can get it to
> work.  A pretty hooker still costs much less than $500.
>
> I, myself, have two open tickets with Checkpoint for almost 3
> months and they are still pending with no resolution.
>
> Am I the only one in this group who feel this way or am I
> being too hard on both Nokia and Checkpoint TAC engineers?
>
> Please share your comments.
>
> cisco4ng

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>