Firewall-1

[FW-1] SV: [FW-1] SCV policy

Subject: [FW-1] SV: [FW-1] SCV policy
From: Torkel Mathisen <torkel.mathisen AT BBS DOT NO>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Wed, 22 Nov 2006 12:15:12 +0100
> Hi,
> there are much more parameters to configure, but not with
> SmartDashboard. As you write, you can modify userc.C, so e.g. users
> cannot stop SecureClient.
> Additionally, at the SmartCenter you have the file
$FWDIR/conf/local.scv
> which deals with SCV. As an example: If the parameter
> "disconnect_when_not_verified" is set to "true", it will not only be
> checked if the client is compliant when starting the session. Maybe
the
> SCV Editor
>
(http://www.checkpoint.com/downloads/quicklinks/utilities/downloadsng/ut
il
> ities/sc_scv_tools.html)
> helps modifying local.scv.
> Hope it helps,
> best regards,
> Matthias

I tried to modify local.scv also. I modified:

        :SCVGlobalParams (
                :disconnect_when_not_verified (true)
                :block_connections_on_unverified (true)
        )

Modifised from false to true.

It looks right to me, but he still didn't get blocked.

Anything else?


Regards,
Torkel

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>