Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Firewalls
[Top] [All Lists]

Problems Interfaces Bge in Solaris 9 with CheckPoint R55 HF13

Subject: Problems Interfaces Bge in Solaris 9 with CheckPoint R55 HF13
Date: Fri, 18 Mar 2005 19:44:54 -0500
Hi all ,

I am installing  R55+HF13  in Solaris 9 Kernel : 118558-04 over two Sun
V210 for ClusterXL "New Mode" with bge interfaces, so I added the line "bge
accept" based in the SecureKnowledge  # a-Sk 21114 and b -Phoneboy in the
file : /etc/fw.boot/ifdev

a-https://secureknowledge.checkpoint.com/sk/public/idsearch.jsp?id=sk21114&QueryText=%28%28%3Cthesaurus%3E+bge%2C+%3Cthesaurus%3E+inter%29%29&resultStart=1
b-http://www.phoneboy.com/bin/view.pl/FAQs/BgeInterfaces , now I can enter
to my operating system , but when it boots shows :

"FW-1*: get (SIOCGLIFFLAGS c0786975) inconsistency for bge1 (843, 803)
FW-1*: get (SIOCGLIFFLAGS c0786975) inconsistency for bge2 (843, 803)
FW-1*: get (SIOCGLIFFLAGS c0786975) inconsistency for bge3 (843, 803)"

I am very worried , because I dont Know what will be the problems in the
future , The  two Sun V210 will be install in New Mode Cluster of Cluster
XL, each Sun V210 has one interface of four ports 10/100/100 bge0-3????

###################################### COMPLETED  BOOT
#########################################
##################################################################################################

Sun Fire V210, No Keyboard Copyright 1998-2003 Sun Microsystems, Inc.  All
rights reserved.
OpenBoot 4.13.2, 1024 MB memory installed, Serial #61386879. Ethernet
address 0:3:ba:a8:b0:7f, Host ID: 83a8b07f.

Rebooting with command: boot  Boot device: disk0  File and args: SunOS
Release 5.9 Version Generic_118558-04 64-bit
Copyright 1983-2003 Sun Microsystems, Inc.  All rights reserved. Use is
subject to license terms.
Hardware watchdog enabled
FireWall-1 boot security configuration:
FW-1: Disabling IP forwarding
FW-1: Loading default filter
FW-1: driver installed
FW-1: Default filter installed successfully
FW-1: Loading I/F device list: le qfe hme bge ge eri dmfe ce bge sppp
FW-1: Starting bootd: fwbootd: child pid=17
FW-1: Autopushing under UDP
FW-1: Autopushing over network interface drivers
FW-1: Autopushing over le
FW-1: Autopushing over qfe
FW-1: Autopushing over hme
FW-1: Autopushing over bge
FW-1: Autopushing over ge
FW-1: Autopushing over eri
FW-1: Autopushing over dmfe
FW-1: Autopushing over ce
ap: ioctl failed: Out of stream resources
FW-1: ce autopush failed: resetting ...
Usage:
        ap -a drv minor last-minor mod [mod ...]

        add:    last-minor = 0 means one and not range    minor = -1 means
all


        ap -r drv minor

        remove: minor should be in range (0 for all)


        ap -g drv minor [ place    mod [mod ...]]

        get:    minor should be in range (0 for all)
                prints arguments for add command
                place specifies where to insert mod


        See also autopush(1M)


        Other options:

        ap -e drv mod
        query:  check if mod is already autopushed over drv

ap -g: ioctl failed (0): No such device
/etc/rcS.d/S25fw1boot: /usr/sbin/autopush: not found
CPHA : Getting into preconfigured mode...
FW-1: initialized on bge0 (1)
FW-1: loading filter on bge0 (db2ce0)
FW-1: initialized on bge1 (2)
FW-1: loading filter on bge1 (db22a0)
FW-1: initialized on bge2 (3)
FW-1: loading filter on bge2 (1cbaa58)
FW-1: initialized on bge3 (4)
FW-1: loading filter on bge3 (1cb7210)
configuring IPv4 interfaces: bge0 bge1 bge2 bge3.
FW-1*: get (SIOCGLIFFLAGS c0786975) inconsistency for bge0 (843, 803)
Hostname: fwusers02
Configuring /dev and /devices
VPN-1: driver installed
The system is coming up.  Please wait.
FireWall-1 boot security configuration phase two:
FW-1: Restarting bootd: fwbootd: child pid=166
FW-1: Autopushing over remaining network interface drivers
FW-1: Autopushing over ce
ap: ioctl failed: Out of stream resources
FW-1: ce autopush failed: resetting ...
Usage:
        ap -a drv minor last-minor mod [mod ...]

        add:    last-minor = 0 means one and not range
                minor = -1 means all


        ap -r drv minor

        remove: minor should be in range (0 for all)


        ap -g drv minor [ place    mod [mod ...]]

        get:    minor should be in range (0 for all)
                prints arguments for add command
                place specifies where to insert mod


        See also autopush(1M)


        Other options:

        ap -e drv mod
        query:  check if mod is already autopushed over drv

ap -g: ioctl failed (0): No such device
checking ufs filesystems
/dev/rdsk/c1t0d0s3: is logging.
/dev/rdsk/c1t0d0s6: is logging.
/dev/rdsk/c1t0d0s4: is logging.
FW-1*: get (SIOCGLIFFLAGS c0786975) inconsistency for bge1 (843, 803)
FW-1*: get (SIOCGLIFFLAGS c0786975) inconsistency for bge2 (843, 803)
FW-1*: get (SIOCGLIFFLAGS c0786975) inconsistency for bge3 (843, 803)
Machine is an IPv4 router.
Setting netmask of bge0 to 255.255.0.0
Setting netmask of bge1 to 255.255.255.128
Setting netmask of bge2 to 255.255.255.0
Setting netmask of bge3 to 255.255.255.252
Setting default IPv4 interface for multicast: add net 224.0/4: gateway
fwusers02
cprid started...
cpstart: Power-Up self tests passed successfully

cpstart: Starting product - SVN Foundation

SVN Foundation: Starting cpWatchDog
SVN Foundation: Starting cpd
SVN Foundation started

cpstart: Starting product - VPN-1

FW-1: Warning: No valid license
FireWall-1: starting external VPN module -- VPN-1: Cryptographic algorithm
tests
 passed successfully
VPN-1: connected to FW-1
OK
Note: This machine is not defined as a part of any Cluster.   It is
possible that the IP of this machine as it appears in your hosts file
differs from the general IP of this machine in the Management server.
Alternatively, Check your Cluster configuration in the Management server.
If this machine is no longer part of Cluster, please disable Check Point
ClusterXL   or State Synchronization on it. FireWall-1: Starting fwd

Installing Security Policy InitialPolicy on all.all@fwusers02
FW-1: Warning: The bge0 interface is not protected by the anti-spoofing
feature.  Your network may be at risk. In the future, it is recommended
that you
      define anti-spoofing protection before installing the Security
Policy.

FW-1: Warning: The bge1 interface is not protected by the anti-spoofing
feature.  Your network may be at risk. In the future, it is recommended
that you
      define anti-spoofing protection before installing the Security
Policy.

FW-1: Warning: The bge2 interface is not protected by the anti-spoofing
feature. Your network may be at risk. In the future, it is recommended that
you
      define anti-spoofing protection before installing the Security
Policy.

FW-1: Warning: The bge3 interface is not protected by the anti-spoofing
feature.  Your network may be at risk. In the future, it is recommended
that you
      define anti-spoofing protection before installing the Security
Policy.

VPN-1: ERROR: No license for encryption, disabling encryption features
Fetching Security Policy from localhost succeeded
FireWall-1 started
The system is ready.

fwusers02 console login: root
Password:
Last login: Fri Mar 18 15:26:11 on console
Sun Microsystems Inc.   SunOS 5.9       Generic May 2002
#



--------------------------------------------------------------------------
FREE Download - The Future in Desktop Firewalls is Available Now
 
NEW NetOp Desktop Firewall, the world's first driver-centric 
firewall software - protecting your laptops and corporate PCs at  
ring-zero! NetOp features sophisticated process & application
control, centralized management and multiple network user profiles -
NetOp is able to increase security when mobile users plug back 
into your network. Step into a more secure future - Try it FREE
http://www.securityfocus.com/sponsor/CrossTec_firewalls_050315
--------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>
  • Problems Interfaces Bge in Solaris 9 with CheckPoint R55 HF13, Cesar Farro Flores <=