Wednesday, April 1, 2026

Check Point Software Announces “Historic” Merger with Palo Alto Networks in Bold April 1 Move

 

April 1, 2026 — Tel Aviv, Israel / Santa Clara, CA



In a move that analysts are calling “either visionary or very well-timed,” Check Point Software Technologies and Palo Alto Networks today announced a definitive agreement to merge, forming what they describe as the industry’s first Open Garden cybersecurity ecosystem powered by Hybrid Mesh AI security.

The newly combined company will operate under the name “Check Point Alto Networks (CPAN™)”—a brand executives say “tested extremely well in at least one internal Slack poll.”


🌐 From Walled Gardens to Open Garden

Breaking away from the traditional “walled garden” approach, the new entity is introducing a bold philosophy: Open Garden Security.

“Why lock customers in when you can gently surround them with interoperability?” said a joint spokesperson. “Open Garden means everything works together—especially our products.”

The Open Garden approach promises:

  • Seamless integrations with select third-party vendors (pending partnership agreements, certifications, and vibes)
  • Unified policy management across platforms, clouds, and marketing decks
  • The freedom to choose… within a carefully curated ecosystem

🕸️ Hybrid Mesh Architecture Meets AI Security

At the core of the merger is a new architecture combining Check Point’s Hybrid Mesh Security with Palo Alto’s AI-driven platforms.

The result:
Hybrid Mesh AI Security Fabric™

This next-gen framework will:

  • Dynamically route protections across networks, endpoints, cloud, and wherever your data is hiding
  • Use AI to predict threats, prevent threats, and occasionally rename features
  • Automatically adapt security policies based on risk, context, and quarterly earnings calls

When asked how it works, engineers confirmed:

“It’s both distributed and centralized. That’s the beauty of mesh.”


🤖 AI, But More of It

Both companies emphasized that AI will play a central role in the new platform—appearing no fewer than 27 times in the official announcement.

Key capabilities include:

  • Predictive Threat Prevention AI™ (stops attacks before they’re invented)
  • Autonomous SOC Co-Pilot Max Ultra™ (responds to incidents and writes your reports)
  • Generative Security Narratives™ (explains breaches in a reassuring tone)

🧑‍💼 Leadership & Culture

To reflect the merger of equals, the company will adopt a “Collaborative Leadership Mesh”, where decisions are made through a combination of:

  • AI recommendations
  • Executive alignment
  • Whoever speaks first on the call

A new internal initiative, “One Culture, Many Logos,” aims to unify employees under a shared mission and a slightly larger email signature.


💬 Customer Experience

Customers can expect:

  • A single, unified platform with one login (and a backup login, just in case)
  • Consolidated licensing into a Flexible Infinity Prisma Cortex Harmony Bundle™
  • Fewer vendors… but more acronyms

Early feedback has been enthusiastic:

“I don’t fully understand it, but it sounds secure.” — Enterprise CIO
“Do I still call my old account manager?” — Everyone


🔮 What’s Next

The companies expect the merger to close pending regulatory approval and agreement on whose naming conventions are longer.

Until then, both organizations will continue operating independently—while jointly hosting webinars titled:
“Hybrid Mesh AI Security in an Open Garden World: What It Means for You (Part 7 of 12)”


Disclaimer:
This announcement was released on April 1st.
Please apply zero trust accordingly.

Thursday, April 1, 2021

Check Point Research Leak - Universe Is A Simulation

 

According to unpublished documents, Check Point Research a.k.a CP<R> division stumbled upon unequivocal proof that we are living in a digital simulation

One of researches, Uval Kerby, has decided to blow the whistle on an accidental discovery of that fact. He reached out to me the last week, and I have no other option but to publish what he told me. To make it simple, I am just posting the transcript of my phone call with Uval. Here we go (and you do want to sit down before continuing):

Author: Uval, hi. How are you doing?

Uval: Thanks, I am doing fine. I have only about 10 minutes, so let's just go to the main subject.

Author: Sure, although, I have to admit, I have a hard time with the whole idea. Your email said, you have proof the world is a simulation, right? So what, are we all living in Matrix, like in the movie?

Uval: No, no like in the movie. Matrix means there is a physical world outside of the simulation, and one can exit from the artificial construct into reality. That is not our case. We are all trapped in the simulation, and the boundaries are impenetrable for us. 

Author: Right... In your email, you have mentioned the work of Nick Bostrom, where he basically debunks the simulation theory, saying even if it is true, we do not have any practical means to prove it. Then, how come?

Uval: Bostrom is good, and the work you are quoting is quite compelling. Before him, by the way, the same idea was contemplated by Mayans, Antique Greeks and even Rene Descartes. To prove you are in the simulation, you have to step out of that simulation. Like any character in your favourite computer game, you cannot do that, ever. But there is a catch. Bostrom, and any other philosophers are/were not coders. 

Author: How does that make a difference? I do not understand.

Uval: Yes, it is only simple when you already know the answer and look at whole idea in retrospect. Let me put it in this way. Even if you cannot step out of the simulation, you still can hack it. Or could, as in our case. We hacked the universe.

Author: Hacked?! What does even mean?

Uval: Well, maybe not exactly hacked, but we managed to turn on some kind of "debug mode" in it, more than once.

Author: Can you elaborate?

Uval: I can try. In short, there are quite a few tell-tale signs all around us. My own revelation happened when I learned about Chronon, the quantum of time. The idea is about one century old. Robert Lévi came up with that theory in 1927, and since then it gained weight. Piero Caldirola is the author of compelling theory. For scholars, that is a way to simplify description of the observed results in quantum decoherence. For a coder it is something completely different. Why would time be discrete? It only makes sense if you are using a program which is calculating certain iterations. It looks like computational cycles, don't you think?

Author: Maybe... But there is a huge difference between any aspects of quantum theories and your original claim. Can we stay on topic, please? Tell me what happened.

Uval: Sure. As part of my freelance, I am doing digital quantum calculus for CERN. There was an issue with interpretation of one of the experiments. The program worked, and the experiments show consistent results, but if we would run real time digital analysis an experiment, the outcome was odd. The particle chamber would go to a weird state, where the interacting particles would suddenly "freeze" for a moment. It looked like time in the chamber would freeze, while outside of it time was still ticking. 

Author: How did CP<R> come into the picture?

Uval: That's the best part. I wanted Check Point researches to look into any problem with the code we run, to make sure it is not compromised. CERN suffered multiple hacking attempts (some of them partially successful) over the last ten  years. We wanted to be sure nobody plays us for a fool. I called Oded Vanunu, and his team helped us. This is where we found what we found.

Author:... not sure I understand.

Uval: Our code was okay. But then cyber security researches found a way to freeze time without that particle chamber. In fact, we have discovered a combination of events leading to a relatively short time freeze in a certain portion of space. There is also way to define, how big this bubble of frozen time is, and how to manipulate it. Time is not just freezing, you can move it forward and back at will, within certain limits. It looks like certain chain of events "breaks" the simulation, and it goes to a limited debug mode of sorts, before recovering.

Author: I am still trying to comprehend. Anyhow, why was not it published? Why the secrecy? Too dangerous? Military implications? Political pressure? Too crazy?

Uval: Potentially, it could be all of the above, but... don't laugh... I think the main reason is that "debug mode" vulnerability in the universe is now patched. We cannot reproduce the effect anymore. Whoever runs the simulation, they detected our experiments and blocked us for good. We are now back to square one...

 





Monday, April 1, 2019

Urgent - malware can affect humans!




CP alert, 01.04.2019 

Check Point Research Team is about to release an article concerning new and somewhat terrifying development in the world of malware. Apparently, they have discovered a strain of malware affecting not only computers and mobile devices but also humans.

Similar to what has been described in Neal Stephenson's Snow Crash novel, a computer virus sends some seemingly random sets of digits to GPU causing it to show short timed "garbage" images between the regular frames.

This is believed to be a side effect of GPU crypto-jacking attempts.

Normally those images are not registered by human mind, but if one's screen refresh rate is set to 60 frames per second, there is a risk of exposure.

Our source claims that at least one of key researches has been affected.

Symptoms can include nausea, headaches, seizures, and blackouts. In a long term, malware can lead to psychic and personality changes, causing anti-social behaviour, addiction to loud rock and rap music, desire to ware baseball caps, grow a beard, or to ride a heavy motorcycle at high speed.

If you experience any of these symptoms, contact the author of this blog for further investigation. Do not panic, damage can be reversed, but requires immediate attention.




Thursday, July 26, 2018

Future of this blog

To all my readers, subscribers, colleagues and friends,

In July this year, I have re-joined Check Point Software Technologies as a Cyber Security Evangelist. My new role is about developing and running CheckMates communities and live events in Europe and Asia.

I have started this blog as a convenient working notes format, and then with your support and assistance it became much more than that. I have dome my best to share my expertise, knowledge and understanding of security practices in general and Check Point approach in addressing them in particular. I have met with some of you on my workshops, seminars, training events and also on CPUG and CPX events.

Now it is time to take it to the next level.

I am running several Check Point related groups on LinkedIn. In my new role, I have also assumed admin role at CheckMates. I will be going around to meet some of you during CheckMates User Group regional events. I am already having some dates booked for this year around Europe, and there will be more.

However, it is no longer practical to run this particular blog as an independent discussion board. I will keep it alive, of course. But if you want to stay in touch, please follow me on LinkedIn and CheckMates, please.

Thanks a lot for your support and trust, that means a lot.

Thursday, June 7, 2018

Malwaretec vs FBI - all shades of grey

There is a new development in the FBI vs Marcus Hutchins case. The young fellow is now facing another charge, about lying to FBI.

Marcus's arrest and detention in USA the last year was widely publicized, and his campaign to raise money for his defence is quite successful.

I do appreciate his lawyer's vigour. There is a huge outcry now about how FBI has no case and keeps adding charges to the case. This is a reasonable strategy, however if we want to see the the real picture, it is also good to hear the other part of the story.

There is of course, FBI's indictment papers, but it is not a fun read, and a very long one. Instead I suggest you reading quite compelling research Krebs did on Marcus the last year. If FBI is half as good as Krebs, I would be concerned about the actual outcome of this case. It seems to me there is no back in white in this specific situation, but lots of grey in too many shades.


Friday, April 20, 2018

GuardiCore scores 5 awards on RSA conference

I am happy to share with you that GuardiCore has received 5 (five!) prizes at RSA conference recently. Here is the short list:

InfoSec Magazine Awards:
Cloud Security - Best Product
Microsegmentation - Most Innovative

InfoSecurity Global Excellence Awards:
Innovative Company of the Year (Security)
Cloud Security
Deception Based Security

Proud to be a guardicorean!

Friday, March 30, 2018

Cloud security concerns and ways to address them

It is common today for cloud services to be compromised for months without detection. Remember that Tesla cloud case, where hackers were able to mine moneros for at least a month before being detected? Similar things may happen to others.

Today MyFitnessPal has sent a notification to its users that their accounts are compromised. The hack as discovered five days ago, but the actual hack happened at least a month ago. 150 million accounts are affected.

In light of GDPR coming into effect in May this year, I would expect many companies to review and eventually report personal data breaches more often.

Let's face it: cloud requires elaborate and agile security tools. It is not enough to through an expensive FW on the perimeter anymore to feel safe. If at least one VM or container is compromised, the whole environment is pretty much a goner, unless you have ability to detect and mitigate penetration on time.

Cloud security solution should combine elasticity, effective micro- and nano-segmentation abilities, application integrity control and effective breach detection that would help to avoid a situation when hackers are sitting at your cloud for weeks and months without being detected.

GuardiCore Centra is probably the only one solution today that combines dynamic deception, deputation based detection, effective segmentation technology and unprecedented visibility for virtualised and cloud based data center environment.

Feel free to contact me if you want to learn more.

Saturday, February 10, 2018

UserCenter battle continues as Check Point account services are still failing to do their job properly

In my previous post I have already mentioned that my old account came back online. I have also received several notifications from CP account services.

The first one was hilarious. They have asked me to update my email with Pearson VUE before transferring my certifications that are already granted. After asking them if this is a joke, they reported that they have transferred certification history. Well, I had to check. Guess what...

Two out of 14 certificates were lost in the process. Every time account services answer, they are also closing the open case. I have had to reopen it twice already.

So far nobody picked up a challenge about email address change. Too bad, as all this hustle would be avoided completely, would I be able to change that bloody email myself.

However, I would like to ask one more question. What is wrong with account services and Check Point? Why are they failing to perform a simple task?

Update: The issue is finally resolved. 6 days and two escalations. For a simple email change. Fantastic job, Check Point, really well done


Thursday, February 8, 2018

Changing jobs? Brace yourself for impact of losing your UserCenter access

Probably the most annoying part of having and account with Check Point UserCenter is that you cannot change your email address.

Which is, please allow me to say it plainly, utterly stupid.

8 years ago the company I was working for, Dimension Data, had gone through a re-branding phase. All emails where changed from 'name'@'region'.didata.com to 'name'@dimensiondata.com. Considering hundreds of accounts for all company employees around the globe, the impact was huge.
Old email accounts were discontinued, so to fix this, we have approached Check Point with a request to re-assign logins to new new email domain. Guess what was the answer?

- No can do.

So hundreds of DD engineers, sales and accounting guys have had to re-create email alliances to continue working with Partners' portal and UserCenter. They are still using this method now, after those 8 years. It was easier to keep all email addresses afloat than redefine manually tons of dependencies and details.

That was about business. On a personal level there is also lots of pain. If you are changing jobs, be ready that Check Point will sever your access even if you ask them not to do that.

In my case, I have left Dimension Data at the beginning of 2018. One month before that I have opened a case with account services to move my certification details, CheckMates account and UserCenter access to another email address. Once more, the answer is:

- We cannot do that. Please open a new UserCenter account and ask to move your certificates there. 

They have also assured me that my old account will not be closed automatically. Guess what... It is no longer working.

The main implication with changing your email with UserCenter this was is that you lose your history and your CheckMates access. You will appear as a new user everywhere. You will have to wait till they figure out how to move your certification. And I suspect recovering expert access to UserCenter resources will also be a story.

I do not even want to speculate why an established security company cannot figure our how to change an account ID without killing it altogether in the process.

However, this is the reality we are facing today. If you are planning to change your job, make sure you download all your valid certificates and bookmark your CheckMates threads. Because you will not be able to keep all that intact after moving to another email address. Bugger...

I dare Check Point admins to name me a single reason why I cannot change my email address on my account.

Anybody out there up for the challenge?


-----------------
Update: My old account is operational again. Whoever is responsible, thanks a lot. The issue of transferring the access level and certification history to a new account is not yet resolved. So the challenge stands.






Thursday, February 1, 2018

The main cyber security questions of 2017 and the way to answer them

At the end of 2017 I was talking to some US based business analytics firm, and the main questions they asked was why.

- Why security budgets are not growing rapidly, after all that scare with WannaCry and NotPetya? 
- Why businesses are not spending more to protect themselves, aren't they scared now? 
- Why the impact was so hard, even for the customers with high end perimeter security systems?
- Why is it happening?


Well, let's start with the easy one. Businesses are scared.

They were scared long before 2017 malware rampage. In 2017 they suddenly realised it does not matter how scared you are. They reached the limit of fear. They have realised it does not matter how much you spend on perimeter security. It does not matter how well-known your vendor is, which part of the Gartner it occupies and how great is his marketing campaign. None if it matters. By the end of the day, a weak link will be found and you will be owned.

So business is doing what it's doing best - counting money. They have switched to a risk management mode. For what it worth, backup tech budgets were raised, not firewalls. Additional insurances and legal protection fees are on the rise, not perimeter security budgets.

The second why is also simple but not that obvious. Perimeter security solutions today are top-notch, but they are still failing the customers. You can have all the jazz: FW, IPS, Anti-Virus, sandboxing, and you will still miss something eventually. Or even better, business will not wait for your security cycle and will deploy something completely exposed, with, god forbid, SMB services open to the Internet.

Hello, WannaCry, here is your free lunch,  come and get it.

In the eternal struggle between security professionals and business the latter always wins. Why? Because, think about it. It is just the matter of money. Business makes money, security spends some of it. If from the business perspective cost to effect ratio is not getting better, additional spendings are at best questionable.

Yet, the major security vendors are still beating the dead horse. Every conference, every vendor event includes some scare presentation about malware on a loose, hackers success stories and slides with names and sums of damages in big red letters.

Well, good luck with that.

In Guardicore we take an alternative route. We protect your East-West traffic, securing later movements in your infrastructure. We enable business and speed up DevOps actions by applying dynamic labelling as part of micro segmentation security policies, we provide unprecedented visibility of your assets traffic and detect intrusion attempts and anomalies in real time. On top of all that, we provide dynamic deception to lure an attacker into a honeypot to make sure his tools and tactics are registered and blocked everywhere across the ecosystem.

The new age of security is here. You do not have to be scared anymore.

Tuesday, January 23, 2018

Come to my session at CPX in Barcelona


Hi all, if you are coming to CPX 360° at Barcelona, feel free to visit my session about hybrid cloud security practices. It happens on Thursday at 14:00 in the room 116.


Wednesday, January 3, 2018

Goodbye Check Point, Hello GuardiCore

Today is my last day with Dimension Data. Looking back to almost 10 years of my work there, I want to say thank you for all my colleagues and friends for their support, help and assistance through that time. I felt being appreciated and valued, I have had many interesting projects, challenges and wins. Later this week I will board a plane to Tel Aviv to join my new company: GuardiCore.  I have visited GuardiCore on September the last year while being on vacation in Israel by the invitation of Sharon Besser.  I falled instantly in love with the company, the technology and the team. At that point my departure from Dimension Data was only a question of time.  I am leaving a very comfortable place to embarque on a new exciting journey. I am also giving up my 17 years of Check Point engineering for a challenging world of cloud and virtualization security.  If you are concerned about your virtualized DC security, if you are seriously considering moving to a cloud, private, hybrid or public, feel free to ask for an advice. I will be happy to assist you into putting in place a brilliant and effective security solution - GuardiCore Centra.   I also have to add a note about my personal projects related to Check Point.

With this transaction, unfortunately, I will have to put to rest Check Point Expert Talks.

This blog will remain up, and I am still deciding whether I will continue it as it is or run a spin-off for cloud security only.

Your thought for the matter are appreciated.

Anyhow, wish me luck and stay in touch. We will have yet another good ride, people. This time, to the cloud and beyond.

Monday, November 6, 2017

Kernel debug Best Practices or "Why "fw ctl zdebug..." should not be used"

Over last several days I have seen rapidly growing amount of posts at CPUG and CP Community where "fw ctl zdebug..." command was mentioned, used and advised.

Although some of you already know my position for the matter, I have decided to write a post about the growing custom to use zdebug instead of employing full fw ctl debug mechanism.

Kernel debug in general


Check Point FW is essentially a Linux-based system with a kernel module inserted between drivers and OS IP stack. If you do not know what I am talking about, you may want to look into this post with an explanatory video for the matter.

Extracting information about kernel based security decisions is rather tricky, so Check Point developed an elaborate tool to read some info about various FW kernel modules actions.

In a nutshell, each kernel module has multiple debug flags that force code to start printing out some information. I have numerous posts in this blog explaining different flags, tips and tricks with kernel debug and also providing links to CP kernel debug documents.

Debug buffer


It is important to understand FW kernel is always printing out some debug messages. For most of the kernel modules, error and warning flags are active, and the output goes to /var/log/messages by default. This is not practical for debug, so before starting kernel debug, an engineer needs to set a buffer which would receive debug output instead of /var/log/messages file.

To do so, the following command is used: fw ctl debug -buf XXXXX, where XXXXX is the buffer size in KB. The maximum possible buffer today is 32 MB, but I advise my students to use 99999 to make sure they get maximum buffer possible anyway.

Kernel can be very chatty, so having a bigger buffer would ensure less kernel messages being lost.

Debug modules and flags


FW kernel is a complex structure. It is built with multiple modules. Each of the modules has its own flags. One can run a single debug session with multiple flags raised for several modules. To raise debug flags, one use one or several commands of this type:

fw ctl debug -m (module name) (+|-) (list of flags)

It is essential that + and - options allow you to raise and remove flags on the fly, even during an already running debug session. List of modules and flags can be found by the first link in this post.

Printing info out of buffer


Raising flags is not enough, as to get information, you need to start reading buffer out with this command:

fw ctl kdebug -f (with some options)

There will be A LOT of information, so never do this on the console. Use SSH session or redirect to a file.

Stopping debug


Once you collected the relevant info, you need to reset kernel debug to the default settings, otherwise you FW will continue printing out tons of unnecessary info. To do so, run

fw ctl debug 0

What is fw ctl zdebug then?

fw ctl zdebug is an internal R&D macros to cut corners when developing and testing new features in the sterile environment. It is equivalent to the following sequence of commands:

fw ctl debug -buf 1024
fw ctl debug (your options)
fw ctl kdebug -f
-------(waiting for Ctrl-C)
fw ctl debug 0

Why is this a problem?


If you are still reading this post and get to this line, you probably think zdebug is a god sent miracle. It simplifies so many things, it is the only way to run debug in production environment! Right? 

Wrong. To make it plain, here is the list of problematic point with this way of doing things:

1. The buffer is way too small. Lots and lots of messages might be just lost because buffers does not have enough room to hold them before read.
2. It is not flexible enough. Running debug in production requires lots of consideration and certain amount of caution. After all, you are asking FW kernel to do extra things, lots of them. The best practice is to start with a single flag or two and expand area of research in the fly trying to catch an issue. This is impossible to do with fw ctl zdebug macros.
3. It is too simple to use. You could say, what a funny argument. Yet, let's think about it. To master kernel debug as described above, one has to understand kernel structure, dependencies, flags and modules. You don't have to do any of that to run fw ctl zdebug drop, and many people do just that. 

My personal position on this is that kernel debug is a sensitive and risky operation. It requires understanding of the technology and the tool itself beforehand. Without such understanding one could miss messages, complicate things and in some very limited cases, crash the GW under debug. The latter I have not seen for quite some time, though.


-----------
Support CPET project and this blog with your donations to https://www.paypal.me/cpvideonuggets 


Monday, October 30, 2017

Check Point researches dissect IOTroops Botnet

Check Point security research team has recently posted an elaborate and impressive report about IOTroops botnet.

The details and depth are fascinating. Highly recommended to read.

-----------
Support CPET project and this blog with your donations to https://www.paypal.me/cpvideonuggets 


Monday, October 16, 2017

Check Point is finally fixing issue with CCSM continuity, somewhat

At the beginning of the year I was posting about CCSM continuity hiccup (1, 2, 3).

In a nutshell, there were two main issues:

1. CP did not managed to let people with expiring CCSM re-certificate in time and did not provide any graceful extension.
2. Due to a clerical error, some people were getting 4 years of CCSM certification while others were having only 2.

I have taken liberty to contact Check Point Education Services managers and to discuss the issue. There was a quite long threat with dozens of emails back and forth, and finally in February Check Point Certification manager has publicly acknowledged the mentioned issue.

However, Check Point did not provide any solution for the matter at that time. Moreover, they have rejected my private proposal to make a one time correction of CCSM validity for all certified specialists from 2 to 4 years, that would resolve both continuity and consistency problems in one shot.

This situation has undermined public trust and appeal of having the highest certification level with Check Point. Also, new partnership program does not require having any CCSMs, even for support partners. It seemed to me that the company did not have any solid strategy to develop an advanced certification at this point.

In my humble opinion, CCSM is nothing but a stripped down version of older CCSE Plus certification, and cannot be even compared with flawed but very challenging CCMA exams that Check Point eventually failed as well.

That said, there are signs the company is finally coming to its senses and trying to reverse the situation.

At the end of September all CCSMs have received an email from Check Point Certification manager Jason Tugwell granting an extension of CCSM status for all people having their certificates expired between the beginning of 2017 and up to end of March 2018.

Everyone in this group, including those whose certification has lapsed already, are granted extension of CCSM status till end of June 2018.

Although this is not making right 2 years of certification versus 4 years for some, but it is still covering the continuity lapse, under condition Check Point Education Services will be able to develop and release new CCSM course and exam till the second quarter of 2018.

Just to make it clear, the extension notice should be received by all CCSM professionals whose certification expires between January 2017 and March 2018. If you are one of them but did not receive such notice, please talk to account managment at Check Point to fix it.



-----------
Support CPET project and this blog with your donations to https://www.paypal.me/cpvideonuggets 

Wednesday, September 6, 2017

Your ultimate landing page for Advanced Tech Reference Guides


Check Point SecureKnowledge database is vast. It has hundreds of thousands of articles and documents. Sometimes, it takes a bit of an effort to find there what you are looking for.

Yet, it sometimes yields fantastic results. Here is something you may want to add to your bookmarks: a landing page for accessing ATRGs - Advanced Technical Reference Guides.

So far, it has links to 36 ATRGs. Whenever you want to learn a feature in depth, this is something you want to visit.

Also, it now has three new documents:



Many thanks to Sergei Shir for sharing this information.

-----------
Support CPET project and this blog with your donations to https://www.paypal.me/cpvideonuggets 

Monday, August 7, 2017

Capsule Docs on Mac? Forget about it...

Last year I was writing about my rather unpleasant experience around Capsule Docs on Mac. It is time to add another chapter to that story.  

I have made yet another attempt to use the tool on Mac. With my 10.12.6 Sierra machine it fails even more miserable than before. With the latest client (still Alpha, mind you!), I cannot even open a document.




Although I am logged in and even can open the same document on Windows with the same credentials, I am getting "Insufficient permissions"...



How hard can it be, really? What should happen for Check Point to start getting Mac user seriously?

In case you ask, the only reason for me to even touch Capsule Doc Viewer is that Check Point Education Services discontinued paper courseware, forcing both students and instructors to use e-kits with Capsule Docs protection. I will address this subject later on.

-----------
Support CPET project and this blog with your donations to https://www.paypal.me/cpvideonuggets 


Sunday, July 30, 2017

CPET session 3 - video is published

Thanks all who could join.

The session subject is Kernel Debug, best practices


-----------
CPET project relies on your support. 
Participate in the talks and help us with your donations to https://www.paypal.me/cpvideonuggets 
Follow us on Facebook and Twitter. 

Wednesday, July 26, 2017

Turning out of state drops on and off on your gateways without pushing policy

One of the regular issues I help my customers resolving is about out of state drops. there might be multiple causes, and those should be addressed by proper troubleshooting and network configuration changes.

However, there are cases when you just need a quick fix before addressing the root case of the problem.

The classic way to do that is to change Global Properties settings on your management and to install policy. The biggest problem with that approach is that the settings are global and will affect all FWs in the security domain after a policy push.

But no worries, there is a way around it, described in SK117374. Fw kernel has two parameter that define out of state drops for TCP and ICMP:

fw_allow_out_of_state_tcp
fw_allow_out_of_state_icmp

For example, by running fw ctl set int fw_allow_out_of_state_tcp 1  you can allow TCP traffic to pass through. Setting the same parameter to 0 will start dropping out of state TCP again.


-----------
Support CPET project and this blog with your donations to https://www.paypal.me/cpvideonuggets