<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for yurisk.info</title>
	<atom:link href="http://yurisk.info/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://yurisk.info</link>
	<description>Technical Blog about IT Security and Networking</description>
	<lastBuildDate>Tue, 07 Sep 2010 19:08:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>Comment on awk weekly &#8211; rule hits statistics . Checkpoint again by Yuri</title>
		<link>http://yurisk.info/2010/03/13/awk-weekly-rule-hits-statistics-checkpoint-again/comment-page-1/#comment-1236</link>
		<dc:creator>Yuri</dc:creator>
		<pubDate>Tue, 07 Sep 2010 19:08:31 +0000</pubDate>
		<guid isPermaLink="false">http://yurisk.info/?p=572#comment-1236</guid>
		<description>Well , strange - I run today this script against NGX R65 and R70.10 and had expected results. Hard to say why it doesnt work for you w/o looking at the log file format you use, so ... 
BTW I think of rewriting this script to calculate hit counts based on rules ID and not numbers that change after you  add/remove rules, so watch for update</description>
		<content:encoded><![CDATA[<p>Well , strange &#8211; I run today this script against NGX R65 and R70.10 and had expected results. Hard to say why it doesnt work for you w/o looking at the log file format you use, so &#8230;<br />
BTW I think of rewriting this script to calculate hit counts based on rules ID and not numbers that change after you  add/remove rules, so watch for update</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 8 Things to do before opening ticket with Checkpoint by guy yovel</title>
		<link>http://yurisk.info/2010/06/25/things-to-do-before-opening-ticket-with-checkpoint/comment-page-1/#comment-1220</link>
		<dc:creator>guy yovel</dc:creator>
		<pubDate>Sat, 04 Sep 2010 12:57:05 +0000</pubDate>
		<guid isPermaLink="false">http://yurisk.info/?p=925#comment-1220</guid>
		<description>I am impressed, you are absolutely correct. Check point support is pretty bad, I might say. Indeed if you have critical situation and proven network or system down due to check point software then you will get good service. Your case will be immediately escalated to higher support level and software developers will be involved fast enough, so you can expect a fixing patch in few days. This is very logic attitude from company perspective because customer can forgive on slow handling of medium severity case but will be very disappointed for slow acting when his business in troubles.

But in reality most, and I estimate this in 95%, the cases will be moderate severity and therefore the case will be 1 out of 30 cases per support engineer in average. Even if the support engineer is really want to assist, you are only one out of 30 other cases. So you can expect big delays and very slow work on your issue. So if you as customer or check point partner is professional enough to assist with debugging, self replication and workaround the issue will progress much faster then if you are passive and wait for instructions from the TAC. By the way in most cases the check point TAC is not acting as real technical and more as kind of call center. And the difference is huge…..

Best regards,
Guy Yovel
guyovel ATT nana.co.il</description>
		<content:encoded><![CDATA[<p>I am impressed, you are absolutely correct. Check point support is pretty bad, I might say. Indeed if you have critical situation and proven network or system down due to check point software then you will get good service. Your case will be immediately escalated to higher support level and software developers will be involved fast enough, so you can expect a fixing patch in few days. This is very logic attitude from company perspective because customer can forgive on slow handling of medium severity case but will be very disappointed for slow acting when his business in troubles.</p>
<p>But in reality most, and I estimate this in 95%, the cases will be moderate severity and therefore the case will be 1 out of 30 cases per support engineer in average. Even if the support engineer is really want to assist, you are only one out of 30 other cases. So you can expect big delays and very slow work on your issue. So if you as customer or check point partner is professional enough to assist with debugging, self replication and workaround the issue will progress much faster then if you are passive and wait for instructions from the TAC. By the way in most cases the check point TAC is not acting as real technical and more as kind of call center. And the difference is huge…..</p>
<p>Best regards,<br />
Guy Yovel<br />
guyovel ATT nana.co.il</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on awk weekly &#8211; rule hits statistics . Checkpoint again by Junior Toledo</title>
		<link>http://yurisk.info/2010/03/13/awk-weekly-rule-hits-statistics-checkpoint-again/comment-page-1/#comment-1217</link>
		<dc:creator>Junior Toledo</dc:creator>
		<pubDate>Wed, 01 Sep 2010 00:49:17 +0000</pubDate>
		<guid isPermaLink="false">http://yurisk.info/?p=572#comment-1217</guid>
		<description>Hi, 

I&#039;m running this command, but do not get the result of all rules only the total hits.
I need to change some syntax for that to happen?

I&#039;m just getting this result:
Rule number: Hits: 1565351

Thanks, Junior Toledo</description>
		<content:encoded><![CDATA[<p>Hi, </p>
<p>I&#8217;m running this command, but do not get the result of all rules only the total hits.<br />
I need to change some syntax for that to happen?</p>
<p>I&#8217;m just getting this result:<br />
Rule number: Hits: 1565351</p>
<p>Thanks, Junior Toledo</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Print rulebase in Checkpoint by Crystal</title>
		<link>http://yurisk.info/2009/12/31/print-rulebase-in-checkpoint/comment-page-1/#comment-1196</link>
		<dc:creator>Crystal</dc:creator>
		<pubDate>Mon, 16 Aug 2010 11:02:09 +0000</pubDate>
		<guid isPermaLink="false">http://yurisk.info/?p=361#comment-1196</guid>
		<description>I know how to print a rulebase, but what if you would like to print out the database of the objects with IP addresses in the rule base. 

thanks</description>
		<content:encoded><![CDATA[<p>I know how to print a rulebase, but what if you would like to print out the database of the objects with IP addresses in the rule base. </p>
<p>thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Change IP address on the interface without losing the connection by Yuri</title>
		<link>http://yurisk.info/2010/06/02/change-ip-address-on-the-interface-without-losing-the-connection/comment-page-1/#comment-1185</link>
		<dc:creator>Yuri</dc:creator>
		<pubDate>Sat, 14 Aug 2010 05:35:08 +0000</pubDate>
		<guid isPermaLink="false">http://yurisk.info/?p=848#comment-1185</guid>
		<description>Hi Karia , 
good point - it was a standalone firewall , so SIC wasnt an issue, so if I recall right I didnt need to reestablish the SIC communication.
No , it wasnt a cluster.
Yuri</description>
		<content:encoded><![CDATA[<p>Hi Karia ,<br />
good point &#8211; it was a standalone firewall , so SIC wasnt an issue, so if I recall right I didnt need to reestablish the SIC communication.<br />
No , it wasnt a cluster.<br />
Yuri</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Change IP address on the interface without losing the connection by Karia</title>
		<link>http://yurisk.info/2010/06/02/change-ip-address-on-the-interface-without-losing-the-connection/comment-page-1/#comment-1184</link>
		<dc:creator>Karia</dc:creator>
		<pubDate>Wed, 11 Aug 2010 16:11:03 +0000</pubDate>
		<guid isPermaLink="false">http://yurisk.info/?p=848#comment-1184</guid>
		<description>Great....Its really difficult.

1. SIC is established VIA externall IP,did u established SIC after this change?
2. Did the box in cluster?</description>
		<content:encoded><![CDATA[<p>Great&#8230;.Its really difficult.</p>
<p>1. SIC is established VIA externall IP,did u established SIC after this change?<br />
2. Did the box in cluster?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Capture packets at IOS Cisco router or finally we have a sniffer by Kyle</title>
		<link>http://yurisk.info/2010/02/01/capture-packets-at-ios-cisco-router-or-finally-we-have-a-sniffer/comment-page-1/#comment-1181</link>
		<dc:creator>Kyle</dc:creator>
		<pubDate>Tue, 27 Jul 2010 20:30:37 +0000</pubDate>
		<guid isPermaLink="false">http://yurisk.info/?p=466#comment-1181</guid>
		<description>Yuri - thank you - good write up on this.</description>
		<content:encoded><![CDATA[<p>Yuri &#8211; thank you &#8211; good write up on this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on You can&#039;t set duplex/speed settings of the Fortigate interfaces? by Chris</title>
		<link>http://yurisk.info/2009/06/10/you-cant-set-duplexspeed-settings-of-the-fortigate-interfaces/comment-page-1/#comment-1174</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 13 Jul 2010 19:13:32 +0000</pubDate>
		<guid isPermaLink="false">http://yurisk.info/?p=152#comment-1174</guid>
		<description>How do I set the wan1 port to auto? i tried everything I could think of. I must be missign something</description>
		<content:encoded><![CDATA[<p>How do I set the wan1 port to auto? i tried everything I could think of. I must be missign something</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on You can&#039;t set duplex/speed settings of the Fortigate interfaces? by jarbro</title>
		<link>http://yurisk.info/2009/06/10/you-cant-set-duplexspeed-settings-of-the-fortigate-interfaces/comment-page-1/#comment-1166</link>
		<dc:creator>jarbro</dc:creator>
		<pubDate>Thu, 08 Jul 2010 19:04:04 +0000</pubDate>
		<guid isPermaLink="false">http://yurisk.info/?p=152#comment-1166</guid>
		<description>Thank you, thank you!  Your post reminded me of a setting I had put on my wan1 interface which was causing serious link speed degradation.  Once I set my wan1 interface back to auto everything was back in tip-top shape. You have no idea how long I banged my head against the wall on this one.</description>
		<content:encoded><![CDATA[<p>Thank you, thank you!  Your post reminded me of a setting I had put on my wan1 interface which was causing serious link speed degradation.  Once I set my wan1 interface back to auto everything was back in tip-top shape. You have no idea how long I banged my head against the wall on this one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MAC finder script by Yuri</title>
		<link>http://yurisk.info/2010/07/02/mac-finder-script/comment-page-1/#comment-1165</link>
		<dc:creator>Yuri</dc:creator>
		<pubDate>Mon, 05 Jul 2010 15:23:48 +0000</pubDate>
		<guid isPermaLink="false">http://yurisk.info/?p=959#comment-1165</guid>
		<description>Thanks Giuliano for the pointer, for a single MAC I also will use whatever is more available - Google being the winner for me, but when it gets to finding 10,20,20 MACs it gets  real ugly without automation.
Yuri</description>
		<content:encoded><![CDATA[<p>Thanks Giuliano for the pointer, for a single MAC I also will use whatever is more available &#8211; Google being the winner for me, but when it gets to finding 10,20,20 MACs it gets  real ugly without automation.<br />
Yuri</p>
]]></content:encoded>
	</item>
</channel>
</rss>
