I have just sat the CCSA NG exam, and failed. One of the questions I had difficulty with was the following.
If you have disabled the 'Accept VPN-1 & Firewall-1 Control Connections' in the Implied rules secion of Global Properties, how can you re-enable communications between VPN-1/Firewall-1 daemons?
According to the manual, if you disble this option, you must explicitly allow these connections in the rule base. My understanding of this procedure, is that if you disable Control Connections, and do not explicitly implement these rules, you will no longer be able to communicate between the Policy Editor and Management Server. Therefore preventing you from modifying the security policy and re-enabling the Control Connections.
Is there a command line option you can use, or a file that can be edited on the Management Server?
Thanks
If you have disabled the 'Accept VPN-1 & Firewall-1 Control Connections' in the Implied rules secion of Global Properties, how can you re-enable communications between VPN-1/Firewall-1 daemons?
According to the manual, if you disble this option, you must explicitly allow these connections in the rule base. My understanding of this procedure, is that if you disable Control Connections, and do not explicitly implement these rules, you will no longer be able to communicate between the Policy Editor and Management Server. Therefore preventing you from modifying the security policy and re-enabling the Control Connections.
Is there a command line option you can use, or a file that can be edited on the Management Server?
Thanks