Online Training Room https://www.youtube.com/channel/UCXDXyOrYcBuQRd1EUVYAKeg?view_as=subscriber
Sunday, 5 April 2020
Tuesday, 17 March 2020
Category
- How do I backup and restore an MDS?
- What is Provider-1?
- How to merge CMA's
- provider-1 problem waiting
- Provider-1 mdsbackup
- Exporting from Provider-1
- Provider-1 NG R55 - Re-Authenticating with SecurID Authentication
- Separating MDS manager from container
- Provider-1 Running Slow
- Provider-1 Global Objects
- MDG Software
- Provider-1 mds_backup no cp.license
- Moving existing management server into PR1
- Logging in Provider1 (NGX)
- Provider-1 backups on SPLAT
- mds_backup vs backup on PR1 (SPLAT)
- Restoring from a backup - compression errors !
- what is CPprofile.sh
- Provider-1 VSX NG AI
- Bridge Mode on VPN-1 NGX
- How to migrate firewall from different CMA?
- Migration from P1's CMA back to Mng Server
- Preconfiguring the IP for CMA on SPLAT
- After in-place upgrade R60A to R61 operations fail on some CMA's
- Provider-1 FWM Process
- Provider-1 and Solaris multipathing?
- How to Fetch logs from VSX?
- cma_migrate error
- Provider-1 Migration
- Problems: P1 R60 trying to manage R61 VPN Pro
- P1 Customer Properties
- Modules intermittently showing "Needs attention"
- Patching PR1 NGX R60 with HFA04
- P-1 R61/NG FP3 SIC issues
- Moving a MDS that is also a CA
- Provider-1: Migration from R60 to R61HFA1
- Provider-1: How to do a fwm sic_reset on a particular CMA?
- Installing a Secondary MDS Manager NGX
- Provider-1 vs. SiteManger-1
- mdsquerydb / cpmiquerybin
- upg/new install from r55 to r61 on new server and use modified cp-admins.C off R55
- cp-gui-clients.C file the same between R55 and R61 ?
- Problems introducing a new remote secondary Provider 1 server (Provider1 NGX R60 HFA0
- Monitoring Provider-1/SiteManager-1 Status
- provider-1 credentials - not passing to SmartDashboard
- securing Provider-1 assets
- Introducing Smartcentre logging server into PR1 NGX
- 2 MLMs defined - how can I confirm syncing ?
- provider1 - bad or good?
- Provider-1 intermittent problems
- CMA migrate
- Provider-1/sitemanager-1
- SIC CMA on Backup Provider
- logging to 2 different CLM versions of Provider-1?
- Provider-1 NGx R65 and licensing issue
- SmartCenter to CMA
- restore
- Provider-1 Global Policy unable to be applied
- How to determine physical IP address of a CMA?
- provider-1 - good/bad thoughts?
- importing policies into CMA
- Provider-1 R65 upgrade from R60
- MDS FWM Process dies
- NGAI VSX cma migration to R61
- unable to login to dashboard after upgrade
- Internal error [11]
- Urgent: Help needed with migrating NGx R65 CMA from Solaris 9 system to SPLAT system
- Urgent help needed with Provider-1 misconfiguration
- Both Provider-1 Managers showing as "active/active"
- Provider-1 NGXR65
- Provider - 1 upgrade R54 to R62
- Provider commands
- Provider-1 with Eventia
- Provider-1
- P-1 problem. need help ASAP
- New CML
- Eventia not generating logf after upgrade from R55 to R61
- LEA Ports to opened for Provider-1
- P-1 and RSA SecurID authentication
- Multiple Standalone FW to 1 CMA
- Error: cannot resolve name!
- Cron MDS Backup for NGX
- GUI for Secureplatform
- migrate users & gui clients
- BACKUP OR MDS_BACKUP?
- Provider installation
- Gateway cluster member doesn't show up in Provider-1 MDG
- P1 HA options
- CMA migration from NGX R60 to R65
- Provider-1 upgrade_export? Is it possible?
- Migrate R55 SC to R65 P1 CMA
- Global policy
- User Provisioning to Provider-1 CMA
- Provider-1 and multi-processor machine
- ¿Provider-1 R62 or R65?
- managing users on a log server that isn't a CLM inside MDS
- mds_backup failed
- Installation failed
- Extracting Administrator Info from P1
- Provider-1 NG R55 to NGx R65 upgrade dilema
- Pre upgrade verifier errors
- Copying objects from CMA to new CMA on same box ?
- Provider-1 NG w/ AI R55 on a Dell 4xCPUs box
- Error to install "global policy" in Provider-1
- Status of network objects (module) in R65 MDS gui
- Provider-1 MLM hardware recommendations
- CHECKPOINT OBJECT REMOVAL
- secondary log server
- R61 to R65 upgrade
- after upgrade to R65 : old folders
- cp_merge could not open the database
- mds backup not synced
- Database Revision Control Houskeeping
- SC to CMA
- Upgrading Provider-1 NGx R65 2.4 kernel to P-1 NGx R65 2.6 kernel
- Import SmartCenter to Pro-1 failed
- a policy push removes rules/objects
- Cannot Create a Log Server in Global Rule Base
- single cma db and policy backup
- R65 - CMA GUI Locks not clearing
- Checkpoint Provider-1 NGx R65 and SMP
- Provider-1 Global mesh Global VPN community with permanent tunnels
- Reasons to move to Provider-1
- CMA to SC: going the other way
- Provider-1 Spec
- difference between CLM and MLM
- Custom commands <NAME> variable
- provider-1 server sizing tool
- CMA Backup
- connectivity issues between the customer cma and its remote-gateway
- cma mirroring error pls help
- provider-1 failover not working help !@!
- Provider R61 to R65 - CMA version issue
- migrating firewall to a different cma
- P1 R65 random CMA stop
- P-1 R65: Read-Only Administrators – Access to Dashboard
- MDS_Restore
- rename Customer
- resuse of ip for clm issues
- Dynamic DNS for Edge in a Provider-1 Environment
- CMA seen with "? Status Unknown" in MDG
- migrate policy and objects
- P1 migration from Solaris to Splat
- Migrating CMAs with VSX objects defined
- Need Procedural Help for setting up P-1
- R65 MDS Central License Fails
- CMA import/cma_migrate. ICA key error
- Failed to read database files.
- Provider1 to Smart centre server
- Auditable (meaningful) permissions from cp-admins.C anyone?
- no Active connections for VSX and R65
- Provider-1 NGx R65 upgrade
- Provider-1 mds_backup and 2GB file size limitation
- FWD 100% on one of CMAs
- CMA reassigning error
- Splitting one SC to many CMA - VS
- Splitting a CMA (provider-1 R65)
- CMA Split best method
- Cannot delete CMA
- Global Policy Database Revision Control Fails
- Question: R70 P1 and R65 VSX upgrades
- Provider-1, unable to add global policy.
- this anoying message after upgrading to NGx R70
- Global policy impact on CMA
- basic Question on global policy
- managment through secondary cma
- Local object "promotion" to global object?
- Upgrading an HA Provider-1 System
- Move to Provider-1
- MLM and CLM License
- Provider-1/Sitemanager-1 product question
- NIC teaming (bonding) is supported on Provider-1 NGx R70?
- Provider-1 migration reccomendations
- Provider-1 New Project
- Problem connecting to Provider-1 with MDG
- Changing the ip address of cma
- Making standby cma active ? (PR1-R60)
- R65 HFA 40 Wont Load on MLM but will on MDS
- Migration and Recovery.
- Provider-1 upgrade Multi-MDS env questions
- R70.1 or R65 with HFA04
- CMA start but MDS could be load
- P-1 to CMA migration.
- SIC is not initialized either at the SmartCenter Server or the peer [error no. 119]
- Weird dynamic objects resolution challenge
- Provider-1 firewall rules required
- Deleted Customer / CMA but directory structure still exists
- CMA disappears after starting
- DELL PowerEdge 2970
- SPLAT Provider-1 NGx R65 upgrade to NGx R70 confusion
- Gateway disconnected
- Provider-1 NGX R65 HFA60 Upgrade Problem
- MDS log_rotate script
- CMA just hung from launching via SmartDashboard
- Smartcentre to P1 Migration
- Provider-1 and VSX ugprade and re-IP address
- Provider-1 R65 backup_util sched error
- HFA70 - Anybody?
- R70.30 Remote File Management
- R70.30 P1 and Odd Behavior with VSX
- Upgrade from P1 R65 to P1 R70 - possible scenarios with VSX R65 gateways
- Provider-1 MDS license
- P1 Upgrade and expansion to HA
- Is it possible to turn on logging on multiple rules in one go?
- cpstat mg on P-1 on R70.30
- No eval license on a new CMA ?
- provider-1 install document
- Import CMA from R65 provider One to R71 Provider One
- Provider-1 CMA migration from R70.40 to R71.10
- Global Object gsnmp-trap causes assignment failure
- P-1 is R70.40 but stand-alone log server is R65 HFA_70
- P1 Inactive Accounts
- CLM design - explanation ?
- Failed to create mirror cma ....
- Provider1 supported under VMware ?
- Provider-1 NGx RR71.20
- Manual CMA import wont start on Provider-1 Splat R65
- P1 Upgrade from R65 to R70
- SPLAT PRO R70.40 and Radius Server
- SPLAT NGx R71.10 on Dell PowerEdge 2650 misery continues
- SPLAT R71.20x on Dell PowerEdge R710 with 12GB RAM
- MDG R70.40 crashes
- SPLAT NGx R71.20 MUST READ
- why am I seeing this message?
- Has Check Point lost all credibility when it comes to software defects?
- Migrate a standalone Smart Center Server to P1 SPLAT
- upgrade P1 from R65 to R70
- in place upgrade from R65 to R71.10 fails
- No logs to CMA after import
- 2 issues
- Multi domain Management (R75) on VMware ESXi 4.1
- Best Practice Guides for Provider-1
- R65 P1 to R75 smart-1 standalone?
- provider-1 trick question sort of
- Not sure if this right, but here goes...additional logging off P-1 to an Eventia....
- [Flows Diagram]
- Unable to install global policy
- CMA : Cannot allocate memory error during policy verification
- SmartDomain Manager GUI quits upon connection
- Provider-1 Connected Administrators - Modify Refresh Rate?
- Policy install fail without detail error
- Perl library for P1 (kind of a scripting question)
- (In)Stability of R71.30 Provider-1
- Upgrade to R75.20 Multi-Domain SecurePlatform on Open Server
- R75 Provider-1 in VMware
- Upgrade to R75.10, with SSDs, from R65; Results
- Unable to "Enable Global Use" on R75.20 SmartDomain Manager
- mds_restore - gzip: stdin: unexpected end of file
- Can't start CMAs FWM stopped
- Migrating a Smart Center with multiple policies to P1
- Provider-1 to new hardware migration
- storage access network
- Global OPSEC application object not seen in CMA
- Merge Rule Base in a CMA
- Provider-1 R65.30 to R75.20 Migrate Error
- Multi Admin roles - User Access Rights in Provider-1
- New R75.20 MLM Server on ESX VM w/SAN Attached Storage
- Question on upgrade_import
- Standalone Security Management Server to Multi-Domain Security Management
- mds_restore failed
- Upgrading MDS from R70.1 to R75.20 with MDS HA.
- Provider-1 and VSX - Migration of a CMA containing VS with change of IP address
- FWM process down after a mds_restore
- Popup when CMA starts
- Unused objects in MDS
- FWM of CMA crashes on policy install after upgrade to R75.30
- admin_for_debug_only default multi-domain super-user account on 75.20?
- Upgrading Provider-1 from R65 to R75.30
- CMA migration from one Provider-1 NGx R70.20 to another Provider-1 NGx R71.30 system
- How to upgrade Check Point Multi-Domain management from R71.20 to R75.30
- How to configure Secondary MDS (MultiDomain Server)...
- all in one SC and Gateway migration to Smartdomain
- P1 MDS and MLM R70.30 to R75.40 Inplace Upgrade
- Log backup/archive scripts MDS / MDLS
- Adding VLAN to VS interface...SmartDomain R75 - issues, advice please
- 10 pound question
- Adding routes with dbedit on VSX and install routes
- MDM R75.40 on GAiA - gotchas
- Import from SmartCenter with multiple policies question
- Database install kills Multi Domain Management GUI on SPLAT R75.40VS
- Newbie question: Adding a existing VSX Cluster to a new domain
- Migrate CLM from old to new hardware
- Gateway Migration to new Provider-1 same CMA
- R75.40 mds_restore is broken
- How to move existing CMAs/MDS to bonded interface
- MLM retore and log file recovery or new MLM install
- Procedure for migrating a CLM to new hardware
- R65.70 CMA to R75.30 CMA
- Advice on migration of multiple Gateways and Provider-1
- Parameters and format for editing queries.conf
- Multiple Policy Import - SDM R75
- What versions of gateways can R75.40 & R75.45 MDS manage?
- Secondary Provider help needed
- Silly question on P-1 installed on a Linux server
- Provider-1 , how to export/import administrators to the secondary Provider-1 server
- Migration of (Globel policy & CMA) Provider-1 to another Provider-1
- MDS Upgradation..
- [SOLVED] R76 MDS / VSX license SmartUpdate Issue
- Clean temporary files in $FWDIR
- MDS migration R71.10 to R76
- smartcenter server configurations to Multi domain security managemnet server
- Purpose of the secondary management server deletion before migrate
- Upgraded R75.2 --> R76 MDS -- Frequent GUI Crashes
- How to find Gateway Status using MDSCMD via CLI
- Missing global rules
- PV1 CMA export-import
- Provider-1 to Smart-1
- Does Checkpoint Provider-1 support LDAP for managing the devices
- Regarding Backup and Snapshot of MDM
- Anti-spoofing configuration
- Migrate Management Server R77 with VSX to MultiDomain R77
- why no backup via sftp?
- Gateways per CMA? Large scale deployment experience?
- SmartDashboard R77.10 crashes on specific CMA when doing "Where used"
- Provider-1 R76 best practices for operational maintenance
- how to make the gateway send logs to the domain server public ip
- Tips to shutdown a SMART-1 50 MDS R75.40 appliance
- New user(Multi Domain super user) not able to login in Multi domain manager & others
- Managing growing filesystem on MDSM (R75.46)- /dev/mapper/vg_splat-lv_current
- MDS (CMAs) <- Static NAT -> MDG
- MDS <-> CP Firewall delay tolerance, MDS <-> MDS delay tolerance
- I have very strange issue. Need help !!!
- How to Move one VSX cluster from one CMA to other CMA.
- threshold_config utility
- Multiple Synchronous Logging Servers (MLMs)
- OPSEC LEA forwarding to Log Rhythm
- Stuck on SmartDashboard loading scree when logging to CMA on Provider 1 version 75.20
- Interesting notes on Jumbo Update and basics
- Building MDS in HA
- Smart1-5 Management server upgrade
- sk103683 - multi domain management server
- AutoBackup with migrtae export or the upgrade_export
- CMA to SMS - Not supported ? HELP
- Backups and or migrate exports for CMAs
- Deleting Secondary MDS and CMA from Primary Multi Doamin Management
- CMA migration fails if any of global objects were ever renamed
- Backup Fails on secondary MDS.
- Need help migrated security policy from one CMA to another
- mds_backup deleting the files it created after upgrade to R77.30
- mds_backup not include customer folder
- vsx_util fails
- CMA Auto Backup
- Not all objects in objects_5_0.C file
- Migrate Provider-1 R75.47 to R80
- Licensing CLM (old name)
- Client Authentication Fails after migrating to CMA
- MDM
- MDS Backup
- Automatic Policy Push
- MDS failed to start after mds_backup in R77.30 with JHFA 205
- DMS Migration issue
- keeping CRL IP after changing IP address of CMA
- Domain Migration with VSX
- Upgrade Provider-1 R77.30 to R80.10 issue (is R80.10 ready for prime time).
- high cpu in clish and confd in Provider-1 R77.30 with JHFA 216
- How to export single domain from MDM to SMS
- Upgrade from R77.30 JHFA 216 to R80.10 not working
- automatic restore of P1 backup
- dbedit rule id syntax
- Error when logging into CLI of Provder-1 server
- CPUSE force install?
- Moving CMA from one MDS env to a different one
- Get VSX objects of a CMA from expert
- MDS R77.30 restore. Some unexpected things.
Wednesday, 19 February 2020
Install Checkpoint Security Gateway R80.20 on VMware Workstation

VMware Workstation Version : 12 PRO
IP Address Details
Gateway 1 (Active) IP : Internal (eth0) –> 192.168.1.2/24
Management Server IP : 192.168.1.10/24
VMNet Details
VMnet1 : Host-Only : Internal : 192.168.1.0/24
As per the above diagram we are going to setup Security Gateway with R80.20 ISO.
STEP 01: Download the R80.20 ISO file by refer the sk122485.

STEP 02: Click on “Clean Install” option because we are not doing any GAIA OS version upgrade from any GAIA OS from lower version to Higher version. For example from R80.10.to R80.20.

STEP 03: File Name: Check_Point_R80.20_T101_Security_Management.iso

STEP 04: Verify the MD5 value.
I am using MD5Checker tool to verify, also you can refer other tools to verify the MD5 value.

STEP 05: Open the MD5Checker and add the R80.20 ISO image by clicking the “Add” icon.


STEP 06: Md5 value is showing “same”.

STEP 07: Check the Network configuration to assign network address to VMnet (Virtual Network), so to verify the network configuration go to VMWARE —> FILE —> Virtual Network Editor

As per the below diagram I am using Network 192.168.1.0 so it required one VMnet to setup the MGMT server so I change network 10.10.10.0 to 192.168.1.0/24 where I configure Management Server IP as 192.168.1.10 and Default Gateway as 192.168.1.2.
STEP 08: Click on “Change Setting”.

STEP 09: As below image I change to 192.168.1.0 Network so basically I add the network address: 192.168.1.0 and Subnet Mask:255.255.255.0.
NOTE: Uncheck the “Use local DHCP service to distribute IP address to VMs” because we assign static IP address.


STEP 10: Verify that what is the IP address of that HOST machine (The Machine where we install/run the VMWARE). So basically by default, if I configure the VMnet as 192.168.1.0 then Host machine will getting First host address as 192.168.1.1 but we can use any IP address from on that network segment but on our LAB we are not going to change, take as is it.
NOTE: As my personal experience most of the time people are using First host address such as 192.168.1.1 (example IP address ) as Gateway address or Management address so on that scenario we not able to run the GAIA First Time Wizard configuration because HOST machine by default took the first host address.

STEP 11: Create a new Virtual Machine click on “Create a New Virtual Machine”.

STEP 12: Select the ISO Image file, click on “Browse”.

STEP 13: Select the R80.20 ISO image file.


STEP 14: Select the Guest Operating System: Other because it not on the list and select the Version: Other 64-bit because I am using 64-bit OS.

STEP 15: Select the location where the VM configuration file is store so I select my “D drive”.
NOTE: It is not necessary that you select the “C Drive” only, You can use other drives as well but space should be there.

STEP 16: We are going to use Maximum disk size(GB):100 and select the “Store virtual disk as a single file”
NOTE: As per my personal experience I always recommended to use more than 60 GB as disk size.

STEP 17: Select “Customize Hardware” for configure some parameter.

STEP 18: Select the memory (RAM): 4 GB but as per the below image we can see the minimum memory required is 6 GB for Management Server but because this is my LAB setup so I use 4GB.


STEP 19: Select the total processor core as “2” .
NOTE: As on Live setup need to check with your checkpoint local SE for sizing.

STEP 20: Select the Network Adapter: VMnet1 because we are using VMnet:192.168.1.0

STEP 21: Click “Finish”.


STEP 22: Power on the virtual machine.

STEP 23: Select “Install Gaia on the this System”.

STEP 24: Click “OK”.

STEP 25: Click “US” because I am not using any other language keyboard.

STEP 26: I modify the default configuration as
System-swap (GB) : 7 %
System-root (GB) : 22 %
Logs (GB): 20% and Backup and upgrade (GB): 50 %
NOTE: It depends on the disk size.

STEP 27: Choose a password for Admin . So by Default username is Admin.
NOTE: Make sure that NumLk is on.

STEP 28: Assign IP address and as well as Default Gateway.

STEP 29: Click “OK”.

STEP 30: We are going to reboot the Security Gateway.

STEP 31: Select Login : admin and password:”****” and run the First Time Configuration Wizard.
And Checking the interface configuration, like verify the IP address that we assign to the Security Gateway is properly or not.

STEP 32: Open the Browser like chrome, Mozilla, Internet Explorer, Opera, and other supported browser and browse https://192.168.1.2.(Is my Gateway IP address)
NOTE: Not “http://” it should be “https://”

STEP 33: Login with Username : admin and Password : ***** and click “Login”.

STEP 34: Click “Next”.

STEP 35: Select “Continue with R80.20 configuration” and click “Next”.

STEP 36: On below The IP address that we see, I already configured (Check STEP:32) but still if you want to change the IP address and the Default Gateway then you can do it. eth0 is the internal interface for the security gateway because we have only one VMnet (VMnet1: 192.168.1.0) but for Gateway setup you must be added one more interface for external.
NOTE: Default gateway can be configured later.
The gateway must have one more interface so on our case we only one interface to demonstrate But it required two interfaces so we can able to install the policy.

STEP 37: Give a Host Name as per your wish, in my case I named as “SG” and also assign the Primary and Secondary DNS then click “Next”.
NOTE: Apart from “Host Name” all rest of configuration we can give later as well.

STEP 38: Select “Set time manually” and choose the Time Zone and after selecting this verify the other parameter such as Date and Time.

STEP 39: Select ” Security Gateway and /or Security Management”
NOTE: On R80.20 onward we have separate ISO for Security Gateway and Management Server and for only Security Gateway ISO we use as StandAlone Setup as well as dedicated Security Gateway setup.

STEP 40: As we can see below image Security Gateway checkbox is already enable because it is a dedicated ISO for Security gateway, Yes we also have an option to enable the “Security Management” so once you enable the “Security Management” then it acts as a StandAlone Setup. Soon my case we only setup the security Gateway so no need to enable the “Security Management” checkbox.
Also, we see the option “Clustering” section because this is a Gateway ISO so basically on my case I am not going to configure the ClusterXL so I leave it as is it like not mark the checkbox “Unit is a part of a cluster type”.
Select the “Automatically download Blade Contracts and other important data (highly recommended)” and click “Next”.

STEP 41: On my case, the Gateway does not have any dynamic assign IP address so select “NO” am click “Next”.

STEP 42: Give a strong Secure Internal Communication (SIC) for establishing SIC between Management Server and Gateway and click “Next”.
NOTE : Note down the SIC key it require when you establish SIC.

STEP 43: Click “Yes”.

Now processing is starts.

NOTE: System is automatically going to reboot.

STEP 44: As we see below image that on the host machine or the machine where the VMware installed and running so that machine we unable to ping the gateway address (IP:92.168.1.2) because the default policy is already applied to the Security Gateway.So we need to uninstall the policy to ping work
command : clish>fw unloadlocal


STEP 45: Set the expert-password for advances access.

STEP 46: Open the command cpview (work on both default mode CLISH and also in Expert mode) to check the System Information.

STEP 47: Power on the “Management Server” VM then open the SmartConsole and create a Gateway Object and establish SIC.



STEP 48: After on the Management Server then Login via CLI and try to ping from the Host Machine where the VMware is installed. So first ping to the Management Server IP if it is successful then we open the SmartConsole before that also verify that all services are established (check CPM and FWM).
Command : [Expert]#cpwd_admin list

STEP 49: Add the Security Gateway by using SmartCosole.

STEP 50: As per the below image we able to see the two option one is Wizard Mode and another is Classic Mode. So we can use any of this option but I always like Wizard Mode because of it simple for me. So click on “Wizard Mode”.

STEP 51: Give a name to the Security Gateway Object. I named as “SG” and it’s an open Server so select “Open Server” so if you add any dedicated checkpoint appliance then you need to select that appliance model in that listed.

STEP 52: Assign the Gateway IP address on my case IP address is IP:192.168.1.2.

STEP 53: Now we need to put the SIC key that we set during the Security Gateway First time Configuration Wizard. (Refer STEP:42) , after assign the One-time password (SIC key) click “Next”.

STEP 54: Click “Close”.

STEP 55: Mark “Edit Gateway properties for further configuration” and click “Finish”.

STEP 56: After established the SIC just verify the General Properties.

STEP 57: On the Security Gateway —> “Network Management” click “Get Interfaces” and Click “Get interface with Topology” so anti-spoofing is automatically configured.



STEP 58: Click “Accept”.
On the below image, we have only one interface is added so we able to see one interface IP address that is eth0.

STEP 59: Install the Database.


STEP 60: Publish and Install.


Subscribe to:
Posts (Atom)
-
Install Checkpoint Security Gateway R80.20 on VMware Workstation VMware Workstation Version : 12 PRO IP Address Details Gateway ...