CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-27
jeetu_chaudhari jeetu_chaudhari is offline
Junior Member
 
Join Date: 2006-04-11
Posts: 16
Rep Power: 0
jeetu_chaudhari has an average reputation (10+)
Default FireWall allows remote "get topology" request

Hi all ,

Kindly help me to remove vulenrability in checkoint.

I recentlly done Vulnerabilty Assesment on chekpint mgmt server segment
I placed scanning machine in same segment of mgmt server.

Following low vulenrabilty is shown in scan report,

Fw1GettopoNoauth: FireWall-1 allows remote "get topology" requests without authentication

The Check Point FireWall-1/VPN-1 SecuRemote client requires knowledge of a network's topology before it can negotiate a VPN (Virtual
Private Network) connection. SecuRemote clients prior to version 4.0 do not encrypt or authenticate connections to the SecuRemote
Server, which could expose possibly sensitive network topology information to remote attackers. The client and server of SecuRemote
version 4.1 support string authentication and encryption of this data, but by default permit weaker, less secure connections for backward
compatibility. An attacker could take advantage of these weaker connections to obtain sensitive network topology information.

Remedy

Disable the FireWall-1 option "Respond to Unauthenticated Cleartext Topology Requests".
To disable this option from the FireWall-1 Policy Editor:
1. Open the FireWall-1 Policy Editor.
2. Select Policy --> Properties.
2. Click the Desktop Security tab.
3. Clear the "Respond to Unauthenticated Cleartext Topology Requests" check box.


I can't able to find remedy which is mention above.

If any one knows please reply to me.

Thanks,
jeetu
Reply With Quote
  #2 (permalink)  
Old 2006-10-27
betski betski is offline
Member
 
Join Date: 2006-07-05
Location: Yorkshire, UK
Posts: 42
Rep Power: 0
betski has an average reputation (10+)
Default Re: FireWall allows remote "get topology" request

do a google image search on "check point policy editor"

that should get you going in the right direction >>>>
Reply With Quote
  #3 (permalink)  
Old 2006-10-27
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 808
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: FireWall allows remote "get topology" request

Which version are you using?
Reply With Quote
  #4 (permalink)  
Old 2006-10-29
jeetu_chaudhari jeetu_chaudhari is offline
Junior Member
 
Join Date: 2006-04-11
Posts: 16
Rep Power: 0
jeetu_chaudhari has an average reputation (10+)
Default Re: FireWall allows remote "get topology" request

checkpoint NGX R60
Reply With Quote
  #5 (permalink)  
Old 2006-10-30
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 808
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: FireWall allows remote "get topology" request

It looks like your scan, and suggested remedy, are for Check Point 4.1. I'm not sure that this is still relevant for post 4.1.
Reply With Quote
  #6 (permalink)  
Old 2006-10-31
Acidio Acidio is offline
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 2
Acidio has an average reputation (10+)
Default Re: FireWall allows remote "get topology" request

Northlandboy is right. In 4.1 days, you could get a topology download without first being authenticated. A check box was available to prevent this, but as of NG the default behavior is to only provide topology once a user is logged in via SecRemote/SecClient.

The only way I could think that you the still have the issue is if you have upgraded from 4.1 through to NGX. However, I'm sure the default behavior was changed when doing upgrades as well.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:26.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0