CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point UTM-1 Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-06-28
Member
 
Join Date: 2008-04-12
Posts: 53
Rep Power: 1
doccocaubai has an average reputation (10+)
Default Critical Problem With Checkpoint

I have nokia IP390 firewall running IPSO 4.2 b069 and checkpoint NGX R65. Althought I set the policy permit any any but I can't access any http web (port 80). But I can access the web with https protocol.
Please help me how to fix it.
Reply With Quote
  #2 (permalink)  
Old 2008-06-28
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Critical Problem With Checkpoint

Please post the SmartView Tracker log entry when you try to access an HTTP site and also the log entry when you access an HTTPS site.

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-06-28
Member
 
Join Date: 2008-04-12
Posts: 53
Rep Power: 1
doccocaubai has an average reputation (10+)
Default Re: Critical Problem With Checkpoint

i checked the smartview tracker but there is nothing about http.
please help me.
Reply With Quote
  #4 (permalink)  
Old 2008-06-28
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Critical Problem With Checkpoint

Is there any log entry at all? Try filtering on just the source IP you're using for the HTTP connection.

Do you have logging enabled on all rules? Do you have a Cleanup rule at the very bottom of the rulebase?

Source: any
Destination: any
Service: any
Action: Drop


Make sure it's set to Log. If not, add it and try again. Check Point has this rule built in but it doesn't log anything. That's why you need to add it yourself.

Ray
Reply With Quote
  #5 (permalink)  
Old 2008-07-13
Member
 
Join Date: 2007-07-27
Posts: 88
Rep Power: 2
desperado618 has an average reputation (10+)
Default Re: Critical Problem With Checkpoint

Is your http rule set to log? Try fw monitor from the command line. Also try tcpdump on the ingress interface to confirm that the packets are reaching the firewall. If you ahve a large rulebase, ass a temporary rule to all your traffic at the very top of the rulebase. If your access then works, you need to locate the rule below that , this is not set to log, that is blocking your traffic.

Netleets.com IT Security news
IT Security news and information.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 07:04.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0