CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-11-17
Member
 
Join Date: 2006-10-07
Posts: 33
Rep Power: 0
brierw has an average reputation (10+)
Default Command Line

Hello,

I am looking for the syntax at the command line to block an individual IP on an R60 Checkpoint Cluster. Anyone help me out with this?

We have Nokia's clustered running Checkpoint R60
Reply With Quote
  #2 (permalink)  
Old 2008-11-17
Member
 
Join Date: 2008-03-15
Location: Mumbai
Posts: 94
Rep Power: 1
amol0009in_7 has an average reputation (10+)
Send a message via Yahoo to amol0009in_7
Default Re: Command Line

I think u can use Smartdefense if you are already using it.
Or more simple
create access list and apply
Reply With Quote
  #3 (permalink)  
Old 2008-11-17
Member
 
Join Date: 2006-10-07
Posts: 33
Rep Power: 0
brierw has an average reputation (10+)
Default Re: Command Line

I was looking to see if there was a Checkpoint or IPSO way to block at the command line an individual IP. It would likely be easier to block at the command line in the event we were getting attacked and the respurces were high on the firewalls. :)
Reply With Quote
  #4 (permalink)  
Old 2008-11-17
Senior Member
 
Join Date: 2006-01-25
Posts: 1,004
Rep Power: 4
melipla has an average reputation (10+)
Default Re: Command Line

This command line should be able to do it "fw sam":

Quote:
# fw sam
Usage:
sam [-v] [-s <sam server>] [-S <server sic name>] [-f <fw host>][-t <timeout>] [-l <log>] [-C] [-e <key=val>]+ -{n|i|I|j|J} <criteria>

sam [-v] [-s <sam server>] [-S <server sic name>] [-f <fw host>] -M -ijnbq {<criteria> | all}

sam [-v] [-s <sam server>] [-S <server sic name>] [-f <fw host>] -D

Options:
-C: Cancel
-M: Monitor
-D: Delete all
-v: Verbose
-s: Server for connection
-S: SIC name of server
-f: Name of target host/group
-t: Timeout in seconds
-l: Either nolog, long_noalert or long_alert
-e: Rule information. Keys are: name, comment and originator
-i: Reject
-I: Reject and close
-j: Drop
-J: Drop and close
-n: Notify

Criteria:
src <ip>
dst <ip>
any <ip>
subsrc <ip> <net mask>
subdst <ip> <net mask>
subany <ip> <net mask>
srcdst <src ip> <dst ip>
srv <src ip> <dst ip> <service> <protocol>
subsrv <src ip> <net mask> <dst ip> <net mask> <service> <protocol>
subsrvs <src ip> <net mask> <dst ip> <service> <protocol>
subsrvd <src ip> <dst ip> <net mask> <service> <protocol>
srvpr <service> <protocol>
srcsrv <src ip> <service> <protocol>
dstsrv <dst ip> <service> <protocol>
subdstsrv <dst ip> <net mask> <service> <protocol>
srcpr <ip> <protocol>
dstpr <ip> <protocol>
subsrcpr <ip> <net mask> <protocol>
subdstpr <ip> <net mask> <protocol>
generic <key=val>+
#
If I remember correctly, if you don't specify a firewall host, it will attempt to apply the SAM (suspicious activity monitoring) to every firewall.
__________________
Its all in the documentation.
Reply With Quote
  #5 (permalink)  
Old 2008-11-18
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 158
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: Command Line

This will be in addition to the existing rule base or will replace that ?
Reply With Quote
  #6 (permalink)  
Old 2008-11-18
Senior Member
 
Join Date: 2007-07-16
Posts: 687
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Command Line

Quote:
Originally Posted by vijayant View Post
This will be in addition to the existing rule base or will replace that ?
In addition. IIRC, SAM rules are processed before the rulebase (rule 0, essentially).
Reply With Quote
  #7 (permalink)  
Old 2008-11-24
Junior Member
 
Join Date: 2006-10-25
Posts: 16
Rep Power: 0
MoreBeer has an average reputation (10+)
Default Re: Command Line

I always loved blackhole routing problem children in the past. fw sam seems to work a lot better than it did in 4.1/NG however.
Reply With Quote
  #8 (permalink)  
Old 2008-12-01
Senior Member
 
Join Date: 2006-03-08
Posts: 122
Rep Power: 3
varera has an average reputation (10+)
Default Re: Command Line

just my $0.05

use "fw sam..." with caution. you don't see the rules it makes in the rulebase, and you have to know you need to go to SVM to see them.

use the command with logging option, it will help with further troubleshooting.
__________________
-------------
Sincerely,
Valeri Loukine
CCMA-0019
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:17.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0