CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Content Security/Security Servers/CVP/UFP
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-30
mumbly mumbly is offline
Junior Member
 
Join Date: 2007-01-26
Posts: 2
Rep Power: 0
mumbly has an average reputation (10+)
Default URI ressource on http proxy service 8080?

My PC are on a secured lan, separated from the site lan by a fw-1 (ngx R60)
IE (on the secured lan) is set so that it uses an http proxy (8080) on the site lan (on the other side of the firewall).

I try to add a rule on fw-1 (ngx R60) so that it filters URI on 8080.

URI filtering works well when the service is on 80 (when IE doesn't use proxy).

If I just change the service port to 8080, and keep the same rule and same URI ressource, then it doesn't work ( IE set to use the proxy).
In this last case, there are no logs in the FW , and IE gets an 'this page cannot be displayed message').

If I use the same service (on 8080), but without a ressource, then it works (but of course, there is not uri filtering...).

Do you know if URI filtering can be done on a port 8080? And if yes, how?
Reply With Quote
  #2 (permalink)  
Old 2007-03-06
manfred.huels manfred.huels is offline
Junior Member
 
Join Date: 2006-11-07
Location: Germany, Münster
Posts: 4
Rep Power: 0
manfred.huels has an average reputation (10+)
Send a message via Yahoo to manfred.huels
Default Re: URI ressource on http proxy service 8080?

Did you configured
$FWDIR/conf/fwauthd.conf,
where the Proxyserviceports are defined?
Reply With Quote
  #3 (permalink)  
Old 2007-04-05
mumbly mumbly is offline
Junior Member
 
Join Date: 2007-01-26
Posts: 2
Rep Power: 0
mumbly has an average reputation (10+)
Default Re: URI ressource on http proxy service 8080?

Thanks for you idea. I tried what you proposed but it's still not OK. However, our support has discovered that the HF5 patch could solve the pbm. We didn't update to HF5 yet, but it should solve the following pbm:

R60_05-21
Product: FireWall-1
Category: Security Servers
Problem: Non-RFC reply received in response to CONNECT request
connecting to the security server as a Proxy (URI resource).
Cause: The word "OK" is missing in the reply.
Resolution: Correct the security server response to a connect request.
Install On: Gateway
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:21.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0