CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Content Security/Security Servers/CVP/UFP
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-14
roadrunner roadrunner is offline
Senior Member
 
Join Date: 2005-08-12
Posts: 162
Rep Power: 3
roadrunner has an average reputation (10+)
Default Redirecting Restricted Users or Websites

Redirecting Restricted Users or Websites
If you want to restrict some IPs from accessing websites at all, set up a rule like this where the "matchall" resource used below is set up per LogWebandFTPFiles. In the "Replacement URL" field, put in the URL that they should be redirected to.

Source Destination Service Action Track
restricted-hosts any http->matchall Reject Long


To restrict access to certain sites only, you can do one of two things:


Create a resource that matches the sites you don't want to allow access to. Use this resource in a rule as shown above.
Create a resource that matches the sites you want to allow access to. If you wish to then redirect them to a policy page if they access a page they are not allowed to, use the "matchall" resource and set the replacement URL accordingly. Should you wish to allow them access to only the sites matched by the resource "allowedsites" and deny access to everything else (via a "matchall" resource), the rules would look like this:
Source Destination Service Action Track
internal-users any http->allowedsites Accept Long
internal-users any http->matchall Reject Long


Note: If you are using this in conjunction with User Authentication and a user is "redirected" to a policy page, they will get FireWall?-1's Authentication Failed page with a link to the "redirected" page.

-- PhoneBoy - 30 Dec 2003


FAQForm
FAQs.Class: AuthenticationFAQs
OperatingSystem?:
FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:54.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0