CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've already had our first sign-ups!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Content Security/Security Servers/CVP/UFP
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-11
bac26 bac26 is offline
Junior Member
 
Join Date: 2005-10-07
Posts: 3
bac26 has an average reputation (10+)
Default HTTPS AND WEBSENSE

Does anyone know how to filter and check https traffic with websense? without using security server ? so shold be transparent without need to configure browser proxy settings on client
Reply With Quote
  #2 (permalink)  
Old 2007-10-11
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 131
Danielpb has an average reputation (10+)
Default Re: HTTPS AND WEBSENSE

You will need to setup a OPSEC application (UFP) then create a resource object.

This should then allow you to add the recourse in the rulebase.

One thing.....you can sometimes get a few issues with this. i.e. memory issues etc, depends how node will using the web.

Hope this helps.
Reply With Quote
  #3 (permalink)  
Old 2007-10-12
gavvys gavvys is offline
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 127
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: HTTPS AND WEBSENSE

Hi
Well if you have integrated the Websense with Cehckpoint you can only apply policies on HTTP traffic but if you want control non-http traffic then you need to go for Port Spanning.
Process goes like this:If you have manageable switch, I mean if you can run port-spanning commands on switch then you can attach one more NIC in websense server and keep that NIC in stealth mode(NO ip on that NIC)and conenct the calble from that NIC to the same switch.Now run the port spanning commands, source as the Firewall port and Destination as the Stealth mode NIC port.Regarding the settings in websense, Open the Network Agent setting, monitor the traffic with stealth mode NIC and use another NIC to through the block page.
I hope this will help you.
In case you need any help please let me know.

Regards
Ranjit
Reply With Quote
  #4 (permalink)  
Old 2007-10-12
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 804
mcnallym has an average reputation (10+)
Default Re: HTTPS AND WEBSENSE

Personally I would use the Websense in Network Agent Mode and place the Websense on a hub between the Firewall and the Internal Network Switch.

This way all web traffic is seen by the Websense as it leaves the network and is completely tranparent to the network. If the Websense see's traffic that should not be allowed then the Websense sends a reset to the requester that blocks the traffic. If it is non-Web traffic, ie SMTP then Websense ignores it.

It also removes the need to configure anything on the firewall and the Websense reporting is far superior to what you would get regarding Check Point resource.

ie, no resource, no fiddling with the rules to redirect the http and https to the Websense Server, it allows the firewall cpu,memory resources to be used for the Firewall rather then being taken up interacting with the Websense.
Reply With Quote
  #5 (permalink)  
Old 2007-10-12
bac26 bac26 is offline
Junior Member
 
Join Date: 2005-10-07
Posts: 3
bac26 has an average reputation (10+)
Default Re: HTTPS AND WEBSENSE

Hi,
add resource on the rulebase with https but than the traffic is not even allow i have error in display the pages
Reply With Quote
  #6 (permalink)  
Old 2007-10-12
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 804
mcnallym has an average reputation (10+)
Default Re: HTTPS AND WEBSENSE

Do you have rules that allow the Check Point and Websense to talk to each other. Websense will be looking for traffic on a port that is not a pre-defined service. I can't remember off the top of my head by the Websense Documentation should tell you.

I believe that it is listed on the Check Point Integration guide what the services are. If you don't have this then I suggest that you get a copy from the Websense website. It is publicly available and doesn't require a login.
Reply With Quote
  #7 (permalink)  
Old 2007-10-12
bac26 bac26 is offline
Junior Member
 
Join Date: 2005-10-07
Posts: 3
bac26 has an average reputation (10+)
Default Re: HTTPS AND WEBSENSE

hi,
i have already communication , is set to clear...
Reply With Quote
  #8 (permalink)  
Old 2007-10-28
JohnMH JohnMH is offline
Member
 
Join Date: 2006-07-15
Posts: 68
JohnMH has an average reputation (10+)
Default Re: HTTPS AND WEBSENSE

I have checkpoint blocking http with one rule (using UFP)
Then have checkpoint allowing https with one rule (using UFP)

The rules have to be reversed with HTPS, but it works fine.

We can't use a hub, it's way too slow...

John
Reply With Quote
  #9 (permalink)  
Old 2007-10-28
gavvys gavvys is offline
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 127
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: HTTPS AND WEBSENSE

Hi
I would like to give you one advice.See if we put the websense server in flow of the traffic it will make the traffic slow and create one more hop.So alternative to this is to, to monitor the traffic using port spanning.Run the port spanning commnads on a manageable switch and insert two LAN cards in Websense server, one for listening and another for pushing the page, then it will not come into the floe it will jist sniff the traffic and policy will be applied according to the needs.

I hope this will help you.
Regards
Ranjit
Reply With Quote
  #10 (permalink)  
Old 2007-10-30
Producer Producer is offline
Junior Member
 
Join Date: 2006-02-23
Location: Cape Cod, MA
Posts: 14
Producer has an average reputation (10+)
Default Re: HTTPS AND WEBSENSE

Quote:
Originally Posted by mcnallym View Post
Personally I would use the Websense in Network Agent Mode and place the Websense on a hub between the Firewall and the Internal Network Switch.
+1

performance is much better then UFP. Been through this many, many times, even with websense 6.3. I think if you have less then 10 mb to the internet, then the UFP would be comparable to the Agent mode. But when you start having 4,000+ clients browsing the internet, the websense box (and checkpoint) takes a huge performace hit in UFP mode.

FYI; Use a GB cisco switch with SPAN commands instead of a hub.
__________________
-Bradley
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:57.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0