CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Content Security/Security Servers/CVP/UFP
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-27
shoenix shoenix is offline
Junior Member
 
Join Date: 2008-03-26
Posts: 1
Rep Power: 0
shoenix has an average reputation (10+)
Default FW1 and proxy usage

Hi,

I have been pulling my hairs on this for a few days now, so I hope someone here can help me prevent premature baldness.

I have a ClusterXL Firewall (NGX R65 on Splat). I also have a proxy server on port 8080 in the dmz.

What I want is to scan the traffic from the intranet to the proxy so I can use the inclusion/exclusion for the URL Filtering. This because when you use a proxy all scanned traffic originates from the proxy server and not the client station in the intranet.

I configured the CFW Cluster to use 'Next Proxy' to the proxy server 8080. Wierd thing is that I now must allow all internal hosts to connect to port 8080 everywhere because otherwise I get an 'Access Denied' screen. The weird thing is that when I connect to the proxy from the intranet, do a request (i.e. google), the firewall tries to do a request directly to the destination host google on port 8080 with the client source IP! When I do allow all internal host access to port 8080->any, all traffic is still routed through the proxy when I configure a proxy in the browsers. But when I try to connect to an internet host directly from the intranet on 8080 (so outside the proxy) it also allows my connection.

This is definitly not what I want. I also tried running the proxy on port 80, but then I get the same problems. I also tried to add port 8080 to the HTTP filter (as described by another thread here) but somehow that traffic is not passing the URL filter.

Can anyone shed a light on this ?

Regards,
Shoenix
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:15.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0