CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Interoperability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-08-06
Junior Member
 
Join Date: 2007-08-03
Posts: 6
Rep Power: 0
willmac has an average reputation (10+)
Default OSE with Cisco routers

I cannot seem to find much on the checkpoint website - but can checkpoint be used to control acls on cisco routers?
If so how effective is it?
Reply With Quote
  #2 (permalink)  
Old 2007-08-09
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: OSE with Cisco routers

you really want to do this? It's like putting a yugo engine into
a Acurra NSX race car.
Reply With Quote
  #3 (permalink)  
Old 2007-08-09
Senior Member
 
Join Date: 2006-01-25
Posts: 895
Rep Power: 3
melipla has an average reputation (10+)
Default Re: OSE with Cisco routers

Centralized management. Need I say more?
Reply With Quote
  #4 (permalink)  
Old 2007-08-10
Junior Member
 
Join Date: 2007-08-03
Posts: 6
Rep Power: 0
willmac has an average reputation (10+)
Default Re: OSE with Cisco routers

I am looking a many options - but as melipla says it is an option to keep security policies in sync.
Anyway why would the method of ACL deployment affect performance - surely it's just about the amount of ACLS?
Reply With Quote
  #5 (permalink)  
Old 2007-08-19
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,662
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: OSE with Cisco routers

It doesn't affect performance. I have to assume the yugo here is the router and not the Check Point.

As for the question, it works with in its limitation. VMS or whatever its called now, is probably a little more flexible but unless Cisco has changed it, it tends to write ACLs that no one can understand.

I at one point had a customer with a Management Module (predisesor to SmartCenter) who was running nothing but OSEs to manage several 100's of routers and PIXen. The PIX/ASA isn't supported any more though.
Reply With Quote
  #6 (permalink)  
Old 2007-08-22
Senior Member
 
Join Date: 2006-09-26
Posts: 804
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: OSE with Cisco routers

Cisco VMS (VPN Management Server) is a piece of sh_t.
Cisco has re-branded a new product called Cisco
Security Manager (CSM) which is an enhanced product
of VMS. CSM is another piece of sh_t.

The point I am trying to make here is that Checkpoint
SmartCenter or CMA is designed to manage
Checkpoint products (InterSpect, Firewall, Connectra, etc...)
Checkpoint SmartCenter or CMA is NOT designed to
manage Cisco Pix/ASA or IOS routers. Cisco and
Checkpoint are competitiors and checkpoint will NOT
design a product to help cisco manage its security
device and vice versa. Checkpoint is a security
company while cisco is NOT. There will always a "lag"
behind for SmartCenter or CMAs to support the latest
revision of either IOS or Pix/ASA code. Last but
not least, use it at your own risk.

If I have to pick a product to manage cisco security
devices, Solsoft seems to be the best product out
there at this time. Solsoft still sucks but it is
better than both VMS and CSM combined.
Reply With Quote
  #7 (permalink)  
Old 2007-08-23
Junior Member
 
Join Date: 2007-08-03
Posts: 6
Rep Power: 0
willmac has an average reputation (10+)
Default Re: OSE with Cisco routers

Thanks for the advice on Solsoft I will take a look.

But whilst I agree Cisco will never help with checkpoint the other way round is always a possibility.

Checkpoint are a software company and do not deal in routing and layer 3.
The software uses the underlying operating system whether it be linux , nokia or windows.
So they are not in competion with Cisco for routing and realise a large proportion of their client base use Cisco routers.


So although for us the first answer is to look at Cisco products for ACLs - checkpoint is still worth a look.
Being able to apply polcies from the same security interface and even review log through the tracker maybe of some benefit.

I take the point about tha lag in the latest code revisons - but this would probably be the case for any vendor other than Cisco.

Also in a large scale environment turn around in upgrading IOS is not fast and generally there is a delay anyway with product revision testing and waiting for any bugs/flaws to be spotted and fixed first anyway.
Reply With Quote
  #8 (permalink)  
Old 2007-08-28
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,662
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: OSE with Cisco routers

H*ll Cisco's management lags its IOS :)

OSE is a solution, though there are likely better ones out there.
I don't see a lot of OSE in the field, so I would doubt there is a lot of development effort on it.

As for logs, SmartCenter can take in SYSLOG and Eventia can even alert on Cisco events.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 07:25.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0