CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-01
nairsunil7 nairsunil7 is offline
Junior Member
 
Join Date: 2006-05-03
Posts: 21
Rep Power: 0
nairsunil7 has an average reputation (10+)
Default How to Block Yahoo.com, Google.com?

Hi Grp,

Pls tell me how I can block certain sites completely like Yahoo.com(it should block yahoo.co.uk, yahoo.co.in etc). Since there will be more than 50 servers for these web sites, how I can block these sites without kbowing the ip address?

Thanks in Advance,

Sunil
Reply With Quote
  #2 (permalink)  
Old 2006-10-01
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 776
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: How to Block Yahoo.com, Google.com?

Three options here, ranked best to worst, in my opinion:

* Don't allow any systems direct access to anything on the Internet. Use a proxy server, force all systems to go via that proxy server. Either use URL filtering software, or configure DNS for your proxy server to send requests to google, yahoo to 127.0.0.1. This is far and away the most secure option, and gives you reasonably good control over the types of sites that staff can access, and perhaps more importantly, gives you reporting.

* Control DNS for all clients, and put blackholes in for those domains on your own, locally controlled, DNS servers. Don't let clients do DNS lookups to anyone else.

* Use domain objects. I would strongly advise against this though, as many people have reported problems with these.

Think carefully about what you are trying to achieve. What's the point in blocking access to a couple of search engines? Why on earth would you want staff to have Internet access, but not access to the most widely used search engine? What's the point? Where's the risk/benefit analysis? So you block access to google.com - big deal, I'll just use ask.com, or alltheweb.com, or altavista.com, or....

Or maybe I'll just use one of the anonymous proxies that are out there.

Think carefully about what you are trying to achieve, and do a proper risk/benefit analysis of the situation, and do a cost/benefit analysis of your proposed solution. Don't just put in a knee-jerk "block all access to google quick!" solution.
Reply With Quote
  #3 (permalink)  
Old 2006-10-04
nairsunil7 nairsunil7 is offline
Junior Member
 
Join Date: 2006-05-03
Posts: 21
Rep Power: 0
nairsunil7 has an average reputation (10+)
Default Re: How to Block Yahoo.com, Google.com?

Hi,

Thanks for the detailed reply. I just put google.com as an example, my requirement is to block some other sites.

I tried with domain object, I could able to block cisco.com and wipro.com, but Yahoo is still coming. I don't know why?

Thanks once again,

Sunil
Reply With Quote
  #4 (permalink)  
Old 2006-10-04
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: How to Block Yahoo.com, Google.com?

northlandboy is right, better don't use domain objects.
May be better to use URI resource than domain object?
But decision with DNS is more elegant if you don't use proxy.
Reply With Quote
  #5 (permalink)  
Old 2006-10-04
nairsunil7 nairsunil7 is offline
Junior Member
 
Join Date: 2006-05-03
Posts: 21
Rep Power: 0
nairsunil7 has an average reputation (10+)
Default Re: How to Block Yahoo.com, Google.com?

Hi Grp,

Thanks for the valuabale input.

Regards,

Sunil
Reply With Quote
  #6 (permalink)  
Old 2006-10-05
stuartgreen stuartgreen is offline
Member
 
Join Date: 2005-09-15
Posts: 65
Rep Power: 3
stuartgreen has an average reputation (10+)
Default Re: How to Block Yahoo.com, Google.com?

i've seen problems with domain objects where there is an alias in the DNS record which some clients seem to resolve when the main / primary IP address cannot be resolved. The other problem with domain objects is the processing overhead. If you have a large amount of domain objects it will slow things down a fair bit while each is being resolved. I'd agree with northlandboy, get a dedicated web filtering solution. While check point does offer this as a feature - don't mistake it for a fully singing and dancing proxy!
Reply With Quote
  #7 (permalink)  
Old 2006-10-05
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 442
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: How to Block Yahoo.com, Google.com?

as mentioned above block it with uri resource. Dont know anything about your network but good to know is that resource rules do have negative impact on performance but in "most" cases it should be fine. In the resource object you can match on host path etc..
Reply With Quote
  #8 (permalink)  
Old 2007-02-22
Acidio Acidio is offline
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 2
Acidio has an average reputation (10+)
Default Re: How to Block Yahoo.com, Google.com?

Smart Defense allows you to block domains - essentially blocks DNS lookups for the banned domains. Seems to work OK.

As Northland boy has mentioned, using domain objects in the rule will most likely casue problems.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:33.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0