CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-11-16
Junior Member
 
Join Date: 2006-11-16
Posts: 4
Rep Power: 0
peterkycheung has an average reputation (10+)
Default Disable port opened on CP NGX.....security server

Hi All,

Find the checkpoint NGX have list of tcp port opened from 1035 to 1042, 1071....etc. Tried to telnet to the port and got some banners like

"220 Check Point Firewall-1 Secure FTP server running on xxx"
"Check Point Firewall-1 authenticated Telnet server running on xxx"
"Check Point Firewall-1 authenticated RLogin server running on xxx"

I think it is the security server feature opened the port but checked the firewall and find didn't enable these feature before.

Any idea on how to disable them?

thanks in advace..

..peter
Reply With Quote
  #2 (permalink)  
Old 2006-11-17
Senior Member
 
Join Date: 2006-07-10
Posts: 164
Rep Power: 3
Porter has an average reputation (10+)
Default Re: Disable port opened on CP NGX.....security server

just create a rule that disallows to connect to those service(s) e.g. telnet auth

sourcy:any dest:gw service:FW1_clntauth_telnet action drop

set the rule(s) at the top of your ruleset
__________________
misery is optional
Reply With Quote
  #3 (permalink)  
Old 2006-11-17
Senior Member
 
Join Date: 2006-10-05
Location: Belgium
Posts: 108
Rep Power: 3
Robby Cauwerts has an average reputation (10+)
Default Re: Disable port opened on CP NGX.....security server

Even better, reject/drop *all* traffic to your firewall and only allow connections to your firewall if they are really necessary.
Reply With Quote
  #4 (permalink)  
Old 2006-11-17
Senior Member
 
Join Date: 2006-07-10
Posts: 164
Rep Power: 3
Porter has an average reputation (10+)
Default Re: Disable port opened on CP NGX.....security server

Quote:
Even better, reject/drop *all* traffic to your firewall and only allow connections to your firewall if they are really necessary.
even better:

edit fwauthd.conf in $FWDIR/conf, locate the ports you want to remove e.g. 259 and remove the entire line, run cpstop, cpstart and service is gone
__________________
misery is optional

Last edited by Porter; 2006-11-17 at 03:21.
Reply With Quote
  #5 (permalink)  
Old 2006-11-20
Junior Member
 
Join Date: 2006-11-16
Posts: 4
Rep Power: 0
peterkycheung has an average reputation (10+)
Default Re: Disable port opened on CP NGX.....security server

Hi,

Create rule can block the traffic, however the port still in listen mode. So i prefer ways to stop the unnecessary process.

the fwauthd.conf (see below) only have very little port , I can't find those port 1038......1042.


21 fwssd in.aftpd wait 0
80 fwssd in.ahttpd wait -4
513 fwssd in.arlogind wait 0
25 fwssd in.asmtpd wait 0
23 fwssd in.atelnetd wait 0
259 fwssd in.aclientd wait 259
10081 fwssd in.lhttpd wait 0
900 fwssd in.ahclientd wait 900
0 fwssd in.pingd respawn 0
0 fwssd in.asessiond respawn 0
0 fwssd in.aufpd respawn 0
0 vpn vpnd respawn 0
0 fwssd mdq respawn 0
0 stormd stormd respawn 0
0 sds sdsd respawn 0
0 dtps dtpsd respawn 0
0 dtls dtlsd respawn 0

rgds..

..peter
Reply With Quote
  #6 (permalink)  
Old 2006-11-23
Junior Member
 
Join Date: 2006-11-16
Posts: 4
Rep Power: 0
peterkycheung has an average reputation (10+)
Default Re: Disable port opened on CP NGX.....security server

hi expert,

any idea to disable the security server services?

thx.

..peter cheung
Reply With Quote
  #7 (permalink)  
Old 2006-11-24
Senior Member
 
Join Date: 2006-07-10
Posts: 164
Rep Power: 3
Porter has an average reputation (10+)
Default Re: Disable port opened on CP NGX.....security server

rlogin, secure ftp server are not started by default, only when you have rules where you're using resources somewhere in your ruleset
__________________
misery is optional
Reply With Quote
  #8 (permalink)  
Old 2006-11-27
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 3
Acidio has an average reputation (10+)
Default Re: Disable port opened on CP NGX.....security server

Have a look at the global properties, and disable all options. Then specify all specific ports you require in the policy rules.

NB: Ensure the rule(s) you create for the services you need are above the stealth rule.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 20:05.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0