CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-12-11
justmcin justmcin is offline
Junior Member
 
Join Date: 2006-12-11
Posts: 6
Rep Power: 0
justmcin has an average reputation (10+)
Default replacing implicit rules with explicit ones

I'm currently going through my rulebases and either removing the implicit rules, or replacing them with explicit ones. My question is what is the best way to replace a implicit object with a defined explicit object. For example, one implicit object is simply "FW1 Host", which isn't a actual object available for explicit rules. Would I just list every firewall object in an explicit rule to cover this?

Another good example is a implicit object of "ftp server". How could I create a explicit rule covering this if I don't have a list of ftp server IPs?
Reply With Quote
  #2 (permalink)  
Old 2006-12-12
stephan411 stephan411 is offline
Member
 
Join Date: 2006-02-17
Posts: 69
Rep Power: 3
stephan411 has an average reputation (10+)
Default Re: replacing implicit rules with explicit ones

Hallo,

why do you want to do this?

Best Regards
Stephan
Reply With Quote
  #3 (permalink)  
Old 2006-12-12
justmcin justmcin is offline
Junior Member
 
Join Date: 2006-12-11
Posts: 6
Rep Power: 0
justmcin has an average reputation (10+)
Default Re: replacing implicit rules with explicit ones

I don't want to do it at all, but I have to - just following orders from folks higher up the ladder. Regardless of why or how stupid it may be, I still have to do it. Any thoughts on the best, least painful way?
Reply With Quote
  #4 (permalink)  
Old 2006-12-12
Acidio Acidio is offline
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 2
Acidio has an average reputation (10+)
Default Re: replacing implicit rules with explicit ones

Disabling the implied rules and explicitly defining only what is required is good security practice in my view. It does however require a good understanding of your Check Point infrastructure. Some of the implied rules you may not need. You'll need to go through step by step and indentify what breaks as a result of the changes. Obviously this is a 'brute force' approach, so doing it this way will require careful consideration.
Reply With Quote
  #5 (permalink)  
Old 2006-12-13
justmcin justmcin is offline
Junior Member
 
Join Date: 2006-12-11
Posts: 6
Rep Power: 0
justmcin has an average reputation (10+)
Default Re: replacing implicit rules with explicit ones

Is there a way in Checkpoint 4.0 to log the implicit rules? I know its an option in 4.1 and above.
Reply With Quote
  #6 (permalink)  
Old 2006-12-13
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,627
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: replacing implicit rules with explicit ones

Quote:
Originally Posted by justmcin View Post
Is there a way in Checkpoint 4.0 to log the implicit rules? I know its an option in 4.1 and above.
I don't remember there being any way to.

You do know that 4.0 & 4.1 for that matter are past end-of-support? NG is the oldest that is supported at this point (FCS-FP3 go off support in June).
Reply With Quote
  #7 (permalink)  
Old 2006-12-13
justmcin justmcin is offline
Junior Member
 
Join Date: 2006-12-11
Posts: 6
Rep Power: 0
justmcin has an average reputation (10+)
Default Re: replacing implicit rules with explicit ones

Yeah I know 4.0 is EOL, but odds are we're stuck with 4.0 on a few legacy firewalls for a while.
Reply With Quote
  #8 (permalink)  
Old 2006-12-18
Acidio Acidio is offline
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 2
Acidio has an average reputation (10+)
Default Re: replacing implicit rules with explicit ones

There probably is a way, however it's most likely buried in a config file somewhere. The only other way to do it would be to define the rules manually and disabled the implied rules.

Have just had a look through a 4.0 CCSA training manual and there was no mention of a way to log the implied rules.
Reply With Quote
  #9 (permalink)  
Old 2006-12-18
justmcin justmcin is offline
Junior Member
 
Join Date: 2006-12-11
Posts: 6
Rep Power: 0
justmcin has an average reputation (10+)
Default Re: replacing implicit rules with explicit ones

Quote:
Originally Posted by Acidio View Post
The only other way to do it would be to define the rules manually and disabled the implied rules.
That would work for me, but my question is what is the best way to do that? In implied rules there are some pretty broad objects automatically created that aren't available for use in an explicit rule.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:27.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0