| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hi All, Looking through our logs for last night. I saw an https request from and external address to our module (splat hfa04) and I saw it was accepted on rule 0. I have checked and I have only have accept smartupdate connections ticked and accept outgoing packets from gateway I did a https://module_hostname from my PC and I saw it get accepted on rule 0 again !? Nothing comes back (page not found). Any ideas where i should look cheers, George |
| |||
| Hello chillyjim, Thanks, we do use visitor mode. the ip in question was in Singapore we don't have anyone there, so I guess it may have been part of a port/sweep scan or just random stuff. Cheers, George |
| |||
| Access to that one isn't controlled by rule 0, that's why I didn't mention it. |
| |||
| That would produce "interesting" results on a Nokia gateway that uses SSL for the Voyager interface if it's still on port 443, since it binds to all interfaces... Ray |
| |||
| Hello All, The implied rules I can see are; Mngmt Server --> SVN Foundation --> FW1_CPID --> Accept LocalMachine --> ANY --> ANY --> Accept DshieldIP Block List --> ANY --> ANY --> Drop Cheers, George |
| |||
| Yep, which is why they tell you to switch Voyager/SPLAT's webUI to something else. |
| |||
| I must have missed that note in the tiny little NGX Upgrade Guide. :-) I would think a change in the implied rules to allow traffic that previously was not allowed would warrant a big, bold-faced note. George, where are you seeing this one? "LocalMachine --> ANY --> ANY --> Accept" If LocalMachine means "enforcement module", it kind of kills the stealth rule. Ray |
| |||
| Hi Ray, The LocalMachine and the Dshield implied rules are at the very bottom of the rule base. The LocalMachine rule goes away if in global properties I uncheck 'accept outgoing packets originating from gateway' If I uncheck it the dshield implied rule moves to the top as the second implied rule after the Management Server/SVN Foundation rule my webgui port is not running on 443 Thanks mate, George |
![]() |
| Thread Tools | |
| Display Modes | |
| |