CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-19
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 72
Rep Power: 4
gfont96 has an average reputation (10+)
Default More Strangeness !

Hi All,

Looking through our logs for last night. I saw an https request from and external address to our module (splat hfa04) and I saw it was accepted on rule 0.

I have checked and I have only have accept smartupdate connections ticked and accept outgoing packets from gateway

I did a https://module_hostname from my PC and I saw it get accepted on rule 0 again !?

Nothing comes back (page not found). Any ideas where i should look

cheers,

George
Reply With Quote
  #2 (permalink)  
Old 2007-01-19
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: More Strangeness !

This could be visitor mode and/or SNX as they both look like https going to the gateway.
Reply With Quote
  #3 (permalink)  
Old 2007-01-19
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 72
Rep Power: 4
gfont96 has an average reputation (10+)
Default Re: More Strangeness !

Hello chillyjim,

Thanks, we do use visitor mode.

the ip in question was in Singapore we don't have anyone there, so I guess it may have been part of a port/sweep scan or just random stuff.

Cheers,

George
Reply With Quote
  #4 (permalink)  
Old 2007-01-19
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 836
Rep Power: 3
melipla has an average reputation (10+)
Default Re: More Strangeness !

Quote:
Originally Posted by chillyjim View Post
This could be visitor mode and/or SNX as they both look like https going to the gateway.
What's SNX?
__________________
Its all in the documentation.
Reply With Quote
  #5 (permalink)  
Old 2007-01-19
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 808
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: More Strangeness !

SSL Network Extender. Clientless VPN.

Last edited by northlandboy; 2007-01-19 at 09:52. Reason: Tyop
Reply With Quote
  #6 (permalink)  
Old 2007-01-19
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 836
Rep Power: 3
melipla has an average reputation (10+)
Default Re: More Strangeness !

Ah thanks :)

Also, Check Point's Web UI defaults to port 443...
__________________
Its all in the documentation.
Reply With Quote
  #7 (permalink)  
Old 2007-01-20
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: More Strangeness !

Quote:
Originally Posted by melipla View Post
Ah thanks :)

Also, Check Point's Web UI defaults to port 443...
Access to that one isn't controlled by rule 0, that's why I didn't mention it.
Reply With Quote
  #8 (permalink)  
Old 2007-01-20
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 891
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: More Strangeness !

Is HTTPS in the implied rules for NGX if Visitor Mode is active? It's not for R55. You have to set a rule in the security policy on R55.

Ray
Reply With Quote
  #9 (permalink)  
Old 2007-01-21
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: More Strangeness !

I'm pretty sure it is. I'll have to check that nest time I'm in the lab
Reply With Quote
  #10 (permalink)  
Old 2007-01-21
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 891
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: More Strangeness !

That would produce "interesting" results on a Nokia gateway that uses SSL for the Voyager interface if it's still on port 443, since it binds to all interfaces...

Ray
Reply With Quote
  #11 (permalink)  
Old 2007-01-22
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 72
Rep Power: 4
gfont96 has an average reputation (10+)
Default Re: More Strangeness !

Hello All,

The implied rules I can see are;

Mngmt Server --> SVN Foundation --> FW1_CPID --> Accept
LocalMachine --> ANY --> ANY --> Accept
DshieldIP Block List --> ANY --> ANY --> Drop

Cheers,

George
Reply With Quote
  #12 (permalink)  
Old 2007-01-22
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 808
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: More Strangeness !

Quote:
Originally Posted by RayPesek View Post
That would produce "interesting" results on a Nokia gateway that uses SSL for the Voyager interface if it's still on port 443, since it binds to all interfaces...

Ray
Yep, which is why they tell you to switch Voyager/SPLAT's webUI to something else.
Reply With Quote
  #13 (permalink)  
Old 2007-01-22
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 891
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: More Strangeness !

I must have missed that note in the tiny little NGX Upgrade Guide. :-)

I would think a change in the implied rules to allow traffic that previously was not allowed would warrant a big, bold-faced note.


George, where are you seeing this one?

"LocalMachine --> ANY --> ANY --> Accept"

If LocalMachine means "enforcement module", it kind of kills the stealth rule.

Ray
Reply With Quote
  #14 (permalink)  
Old 2007-01-23
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 72
Rep Power: 4
gfont96 has an average reputation (10+)
Default Re: More Strangeness !

Hi Ray,

The LocalMachine and the Dshield implied rules are at the very bottom of the rule base.

The LocalMachine rule goes away if in global properties I uncheck 'accept outgoing packets originating from gateway'

If I uncheck it the dshield implied rule moves to the top as the second implied rule after the Management Server/SVN Foundation rule

my webgui port is not running on 443

Thanks mate,

George
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:26.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0