CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-23
HomiD HomiD is offline
Junior Member
 
Join Date: 2007-01-17
Posts: 16
Rep Power: 0
HomiD has an average reputation (10+)
Default Disable Implied Rule

I am running NGX R60, need to know how to disable implied rule 0

Thanks.
Reply With Quote
  #2 (permalink)  
Old 2007-02-23
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Disable Implied Rule

Look at Global Properties -> Firewall
Reply With Quote
  #3 (permalink)  
Old 2007-02-23
HomiD HomiD is offline
Junior Member
 
Join Date: 2007-01-17
Posts: 16
Rep Power: 0
HomiD has an average reputation (10+)
Default Re: Disable Implied Rule

Which option in there please?
Reply With Quote
  #4 (permalink)  
Old 2007-02-23
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 862
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Disable Implied Rule

Every single implied rule shows up under the single number of zero. Disabling the implied rules will break a lot of things if you have not manually created the needed rules to replace them.

Ray
Reply With Quote
  #5 (permalink)  
Old 2007-02-24
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Disable Implied Rule

RayPesek is right. There are some implied rules for CP. They need to different purposes.
Why do you want to disable implied rules?
Reply With Quote
  #6 (permalink)  
Old 2007-02-26
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Disable Implied Rule

Ray and kva already said it, but in case you need a 3rd opinion...

If you don't know Check Point pretty well, don't disable the implied rules, especially the top 4 tick boxes.

They exist and are ticked for a reason, they allow vital Check Point connections, you can lock yourself out, lose connectivity between modules, etc.
Reply With Quote
  #7 (permalink)  
Old 2007-02-28
HomiD HomiD is offline
Junior Member
 
Join Date: 2007-01-17
Posts: 16
Rep Power: 0
HomiD has an average reputation (10+)
Default Re: Disable Implied Rule

"Accept Outgoing Packets Originating from Gateway"

This is what I want to disable. Dont know what its going to break. I'm scared...LOL
Reply With Quote
  #8 (permalink)  
Old 2007-02-28
HomiD HomiD is offline
Junior Member
 
Join Date: 2007-01-17
Posts: 16
Rep Power: 0
HomiD has an average reputation (10+)
Default Re: Disable Implied Rule

What is the purpose of this UDP_All_Ports in this VPN Tunnel?

Number: 3522675
Date: 28Feb2007
Time: 16:54:12
Product: VPN-1 Pro/Express
Interface: eth-s1p2c0
Origin: myfirewall
Type: Log
Action: Drop
Protocol: udp
Service: UDP_All_Ports (33524)Source: myfirewall
Destination: Ext_Peer
Rule: 4
Current Rule Number: 4-Houston2_20061205
Rule UID: {1A5BCE10-5B11-4803-9D27-45DDB8097F58}
Rule Name: Implied Rules Outbound
Source Port: 36998
Encryption Scheme: IKE
VPN Peer Gateway: Ext_Peer
Encryption Methods: ESP: 3DES + MD5 + PFS
Community: EXT-Extranet
Subproduct: VPN
VPN Feature: VPN
Information: service_id: UDP_All_Ports
encryption fail reason: Packet is dropped because there is no valid SA - please refer to solution sk19423 in SecureKnowledge Database for more information
Reply With Quote
  #9 (permalink)  
Old 2007-02-28
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 862
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Disable Implied Rule

Quote:
Originally Posted by HomiD View Post
"Accept Outgoing Packets Originating from Gateway"

This is what I want to disable. Dont know what its going to break. I'm scared...LOL
What does SmartView Tracker show for source=gateway? Seems to me I had to enable this for Edge management, but I am not sure.

Ray
Reply With Quote
  #10 (permalink)  
Old 2007-02-28
HomiD HomiD is offline
Junior Member
 
Join Date: 2007-01-17
Posts: 16
Rep Power: 0
HomiD has an average reputation (10+)
Default Re: Disable Implied Rule

Shows my firewall's external IP address for source and origin.
Reply With Quote
  #11 (permalink)  
Old 2007-02-28
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 862
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Disable Implied Rule

What services and destinations?

Ray
Reply With Quote
  #12 (permalink)  
Old 2007-03-01
HomiD HomiD is offline
Junior Member
 
Join Date: 2007-01-17
Posts: 16
Rep Power: 0
HomiD has an average reputation (10+)
Default Re: Disable Implied Rule

Service: UDP_All_Ports (33524)
Source: myfirewall
Destination: Ext_Peer firewall's IP
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:01.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0