| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| I have a question pertaining to a Client Auth rule. Say I have a client auth rule similar to below admins@any -> any via HTTP/HTTPS action client auth Do any rules that have either HTTP or HTTPS in the service field have to be above the client auth rule? It appears thats the way my firewall functions but I cant find any documentation detailing this behavior. If a rule with HTTP or HTTPS in the service field is below this client auth rule it is never met. I would like to find a way around this, because this causes a number of rules to have to go above my stealth rule, which I would like to avoid if possible. |
| |||
| Quote:
Quote:
At the very least make a seperate client auth for your stealth rule(s) so that the real client auth rule can go below and all your other rules can stay in place. __________________ Its all in the documentation. Last edited by melipla; 2007-03-15 at 08:17. |
| |||
| Quote:
Quote:
Thanks for your assistance. |
| |||
| I have always understood that Client Auth had to be above Stealth rules. This is what I have found in the Checkpoint documentation: Quote:
|
| |||
| erm...what to you mean by cl auth rules need to be above stealth rule? Only rules that needs to be above stealth rule is the actuall port 900 or 259 connection to the gateway. ACTUAL client auth rules don't have to be put before stealth. |
![]() |
| Thread Tools | |
| Display Modes | |
| |