CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-22
pluto pluto is offline
Junior Member
 
Join Date: 2007-04-02
Posts: 7
Rep Power: 0
pluto has an average reputation (10+)
Default Help understanding Checkpoint

Hi there,

Looking for some help understanding the following as the checkpoint docs are not very clear and searching the posts im not convinced i have the answers to my questions:

1 - Am i correct in saying a packet is first checked for anti-spoofing the NAT and then Security and finally routing? There are no clear details on this. I have tried to use fw monitor but not clear from that either. I want to understand exactly what happens when a packet hit FW-1 and when it leave inlcuding the INSPECT process.

2 - Are there any guidelines as to how a solaris box should be built for a smartcentre or Provider-1 use?

3 - What advantages are there of using SPLAT over Nokia's?

4 - How do you apply HFA's to windows, SPLAT, Nokia and Solaris (modules and managers)

Sorry for the general questions... just trying to clear things in my head...

Thanks
Paul

Last edited by pluto; 2007-09-22 at 10:40.
Reply With Quote
  #2 (permalink)  
Old 2007-09-22
Bob_Zimmerman Bob_Zimmerman is offline
Junior Member
 
Join Date: 2007-03-30
Location: DFW, TX
Posts: 25
Rep Power: 0
Bob_Zimmerman has an average reputation (10+)
Send a message via AIM to Bob_Zimmerman
Default Re: Help understanding Checkpoint

Quote:
Originally Posted by pluto View Post
1 - Am i correct in saying a packet is first checked for anti-spoofing the NAT and then Security and finally routing? There are no clear details on this. I have tried to use fw monitor but not clear from that either. I want to understand exactly what happens when a packet hit FW-1 and when it leave inlcuding the INSPECT process.
Take a look at the 'fw monitor -p all' command and ... 'fw ctl chain', I think it is. That gives a much more detailed list of what's going on. Very generally speaking, stateless TCP verifications tend to be first (things like stripping IP Options), then antispoofing. Security and translation seem to be applied simultaneously, since both are done by the firewall kernel, though NAT normally only happens on the inbound or the outbound leg for a given connection. Occasionally, you'll see NAT on both the i-I and the o-O transition.

Routing is done between I and o in an fw monitor. Then it goes through the firewall kernel again.

Quote:
Originally Posted by pluto View Post
3 - What advantages are there of using SPLAT over Nokia's?
The big advantage would be that there's one vendor for both the OS and the application you're running on it. Then again, with Nokia boxes or that sort of thing, you have one vendor for the hardware and the OS, so there aren't really driver issues. Everything is built to work together.

I use SecurePlatform, because I like how if I have a catastrophic hardware failure, I can dig up enough spare hardware to build a new box, install SecurePlatform on it, and get it back up and running in under an hour.

Quote:
Originally Posted by pluto View Post
4 - How do you apply HFA's to windows, SPLAT, Nokia and Solaris (modules and managers)
That would be described in the individual HFA's release notes. Unfortunately, the method of application sometimes changes.

Quote:
Originally Posted by pluto View Post
Sorry for the general questions... just trying to clear things in my head...

Thanks
Paul
Not a problem. Hopefully someone else can help you with number 2, because I don't have any specific documentation on that.
__________________
Robert Zimmerman
Reply With Quote
  #3 (permalink)  
Old 2007-09-23
pluto pluto is offline
Junior Member
 
Join Date: 2007-04-02
Posts: 7
Rep Power: 0
pluto has an average reputation (10+)
Default Re: Help understanding Checkpoint

Thanks Bob....

Hopefully someone can clarify the recommended way of building solaris boxes inorder to run a FW manager or Provider-1

Cheers
Paul
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 12:58.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0