CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-26
badbeagle badbeagle is offline
Junior Member
 
Join Date: 2005-11-28
Posts: 10
Rep Power: 0
badbeagle has an average reputation (10+)
Default Firewall Management

Can someone give me some advice on how you manage your firewall? I am curious to know how you handle requests to open ports on the firewall. There are many times that we are requested to open a port on the firewall but how do you tell if it is reasonable or not. Obviously poking holes in the firewall is not secure but some business cases are made and it has to be done. Are there any sites etc that you can check to know if there has been an vulnerabilites on certain ports? What steps do you use to assess the risks?
Reply With Quote
  #2 (permalink)  
Old 2007-09-26
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 724
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Firewall Management

There are a lot of sites you can use to check. Try doing a google search for your port and protocol like "tcp 10000" and see what you get. My favorite is SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc They have a search at the top for port.

Otherwise it comes from a lot of experience in knowing which applications use what ports, what type of information is typically passed over that port, is it encrypted communication. There are other steps you can take like create the most specific rule you can by specifying source and destination and ports. Smart Defense and the UTM features also go a long way to monitoring traffic as well.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:32.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0