CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-12
ugirl ugirl is offline
Junior Member
 
Join Date: 2007-12-11
Posts: 5
Rep Power: 0
ugirl has an average reputation (10+)
Default DFAIT restricted countries

Hi Folks

First post on this forum, but I have turned to you guys for help in the past.

Does anyone else have a requirement to block DFAIT (Department Foreign Affairs and International Trade) restricted countries from downloading software from your company that includes encryption modules?

We have been told that we must block access to ~200 CIDR blocks that fall within these restricted countries, failure to comply could mean stop shipment of product.

DFAIT recommends that we do a DNS reverse lookup on the addresses coming in and if they match the restricted list drop the connection. However, my company would prefer that they be redirected to a site providing the blocked user with our company contact details.

I have told them I could outright block these addresses from accessing our FTP servers but that would require that I manually enter ~200 CIDR blocks as network objects and adding them to a drop rule. I really do not believe that this should be the job of our Checkpoint NGX firewall and really is the job of the web application layer..However I have been asked how to accomplish this task with our Checkpoint Firewall.

Ideally we would prefer to allow access to all other components of our Web
infrastructure, but should they try to access a site that has software with encryption they be redirected to a page that provides them with our company contact information.

I can think of a number of ways this whole thing can be circumvented, ie - get your buddy in a non-restricted country to download for you... ssh to a system that does not fall within the ranges etc etc etc. However, with that said should we not comply could mean stop shipment of product.

Anyone else have this requirement? and if so how are you managing it?

Thanks
Ugirl
Reply With Quote
  #2 (permalink)  
Old 2007-12-12
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 131
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: DFAIT restricted countries

I think you can do this with the FTP-Security server

A rule like this shoud do this.
Code:
Source    Destination  Service        Action  Comment  
!Net_200  My.DMZ.ftp   ftp->download  Accept  'restricted download'
With an open proxy's or other tools this rule cannot see the source IP.

I agree with you that this is better handled at the application, maybe you can restrict the access directly at the ftp/http server.

Some other suggestion if the software is not *free* is to change the download process (only approved downloads) ...
Reply With Quote
  #3 (permalink)  
Old 2007-12-12
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 534
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: DFAIT restricted countries

Quote:
Originally Posted by ugirl View Post
Hi Folks

First post on this forum, but I have turned to you guys for help in the past.

Does anyone else have a requirement to block DFAIT (Department Foreign Affairs and International Trade) restricted countries from downloading software from your company that includes encryption modules?

We have been told that we must block access to ~200 CIDR blocks that fall within these restricted countries, failure to comply could mean stop shipment of product.

DFAIT recommends that we do a DNS reverse lookup on the addresses coming in and if they match the restricted list drop the connection. However, my company would prefer that they be redirected to a site providing the blocked user with our company contact details.

I have told them I could outright block these addresses from accessing our FTP servers but that would require that I manually enter ~200 CIDR blocks as network objects and adding them to a drop rule. I really do not believe that this should be the job of our Checkpoint NGX firewall and really is the job of the web application layer..However I have been asked how to accomplish this task with our Checkpoint Firewall.

Ideally we would prefer to allow access to all other components of our Web
infrastructure, but should they try to access a site that has software with encryption they be redirected to a page that provides them with our company contact information.

I can think of a number of ways this whole thing can be circumvented, ie - get your buddy in a non-restricted country to download for you... ssh to a system that does not fall within the ranges etc etc etc. However, with that said should we not comply could mean stop shipment of product.

Anyone else have this requirement? and if so how are you managing it?

Thanks
Ugirl
But IP addresses don't map neatly to countries and it's really easy to change your IP address anyway. Anyone who lives in a country with blocked CIDR networks already knows how to use TOR or any one of thousands of free web proxies to make it appear they're coming from somewhere else. They saw this coming long ago. This battle is lost before you start.

And the reverse DNS lookup is silly, too. Top Level Domains only tangentially map to countries. What if they just grab a .com domain name and put in a fake address?

You're being asked to perform security theater.

But you probably already know this.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 15:48.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0