CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-12-13
Junior Member
 
Join Date: 2005-12-13
Posts: 2
Rep Power: 0
BarryG has an average reputation (10+)
Default Implied rule dropping snmp-read

CheckPoint Firewall-1 NG-AI R55 Hotfix 6 on Nokia IP 380 running IPSO 3.8

SmartCenter Server NG-AI R55 Hotfix 16 on Windows 2000 Server

Problem:

Number: 56396
Date: 13Dec2005
Time: 11:12:15
Product: VPN-1 & FireWall-1
Interface: eth-s1p1c0
Origin: fwne12 (10.31.16.137)
Type: Log
Action: Drop
Protocol: udp
Service: snmp-read (161)
Source: Server_1 (10.31.16.156)
Destination: Server_2 (10.31.124.101)
Rule: 0 - Implied Rules
Source Port: 2190


There is an explicit security rule that allows Server_1 (Windows 2000 Server) to make snmp-read connections to Server_2 (Windows 2000 Server) but it is dropped by the implied rule.

Any ideas why ?
Reply With Quote
  #2 (permalink)  
Old 2005-12-14
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Implied rule dropping snmp-read

What does it say in the Information section of the drop? You seem to have missed that when copying it into the forum.
Reply With Quote
  #3 (permalink)  
Old 2005-12-15
Junior Member
 
Join Date: 2005-12-13
Posts: 2
Rep Power: 0
BarryG has an average reputation (10+)
Default Re: Implied rule dropping snmp-read

The information field is blank (empty).
Reply With Quote
  #4 (permalink)  
Old 2005-12-15
Junior Member
 
Join Date: 2005-12-15
Posts: 1
Rep Power: 0
ogre_t has an average reputation (10+)
Default Re: Implied rule dropping snmp-read

Try adding snmp to your allow rule.

I had the same problem with monitor services and I had to add snmp to the snmp-read to mkae it work.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:42.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0