CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've already had our first sign-ups!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-04
newbee newbee is offline
Junior Member
 
Join Date: 2008-04-03
Posts: 5
newbee has an average reputation (10+)
Default transprent proxy

Do you know what is the smallest possible Checkpoint firewall ? It only needs two interfaces, and needs to support "Transparent Proxy".

i was thinking a UTM-1 Edge Checkpoint device will be ok-- sorry - it may a basic question but cant find anything on the web about checpoint firewalls regarding "Transparent Proxy". Iam sure most will supoort it
Reply With Quote
  #2 (permalink)  
Old 2008-04-04
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 306
MarioL has an average reputation (10+)
Default Re: transprent proxy

From your requirements I bet a small NetScreen would probably be better, though that might not be an option for you.
Reply With Quote
  #3 (permalink)  
Old 2008-04-04
newbee newbee is offline
Junior Member
 
Join Date: 2008-04-03
Posts: 5
newbee has an average reputation (10+)
Default Re: transprent proxy

Can you provide me a model number or part number for a netscreen version you would reccomend

I would prefer a checkpoint firewall- the only reason been we have some already in place. whats the lowest one i can go for which has transprent proxy and 2 interfaces
Reply With Quote
  #4 (permalink)  
Old 2008-04-04
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 791
mcnallym has an average reputation (10+)
Default Re: transprent proxy

Check Point isn't a transparent proxy firewall. It is stateful inspection.

What is it that you are looking to use the firewall for, also what sort of throughput are you looking for on the box?
Reply With Quote
  #5 (permalink)  
Old 2008-04-04
newbee newbee is offline
Junior Member
 
Join Date: 2008-04-03
Posts: 5
newbee has an average reputation (10+)
Default Re: transprent proxy

Sorry, my confusion about the Checkpoint products. Nokia firewall running Checkpoint functionality sounds like what we need. So long as it supports the "Transparent Proxy" function.
Reply With Quote
  #6 (permalink)  
Old 2008-04-04
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 791
mcnallym has an average reputation (10+)
Default Re: transprent proxy

I'll rephrase my question then.

As Check point ISN'T a transparent proxy. Rather then saying it needs to support Transparent proxy what are you actually looking to use this box for.

ie

logging of where people go on the Internet
URL filtering
Reply With Quote
  #7 (permalink)  
Old 2008-04-04
newbee newbee is offline
Junior Member
 
Join Date: 2008-04-03
Posts: 5
newbee has an average reputation (10+)
Default Re: transprent proxy

I want to use a hosted Internet filtering service, Scansafe. This works as a sort of proxy "in the cloud". Normally we'd use Group Policy or similar to point the browsers to the Scansafe service, and configure the firewall to block any requests that do directly. In this case we can't do that as the facility is to be used by visitors withot us being able to get any control over their PCs or browsers. Scansafe tell us that Checkpoint firewalls can be configured to transparently catch HTTP requests and redirect them to the Scansafe proxy. (A bit like the Websense support in Cisco).
Reply With Quote
  #8 (permalink)  
Old 2008-04-04
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 306
MarioL has an average reputation (10+)
Default Re: transprent proxy

Ah... yeah, Check Point can do that, it's called "HTTP next proxy". I don't think the Safe@Office boxes have that (can't remember for sure), so I guess the next cheapest option will do, which will probably be the smallest Nokia... Or get a really cheap PC and install Splat with the smallest license :)

Note: When you say "Transparent proxy" most people will think about arp proxy on the firewall, meaning the same network present in 2 or more interfaces, usually not doing any IP routing at all, just "arping".
Reply With Quote
  #9 (permalink)  
Old 2008-04-04
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 791
mcnallym has an average reputation (10+)
Default Re: transprent proxy

Scansafe actually have a document on exactly how to configure the Check Point software to do that. Any Check Point platform should do as long as it can support the number of users that you want it to protect. They should have provided that document too you, if not your Scansafe reseller should be able to get for you.

All the check point does is a http redirect and directs all http/https requests off to the Scansafe Web Filtering.

To me this isn't a Transparent Proxy. Transparent Proxy is what Scansafe are doing.

If you do go with a Nokia avoid the IP260 as painfully slow, go with an IP290 or look at the UTM450 model as you get the license with that.
Alternatively if all that need it for is this then just get a cheap PC with two NICs and install SPLAT/Check Point on that. What you need is a Check Point function so the platform won't matter.
Reply With Quote
  #10 (permalink)  
Old 3 Weeks Ago
newbee newbee is offline
Junior Member
 
Join Date: 2008-04-03
Posts: 5
newbee has an average reputation (10+)
Default Re: transprent proxy

Thanks for the above -- it been a big help

so if a pick say Nokia IP 290 and say Checkpoint vpn 1 powergate for x amounts of users ( eg CPPWR-VPG-25) this should do the job --
Reply With Quote
  #11 (permalink)  
Old 3 Weeks Ago
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 791
mcnallym has an average reputation (10+)
Default Re: transprent proxy

Providing you have less then 25 users on the network behind the gateway that should be fine.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 23:29.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0