CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-01
Member
 
Join Date: 2006-01-20
Posts: 39
Rep Power: 0
bvanniekerk has an average reputation (10+)
Default Problem on 4.1 (don't ask about 4.1...long story)

Hi All

I need some assistance please.
I have a rule, say 124, that has an

any | negated network object | any | service ports(SP) | drop | log

I've inserted a rule above this to allow traffic on (SP), but it is not allowing the traffic.

My understanding is that if the network object is negated, that it defaults to an any any rule.

Other than disabling the rule 124 and then testing, what is your take on this?

Rgrds
b

Last edited by bvanniekerk; 2006-02-01 at 08:00. Reason: Clarity
Reply With Quote
  #2 (permalink)  
Old 2006-02-02
Member
 
Join Date: 2005-09-08
Location: England
Posts: 38
Rep Power: 0
thefunkygibbon has an average reputation (10+)
Send a message via MSN to thefunkygibbon
Default Re: Problem on 4.1 (don't ask about 4.1...long story)

Quote:
Originally Posted by bvanniekerk
Hi All

I need some assistance please.
I have a rule, say 124, that has an

any | negated network object | any | service ports(SP) | drop | log

I've inserted a rule above this to allow traffic on (SP), but it is not allowing the traffic.

My understanding is that if the network object is negated, that it defaults to an any any rule.

Other than disabling the rule 124 and then testing, what is your take on this?

Rgrds
b

the negate rule is what it says on the tin.

the rule

any | negated network object | any | service ports(SP) | drop | log


would make sure that everything accessing the service ports on any machine except the negate object will be dropped.

i'm not entirely sure what you are trying to do. if you could elaborate some more maybe we could help
Reply With Quote
  #3 (permalink)  
Old 2006-02-06
Member
 
Join Date: 2006-01-20
Posts: 39
Rep Power: 0
bvanniekerk has an average reputation (10+)
Default Re: Problem on 4.1 (don't ask)

Hi
this is something my predecesors have put together.

I've gotten to the point where I've added the machines that I want to be able to access the ports, to the negated list, which makes sense.

It is however still dropping the packets like flies.

I'm trying to allow servers access to the tcp ports that are currently dropped.
The thinking was that if I add the Network objects to the negated object (which would negate them as well), that the rule would then allow the packets to go through.

Still vague?
rgrds
b
Reply With Quote
  #4 (permalink)  
Old 2006-02-07
Member
 
Join Date: 2006-01-20
Posts: 39
Rep Power: 0
bvanniekerk has an average reputation (10+)
Default Re: Problem on 4.1 (don't ask)

Hi All

The problem was all my own.
Apologies for wasting your time.

Rgrds
b
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:28.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0