CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Services
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-27
tdgast tdgast is offline
Junior Member
 
Join Date: 2006-09-27
Posts: 5
Rep Power: 0
tdgast has an average reputation (10+)
Default SQLNET through FW1

Hello all,

I am currently involved in migrating from Symantec firewalls to CP FW1 (on Nokia). We currently have several applications that utilize Symantec's sqlnet proxy service. As a matter of fact, up till now these firewalls have not been upgraded to version 8 because Symantec did away with the sqlnet service support in the newer version.

As I understand it, the sqlnet proxy service negotiates the communications between servers and is initiated on port tcp/1521 with high port negotiation following. The Symantec proxy service can support 30 concurrent connections.

An alternative to sqlnet proxy is ORACLE 8i Connection Manager which redirects sqlnet traffic to 1630/tcp.

Does FW1 support sqlnet and its negotiated random port usage or should I consider purchasing third party software such as ORACLE 8i Connection Manager to handle this type of traffic?

Thanks,
Ty
__________________
----------------
Ty Gast
G2, Inc.
www.g2-inc.com
Reply With Quote
  #2 (permalink)  
Old 2006-09-28
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 434
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: SQLNET through FW1

sqlnet is defined as proto type in the checkpoint, so i assume it does support it.

Short description:


Quote:
SQLNet v2 is Oracle Inc. network protocol for database data exchange. Our protocol handler handles the connection between the SQLnet2 client to the Oracle NTS Network-Listener. This Network Listener then redirects the client to the appropriate Oracle database server. Our INSPECT handler records these connections as data connections.
Reply With Quote
  #3 (permalink)  
Old 2006-09-28
tdgast tdgast is offline
Junior Member
 
Join Date: 2006-09-27
Posts: 5
Rep Power: 0
tdgast has an average reputation (10+)
Default Re: SQLNET through FW1

Thanks abusharif, I appreciate the response.
__________________
----------------
Ty Gast
G2, Inc.
www.g2-inc.com
Reply With Quote
  #4 (permalink)  
Old 2006-11-07
bknight bknight is offline
Junior Member
 
Join Date: 2006-11-07
Posts: 1
Rep Power: 0
bknight has an average reputation (10+)
Default Re: SQLNET through FW1

Note that as of Oracle 8 the SQLNet protocol inspection on the Checkpoint does not work properly.

The issue is that now the Oracle server tells the client to connect to a FQDN and dynamic high port. The Checkpoint will not resolve that name to an IP and the connection will fail. Older version returned an IP only so there was no issue.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:12.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0