CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Services
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-04-13
ChrisA ChrisA is offline
Member
 
Join Date: 2006-02-18
Posts: 99
Rep Power: 3
ChrisA has an average reputation (10+)
Default Restricting ports for web-based traffic outbound

Does anyone out there have a proxy server that users on the network point to in their browser for access to the Internet? If so, do you restrict the ports that the proxy server is allowed to talk out on (eg, only 80/443) or are any ports allowed outbound? If you restrict, is the restriction imposed on the firewall, on the proxy itself, or both? If you restrict on the firewall, do non-allowed ports get dropped (eg, in the cleanup rule) or rejected?

Any experience, advice, comments are welcomed/appreciated. Thanks.
Reply With Quote
  #2 (permalink)  
Old 2007-04-13
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 724
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Restricting ports for web-based traffic outbound

Quote:
Originally Posted by ChrisA View Post
Does anyone out there have a proxy server that users on the network point to in their browser for access to the Internet? If so, do you restrict the ports that the proxy server is allowed to talk out on (eg, only 80/443) or are any ports allowed outbound? If you restrict, is the restriction imposed on the firewall, on the proxy itself, or both? If you restrict on the firewall, do non-allowed ports get dropped (eg, in the cleanup rule) or rejected?

Any experience, advice, comments are welcomed/appreciated. Thanks.
Yes. Yes. Firewall/Both. Yes.
Reply With Quote
  #3 (permalink)  
Old 2007-04-13
ChrisA ChrisA is offline
Member
 
Join Date: 2006-02-18
Posts: 99
Rep Power: 3
ChrisA has an average reputation (10+)
Default Re: Restricting ports for web-based traffic outbound

Thanks for the reply. So you restrict on both the proxy and firewall. Do you restrict to just 80 and 443, or do you also allow specific high ports as needed, and if so, how many approximately are allowed (ie, 10 or 300)? Are non-allowed ports dropped or rejected in the firewall?
Reply With Quote
  #4 (permalink)  
Old 2007-04-13
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 861
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Restricting ports for web-based traffic outbound

Yes, we use a proxy.

Yes, we restrict the ports.

We restrict only on the firewall and drop them.

I've probably go about five exceptions, for dumb things like WebTrends and a cellular company who insists on running their text messaging system (send SMS via a browser) on a non-standard port. Where possible, I create a second rule with the proxy as source, all of the the non-standard ports as the services, and restrict the destinations.

I try to stick to the standards rigorously. Security through obscurity does not work and people who run web servers on non-standard ports are usually small companies. If they think that is making the secure, we don't want to do business with them.

HTH,

Ray
Reply With Quote
  #5 (permalink)  
Old 2007-04-16
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Restricting ports for web-based traffic outbound

I don't "own" firewalls, I just deploy them, but your policy should be as strict as possible and enforced in both devices, just like Ray said.

Since you have a proxy you should also make sure that no machines are going out direct, etc.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:53.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0