CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've just added two more speakers!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Services
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-29
Phayder Phayder is offline
Junior Member
 
Join Date: 2007-05-07
Posts: 22
Phayder has an average reputation (10+)
Default X11 not passing the FW

Hi guys.
I recently bump into a problem:
X11 traffic is not passing the firewall if is not explicitly defined.
I other words, if I have a rule like this:
Source x.x.x.x Destination y.y.y.y Service any
the X11 traffic is not passing the firewall, unless is defined in a rule.
Source x.x.x.x Destination y.y.y.y Service X11.
The rule must be place above any other rule that permit service any, so no
conflict will appear.
So basicly, the X11 connection is in fact "Accepted" by the Rule Base, but is later rejected by another mechanism (called the Session Handler), which does not have any information about rule numbers.

Regards,
Phayder
Reply With Quote
  #2 (permalink)  
Old 2007-06-29
stefan73er stefan73er is offline
Junior Member
 
Join Date: 2006-02-28
Posts: 17
stefan73er has an average reputation (10+)
Default Re: X11 not passing the FW

hi,

open the service object x11 and go to the advanced properties. Then set the "Match for any" option and reinstall the policy.

After this change x11 is part of "any" and your rule will work as you expect.

cheers

stefan
Reply With Quote
  #3 (permalink)  
Old 2007-06-29
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 835
RayPesek has an average reputation (10+)
Default Re: X11 not passing the FW

That's normal behavior because X11 is considered a dangerous service since it can open a new back connection back into the network. That's why it is not included in "any" unless you explicitly put it there. The possible problem with doing so is that "any" anywhere in the rule base now includes X11 and it's just not that prevalent in usage.

Ray
Reply With Quote
  #4 (permalink)  
Old 2007-06-30
chillyjim chillyjim is online now
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,509
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: X11 not passing the FW

You need to explicitly define the rule for X11, the "match on any" trick shouldn't work anymore.
Reply With Quote
  #5 (permalink)  
Old 2007-07-02
dantro dantro is offline
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 176
dantro has an average reputation (10+)
Default Re: X11 not passing the FW

What?

Just go to 'Policy -> Global Properties -> SmartDashboard Customization -> Configure -> FireWall-1 -> Stateful Inspection' and uncheck the 'reject_x11_in_any' checkbox. Then install your policy again.


Glad to be of service,
Danny Trommer
CCSA/CCSE/CCSE+
Reply With Quote
  #6 (permalink)  
Old 2007-07-04
Phayder Phayder is offline
Junior Member
 
Join Date: 2007-05-07
Posts: 22
Phayder has an average reputation (10+)
Default Re: X11 not passing the FW

HI Guys,
Thank you all for the solutions. They are all good, but the best for an enterprise environment I think is Dantro's.

Best regards and thank you all.

Phayder
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:54.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0