CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've just added two more speakers!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Services
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-25
djsven djsven is offline
Junior Member
 
Join Date: 2006-03-28
Posts: 17
djsven has an average reputation (10+)
Default HTTP Traffic over proxy in DMZ

HI,
can someone tell me how i have to configure my checkpoin NG55
so that all http traffic transfer trough a proxy which placed in my DMZ?
Itīs normal proxy like ip:8080.
Where can i configure this option?
Big thanks!
Bye
Reply With Quote
  #2 (permalink)  
Old 2007-07-25
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 131
Danielpb has an average reputation (10+)
Default Re: HTTP Traffic over proxy in DMZ

What proxy server are you using on the DMZ?
Reply With Quote
  #3 (permalink)  
Old 2007-07-25
djsven djsven is offline
Junior Member
 
Join Date: 2006-03-28
Posts: 17
djsven has an average reputation (10+)
Default Re: HTTP Traffic over proxy in DMZ

We are using TrendMicro IWSS Proxy.
Reply With Quote
  #4 (permalink)  
Old 2007-07-25
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 131
Danielpb has an average reputation (10+)
Default Re: HTTP Traffic over proxy in DMZ

I can point you in the right direction but I’m not 100% sure its available for that Trend Micro product.

Open the SmartDash on the left hand panel select the 4th tab in 'Servers and OPSEC applications'

You then right click the OPSEC application Section and select
'New OPSEC application'

You can configure you UFP server from this point.

Then you will need to configure a Http recourse Tab 3 'Recourses'
under the URI section.

Once this has been complete you should create new Http-8080 Tcp service and in the advanced configuration you can select 'Enable for TCP Recourse'.

The on the services selection on the rule you right click and select 'Add with recourse' and located the new Http resource you created above.

hope this helps in some way.
Reply With Quote
  #5 (permalink)  
Old 2007-07-25
djsven djsven is offline
Junior Member
 
Join Date: 2006-03-28
Posts: 17
djsven has an average reputation (10+)
Default Re: HTTP Traffic over proxy in DMZ

Big THanks for your post!
I will try it
Reply With Quote
  #6 (permalink)  
Old 2007-07-25
djsven djsven is offline
Junior Member
 
Join Date: 2006-03-28
Posts: 17
djsven has an average reputation (10+)
Default Re: HTTP Traffic over proxy in DMZ

Ok.
again.
All Lan Traffic for port 80 sorry http traffic goes to checkpoint, and checkpoint forwared to proxy server?
Is this right?
Reply With Quote
  #7 (permalink)  
Old 2007-07-25
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 131
Danielpb has an average reputation (10+)
Default Re: HTTP Traffic over proxy in DMZ

Your best to create a new http (80) services called something like Http-mapped or something like that. This can then be used on you dedicated web allowed out rule and all web traffic hitting that rule will then be forwarded to the Proxy.
Reply With Quote
  #8 (permalink)  
Old 2007-07-29
larstr larstr is offline
Junior Member
 
Join Date: 2005-12-01
Posts: 9
larstr has an average reputation (10+)
Default Re: HTTP Traffic over proxy in DMZ

Quote:
Originally Posted by djsven View Post
Ok.
again.
All Lan Traffic for port 80 sorry http traffic goes to checkpoint, and checkpoint forwared to proxy server?
Is this right?
Yes, If you do as descrived above, all the port 80 traffic matching this rule will go through the proxy server. There are however a few limitations by doing it this way, and I would seriously consider doing it in a traditional way, making the clients aware of the proxy server by an autoconfig script or group policy.

Lars
Reply With Quote
  #9 (permalink)  
Old 2007-08-03
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 805
mcnallym has an average reputation (10+)
Default Re: HTTP Traffic over proxy in DMZ

I really wouldn't advise using the HTTP Security Server to do this as is a real pain. I would just use as a traditional proxy to the DMZ based box and just not allow http/https etc from the the internal networks. This forces the users to go through the proxy to get out.

Presuming you have a Microsoft Windows Network then you can use Group Policy settings to force the clients to use the Proxy Server and not allow them to change the IE settings themselves.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:59.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0