CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've already had our first sign-ups!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Services
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-20
thatgeekinit thatgeekinit is offline
Junior Member
 
Join Date: 2007-11-20
Posts: 2
thatgeekinit has an average reputation (10+)
Default Non-Continous port ranges in a service?

I am migrating slowly to checkpoint NGX R65 on Nokia from IOS access list based firewalling.
I am taking this opportunity to cut down on the number of rules which due to being a whitelist environment (blocking outgoing and incoming by default) we have thousands even though the number of applications and the number of clients are relatively small.

I have a list of servers and a variety of nonstandard ports that they use for the main application here and I am wondering if there is a way to define a service with non-contiguous ports without creating a whole bunch of them and then grouping them.

For instance can I create a single service object that has say port 1001, 6006, and 2003 without making one for each and then making a group?

My other question is that reply traffic for many rules is currently allowed based on src port but with no destination port specified. This does not seem to be an available option in Checkpoint since rules only list services not src and dest port. How do I allow any destination port, but restrict source port from a particular host?
Reply With Quote
  #2 (permalink)  
Old 2007-11-20
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: Non-Continous port ranges in a service?

I'm pretty sure you can't specify non-contiguous ports in a single service obj. You'll have to create them individually. This seems to be confirmed by the GUI help page titled, "To Specify a Port Number." It lists the syntax possibilities and they all involve contiguous ports.

To specify the source port, you'd go to the advanced tab. The first field at the top is the source port field. I'd recommend you copy the objs and then customize them so that you can use the std services too if you want. There's no real draw-back to creating more service objs unless you go over the top and add hundreds more.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 04:25.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0