CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Services
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-12
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 534
Rep Power: 10
BarryStiefel has disabled reputation
Default Allowing ICQ

Allowing ICQ



Note that the following information was based on information available from http://www.icq.com/icqtour/firewall/netadmin.html on 19 November 2002. You may wish to check this page for the latest instructions.

Client to server Communication is done via port 5190 to login.icq.com. Note that login.icq.com resolves to multiple IP addresses, so you will need to perform an nslookup to determine what IP addresses it resolves to. Windows and some Unix implmentations of nslookup only show one IP address even when multiple IPs are possible.

Client to client communication uses tcp high ports (i.e. all ports above 1024). If you allow clients to initiate "any" service outbound, then client to client communication will work. If you don't feel comfortable with this configuration, you can restrict the client to specific "listening" ports. This will be compatible with static NAT, but not HIDE NAT.

In a HIDE NAT configuration, your users will need to configure their clients to "Use Server Proxy Settings" and it will not be possible to initiate a direct communication to other users in a similar configuration.

-- GuyR - 18 Jan 2004

FAQForm FAQs.Class: ServicesFAQs FAQs.OS: FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:45.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0