CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-18
Junior Member
 
Join Date: 2006-03-27
Posts: 3
Rep Power: 0
CDoyle has an average reputation (10+)
Default Zone Transfers (domain-tcp)

Friends,

We created a rule that permits a specific secondary DNS server on the Internet to perform Zone Transfers (domain-tcp) from a Primary DNS server that's protected by our Gateway. The rule was being ignored. We had to enable: Policy > Global Properties > "Accept Domain Name over TCP (Zone Transfers)" or order to pass the traffic. This is not our preferred method. Can this not be accomplished via the rule base ?

Regards,

Craig.

Last edited by CDoyle; 2006-05-18 at 10:53.
Reply With Quote
  #2 (permalink)  
Old 2006-05-18
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 582
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Zone Transfers (domain-tcp)

Quote:
Originally Posted by CDoyle
Friends,

We created a rule that permits specific a secondary DNS server on the Internet to perform Zone Transfers (domain-tcp) from a Primary DNS server that's protected by our Gateway. The rule was being ignored. We had to enable: Policy > Global Properties > "Accept Domain Name over TCP (Zone Transfers)" or order to pass the traffic. This is not our preferred method. Can this not be accomplished via the rule base ?

Regards,

Craig.
Is it possible the zone transfer connection is going in the opposite direction than you're expecting (from primary to secondary, or from secondary to primary)?

What shows up in the log?
Reply With Quote
  #3 (permalink)  
Old 2006-05-18
Junior Member
 
Join Date: 2006-03-27
Posts: 3
Rep Power: 0
CDoyle has an average reputation (10+)
Default Re: Zone Transfers (domain-tcp)

I'm confident the traffic was using the correct src & dst, because when I enabled TCP Zone Transfers in the Global Policy and had Log Implied Rules set to On, I would then see log entries that matched my expectations for src & dst. The session was initiated from the outside.

Before enabling TCP Zone Transfers in the Global Policy, there were no log entries generated when transfer attempts were made, even through the Clean-up rule was set to Log. It was as though the Gateway was doing a silent drop.

Strange ?

Thanks,
Craig.
Reply With Quote
  #4 (permalink)  
Old 2006-05-18
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 582
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Zone Transfers (domain-tcp)

Quote:
Originally Posted by CDoyle
I'm confident the traffic was using the correct src & dst, because when I enabled TCP Zone Transfers in the Global Policy and had Log Implied Rules set to On, I would then see log entries that matched my expectations for src & dst. The session was initiated from the outside.

Before enabling TCP Zone Transfers in the Global Policy, there were no log entries generated when transfer attempts were made, even through the Clean-up rule was set to Log. It was as though the Gateway was doing a silent drop.

Strange ?

Thanks,
Craig.
If you enable the implied rule that allows these connections, go look at exactly what that implied rule says; maybe there's something unexpected there?

Also, have a look at SmartDefense and see if something might be getting blocked or inspected there.
Reply With Quote
  #5 (permalink)  
Old 2006-05-18
Junior Member
 
Join Date: 2006-03-27
Posts: 3
Rep Power: 0
CDoyle has an average reputation (10+)
Default Re: Zone Transfers (domain-tcp)

Thanks Barry, will do!Craig.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:37.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0