CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-07-20
jeetu_chaudhari jeetu_chaudhari is offline
Junior Member
 
Join Date: 2006-04-11
Posts: 16
Rep Power: 0
jeetu_chaudhari has an average reputation (10+)
Default restriction on domains

I am having NGX checkpoint with server based firewall module.

we have last rule as any any service any drop.
now i am making one domain object as .microsoft.com
then i am making rule as src=>xyz dst=> .microsoft.com service=> http https action=>allow
but my firewall droping my connection according to last rule.

Also,
Access to DNS server on UDP port is allowed from any source
& in global properties also i checked accept UDP queries then
why my connection is droping ? why firewall is not resolving the domain to IP ?
Reply With Quote
  #2 (permalink)  
Old 2006-07-20
ButlerKevinD ButlerKevinD is offline
Junior Member
 
Join Date: 2006-07-20
Posts: 4
Rep Power: 0
ButlerKevinD has an average reputation (10+)
Default Re: restriction on domains

I've tried the same thing. We were attempting to block anything resolving to .easynews.com as a destination, and doing so blocks everything going out of our network. I read where there was a delay or something until the domain name and ip was resolved and added into the cache, but how long of a delay are we talking about?? A few minutes?? Thanks in advance for any replied!!
Reply With Quote
  #3 (permalink)  
Old 2006-07-22
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: restriction on domains

jeetu:

May be the problem is Microsoft use Akamay internet proxy and acceleration services to deliver content and reverse DNS lookup is not always correct?

As a workaround you can use HTTP URI resourse with match on HTTP host. So the solution is to deny enytind but HTTP with URI wit one or several sites (several sites can be imported from file).
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:50.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0