CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-13
Senior Member
 
Join Date: 2005-08-12
Posts: 162
Rep Power: 4
roadrunner has an average reputation (10+)
Default Specific Rules on Specific Interfaces

Specific Rules on Specific Interfaces
The INSPECT language that is used in FireWall-1 to program the rulebase actually supports the use of specific rules on specific interfaces. The Smart Dashboard/Policy Editor applications were not designed to allow you to bind specific rules to specific interfaces of a firewall. Rules are processed in-order. Rules that do not apply are skipped. Processing a rule takes a near zero amount of time, so unless you have a few hundred rules, there's little reason to do it this way.

If it is an absolute requirement that certain rules are only active on certain interfaces, it can be done, but it is not elegant. Take the generated .pf file from a policy install in the GUI (it should be called rulebase-name.pf, located in $FWDIR/conf on the management console) and modify it so that the rules in question are only installed on the interface in question. Look in the "Inspect" chapter in your Check Point documentation. It explains some of what you will see in this file and should steer you in the proper direction as to what changes to make.

Once you have modified this file, you can then install it with the 'fw load' command.

Note that every time you change your security policy in the GUI, you will need to go into the generated .pf, manually reapply the changes, and 'fw load' the modified .pf file. It's not elegant, but that's what you have to do to make it do what you want.

-- PhoneBoy - 16 Jan 2004


FAQForm
FAQs.Class: SmartClientsFAQs
FAQs.OS:
FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:35.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0