CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-03
Member
 
Join Date: 2007-01-30
Location: Abudhabi
Posts: 48
Rep Power: 0
sridharraj80 has an average reputation (10+)
Default Recommended R61 Implied Rules

Hi ,

I have a Distributed enviroment with Nokia and R61. Is there any recommended Implied rulebase that needs to be followed.

Canany one please share if u have any such docs.

thanks
sridhar
Reply With Quote
  #2 (permalink)  
Old 2007-06-04
Member
 
Join Date: 2006-06-27
Location: United Kingdom
Posts: 73
Rep Power: 3
munrog has an average reputation (10+)
Send a message via MSN to munrog Send a message via Skype™ to munrog
Default Re: Recommended R61 Implied Rules

It depends upon how pedantic you want to be.

I generally turn off all Global Properties > Firewall Implied rules and write my own as that gives much higher levels of control over what devices can communicate with what.

Generally you will need:
Firewalls to Firewalls (eg clusters) : FW1, CP_ClusterControl and FIBMGR (SPLAT)/IPSO_Clustering
Bidirectional Firewalls to VPN devices: IKE, ESP, AH, FW1_topo, tunnel_test, tunnel_test_mapped, echo-request
Management clients to Firewalls: https, ssh
Management clients to Sofaware: https, ssh, SWTP_Mgmt
Network (SNMP) Managers to Firewalls: snmp-read, echo-request
Managers to Firewalls: CPD, CPD_Amon, FW1, FW1_CRPID, FW1_ICA_Push, FW1_ica_services, FW1_sam
Log servers to firewalls : FW1

Anything else to Firewalls drop (Stealth Rule!)

Firewalls to log servers : FW1_log
Firewalls to Managers: CPD, FW1, FW1_ica_services, FW1_ica_pull, CPD_amon
Firewalls to Network Managers : syslog, snmp-trap
Firewalls to NTP servers: ntp-udp
Firewalls to VRRP multicast: vrrp
Firewalls to DNS servers: domain-udp
Firewalls to RADIUS: new-radius
Sofaware to Management: SWTP_Gateway, SWTP_SMS
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:59.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0