CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-31
Scrif Scrif is offline
Junior Member
 
Join Date: 2007-06-14
Posts: 26
Rep Power: 0
Scrif has an average reputation (10+)
Default How to push rule for Firewall itself

We use dashboard to manage multiple Checkpoint/Nokia Firewall-1 firewalls. I want to enable email alerts (via global properties). I DO NOT have the implied rule enabled permitting the firewall to talk to anything it wants. My questions are:

1. Do I create a rule permitting the 'Firewall Manager' to talk to our Mail server?
2. As the rule is for the Firewall Manager, do I need to put this rule in each Firewall policy? Or is there a separate policy for the firewall manager?

Thanks
Reply With Quote
  #2 (permalink)  
Old 2007-07-31
dantro dantro is offline
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 233
Rep Power: 2
dantro has an average reputation (10+)
Default Re: How to push rule for Firewall itself

I assume you speak of SmartCenter Server (SCS) when writing 'Firewall Manager'. Place a rule that allows all E-mail communication between it and your internal mail server into all security policies that relate to policy installation targets where the traffic has to pass through.

Best regards,
Danny Trommer
CCSA/CCSE/CCSE+
Reply With Quote
  #3 (permalink)  
Old 2007-07-31
Scrif Scrif is offline
Junior Member
 
Join Date: 2007-06-14
Posts: 26
Rep Power: 0
Scrif has an average reputation (10+)
Default Re: How to push rule for Firewall itself

Thanks. Yes, I did mean SmartCenter Server - I guess maybe I dont understand the way it works. So is the SCS just a node on my network? ie: It doesnt have its own policy, but is permitted to talk to stuff via a firewall policy (and this policy could be on a firewall that it may even manage)?

Thanks again.
Reply With Quote
  #4 (permalink)  
Old 2007-07-31
dantro dantro is offline
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 233
Rep Power: 2
dantro has an average reputation (10+)
Default Re: How to push rule for Firewall itself

That depends on your configuration. The SCS can run on the same host where the enforcement module is installed. In this case it would be a firewall node. Otherwise it would just be a management host without any firewall functions. To check this out, run this command on your SCS: fw ver; fw stat
If it says that it's not a firewall, then it's just a management host.

Next if your SCS is in the same network where your internal mail server resides you don't require any additional rules. So you are almost done.

In the case that your SCS is localed in a different network you'll need to tell your firewall node to pass the mail traffic from it to your mail server. Therefore an additional rule is required that needs to be installed on the firewall node (enforcement module).

Best regards,
Danny Trommer
CCSA/CCSE/CCSE+
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:56.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0