CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-21
hahasasa hahasasa is offline
Junior Member
 
Join Date: 2005-08-16
Posts: 5
Rep Power: 0
hahasasa has an average reputation (10+)
Default How to turn off SmartDefence?

Is there any command to turn off SmartDefence and let the firewall perform just as a layer4 filter?
I've disabled anything in SmartDefence,but there still be some log showing packets dropped by SmartDefence,such as DNS packet saying "Illegal query format".
I just want to allow these Illegal query format,but don't know how to do...

Thanks for any one here!
Reply With Quote
  #2 (permalink)  
Old 2006-03-22
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: How to turn off SmartDefence?

There is user friendly SmartDefence GUI disable option in the NGX only (Central Configuration button under the general folder).
For the DNS look for "DNS Protocol Enforcement" options. Uncheck TCP and UDP options.
Reply With Quote
  #3 (permalink)  
Old 2006-03-22
hahasasa hahasasa is offline
Junior Member
 
Join Date: 2005-08-16
Posts: 5
Rep Power: 0
hahasasa has an average reputation (10+)
Default Re: How to turn off SmartDefence?

Here I'm running R54 or R55.

I agree that disabling "enforce UDP" may have some affect,but since the drop reason——"Illegal query format" is the result of Application Layer inspect,so I don't think disabling "enforce UDP" will work.

For example
If I send a packet with dst port UDP 53 and the L7 data isn't DNS format,will the checkpoint drop it?

What can I do to accept these packets?
Reply With Quote
  #4 (permalink)  
Old 2006-03-22
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: How to turn off SmartDefence?

I have seen a lot of DNS enforcement errors with pre-NGX versions on the customers firewalls. Some are just ignore them (internet is still working)

enforce UDP is the right check-box to disable (if you want to stop using DNS enforcement)
Reply With Quote
  #5 (permalink)  
Old 2006-03-23
hahasasa hahasasa is offline
Junior Member
 
Join Date: 2005-08-16
Posts: 5
Rep Power: 0
hahasasa has an average reputation (10+)
Default Re: How to turn off SmartDefence?

I've done it,and will look if it works.
Thanks!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:49.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0