CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-08-09
Junior Member
 
Join Date: 2006-08-09
Posts: 2
Rep Power: 0
Dimitri has an average reputation (10+)
Default How to turn off Smart Defense for one specific host

Is it possible to turn off Smart Defense for one host.....???????
Reply With Quote
  #2 (permalink)  
Old 2006-08-09
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: How to turn off Smart Defense for one specific host

Do you mean for CP server? Or smth else?
For CP module it's impossible, as i know it will be a new feature in new CP release. Smth like profiles in Interspect.
Reply With Quote
  #3 (permalink)  
Old 2006-08-09
Junior Member
 
Join Date: 2006-08-09
Posts: 2
Rep Power: 0
Dimitri has an average reputation (10+)
Default Re: How to turn off Smart Defense for one specific host

It is CP, thank you for the answer
Reply With Quote
  #4 (permalink)  
Old 2006-08-22
Junior Member
 
Join Date: 2006-04-30
Posts: 24
Rep Power: 0
yelwoci has an average reputation (10+)
Default Re: How to turn off Smart Defense for one specific host

Now it would be very nice to be able to define trusted hosts with Smartdefense, that turns it off for a particular host list
Reply With Quote
  #5 (permalink)  
Old 2006-08-22
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,660
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: How to turn off Smart Defense for one specific host

Quote:
Originally Posted by yelwoci
Now it would be very nice to be able to define trusted hosts with Smartdefense, that turns it off for a particular host list
Please open a RFE (http://www.checkpoint.com/jsp/rfe/rfe.jsp) for this. I'm hoping to get critical mass on requests for them to do this.
Reply With Quote
  #6 (permalink)  
Old 2006-08-25
Member
 
Join Date: 2005-11-17
Location: Italy
Posts: 82
Rep Power: 4
maurox has an average reputation (10+)
Default Re: How to turn off Smart Defense for one specific host

For the moment you can do this adding a new tcpservice ( for ex. "tcp80" without adding anything on the protocol type ( in advanced properties , for example http has "http").
After you must add a rule for this host/new service:

old rule
any -> host -> http /any > accept

new rule
any-> host-> tcp80 > accept
Maurox
Reply With Quote
  #7 (permalink)  
Old 2006-08-30
Junior Member
 
Join Date: 2006-08-17
Location: Sao Paulo
Posts: 3
Rep Power: 0
alucinado has an average reputation (10+)
Default Re: How to turn off Smart Defense for one specific host

Yes, you can do this editing the asm.def file located in $FWDIR/lib. The procedure is available at checkpoint with the number sk31918 (the only problem is that you need the advanced access to read this article).
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:53.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0