CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-28
Member
 
Join Date: 2006-02-05
Posts: 74
Rep Power: 3
jmcgrady has an average reputation (10+)
Default X11 enforcement violation

The smartdefence on my firewall is reporting x11 enforcement violation for tcp ports 6000-6063. I have an 'any' port rule which is triggering the reject. The advice says i should create a specific rule. I'd prefer to just turn off this detection in smartdefence. But i cant see a corresponding smart defence rule. Where can i switch this off?
Reply With Quote
  #2 (permalink)  
Old 2008-01-28
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: X11 enforcement violation

Are you trying to use X11 and getting blocked? I can't tell why this is a problem from your note.

If you're trying to use X11, you must create a new rule with X11 as the service. X11 is specifically excluded from being included in "any".

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-01-28
Member
 
Join Date: 2006-02-05
Posts: 74
Rep Power: 3
jmcgrady has an average reputation (10+)
Default Re: X11 enforcement violation

We are not actually using X11. Some user apps use high ports which are triggering this reject. The rule is effectively a firewall-bypass so i want 'any' to mean 'any'.
Reply With Quote
  #4 (permalink)  
Old 2008-01-30
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: X11 enforcement violation

You can create a new service for those ports and flag it "Match on any" and that should work.
Reply With Quote
  #5 (permalink)  
Old 2008-03-05
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: X11 enforcement violation

Hi Ray

Quote:
Are you trying to use X11 and getting blocked? I can't tell why this is a problem from your note.

If you're trying to use X11, you must create a new rule with X11 as the service. X11 is specifically excluded from being included in "any".
What to do if this traffic has to pass through VPN
Reply With Quote
  #6 (permalink)  
Old 2008-03-06
Senior Member
 
Join Date: 2006-10-23
Posts: 168
Rep Power: 3
Danielpb has an average reputation (10+)
Default Re: X11 enforcement violation

I ran into this issue when a customer wanted to use an actual 'ANY' rule.

As ANY does not mean ANY in checkpoint...even if Match ANY is selected.

The X11 service will not be part of the ANY checkpoint selection. You have to create a rule to allow this...I think the checkpoint SK explains a bit more, which I would add if the support site was not so cack. (Finally - sk24600)

To reach my goal I had to create a service which was from 1-65535 which include everything. (An ANY service rule)

May be this is wrong but it was the only work around I could find.

Last edited by Danielpb; 2008-03-06 at 03:54.
Reply With Quote
  #7 (permalink)  
Old 2008-03-06
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: X11 enforcement violation

Quote:
Originally Posted by RayPesek View Post
If you're trying to use X11, you must create a new rule with X11 as the service. X11 is specifically excluded from being included in "any".
Or the alternative is to add X11 back into "any" by unchecking here:

SmartDashboard -> Policy -> Global Properties -> SmartDashboard Customization -> Configure button under Advanced Configuration -> Firewall-1 -> Stateful Inspection -> reject_x11_in_any

HTH
__________________
Its all in the documentation.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:12.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0