CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Sun Solaris
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-02
Junior Member
 
Join Date: 2007-01-19
Posts: 4
Rep Power: 0
rldeshpande has an average reputation (10+)
Default Solaris Hardening

Hi everyone,

I'm pretty new to CP, and have been asked to install and configure CP for testing against some applications.

Well, my solaris box (V210) has no console attached and I use ReflectionX from a win box to connect and install CP. Before I could configure CP, somehow the solaris box was rebooted, and due to the OS hardening that happens during CP install, all communication ports to this solaris box are blocked. Not able to ping, telnet, ssh, nothing.

If I start everything again, is there a way/ option to prevent this hardening that happens during CP install?

I installed R55 on Solaris 8.

Thanks in advance,
~Rahul
Reply With Quote
  #2 (permalink)  
Old 2007-03-02
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Solaris Hardening

well i guess its a initial policy after reboot that is blocking.

One way is to push the policy that allows traffic. SIC and policy push is allowed between module and smartcenter.

If u want to disable initial policy for brief time during testing use control_bootsec -r. To put it back control_bootsec -g
Reply With Quote
  #3 (permalink)  
Old 2007-03-02
Junior Member
 
Join Date: 2007-01-19
Posts: 4
Rep Power: 0
rldeshpande has an average reputation (10+)
Default Re: Solaris Hardening

Thank you very much for your reply.

Yes, it's the initial policy. But this policy has nothing but all the implied rules.
And whenever I create a new policy, same implied rules are present there too.
So I dont know how to create a policy which will allow the traffic.

control_bootsec: Could you please tell me how to use it? I mean when I tried it at the command prompt, I got messages as
root# control_bootsec -r
Disabling boot security
Could not successfully remove boot security
root# control_bootsec -g
Enabling boot security
Could not successfully re-enable boot security

~Rahul
Reply With Quote
  #4 (permalink)  
Old 2007-03-02
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Solaris Hardening

Quote:
Originally Posted by rldeshpande View Post
Thank you very much for your reply.

Yes, it's the initial policy. But this policy has nothing but all the implied rules.
And whenever I create a new policy, same implied rules are present there too.
So I dont know how to create a policy which will allow the traffic.

control_bootsec: Could you please tell me how to use it? I mean when I tried it at the command prompt, I got messages as
root# control_bootsec -r
Disabling boot security
Could not successfully remove boot security
root# control_bootsec -g
Enabling boot security
Could not successfully re-enable boot security

~Rahul
Hi,

Initial policy is the one that is active when no other policy is pushed to the module and the one that is used during boot up. It means that you need to push a new policy from your smartcenter which includes proper accept rules for your traffic. For example add a rule <src: your mgmt pc> <dst: firewall module> <service: any> <action Accept>. And install this policy on your module via smartdashboard.

control_bootsec is used via cli (just ssh to box or whatever). Its strange that you got errors above that it wasnt able to unload. Remember you have to execute this command on the FIREWALL module, not the smartcenter (since smartcenter dont have any initial policy).

I hope you understand what i mean otw we keep posting :)
Reply With Quote
  #5 (permalink)  
Old 2007-03-02
Junior Member
 
Join Date: 2007-01-19
Posts: 4
Rep Power: 0
rldeshpande has an average reputation (10+)
Default Re: Solaris Hardening

Hey Abusherif,

As you said earlier, I tried to execute the command on the same box by ssh.

Now somehow the system got rebooted, and now all communication ports are blocked. No ssh, no telnet, not even ping. And this boz has no console... cannot logon there physically. I guess I have to start everything again.
:(
~Rahul
Reply With Quote
  #6 (permalink)  
Old 2007-03-05
Member
 
Join Date: 2005-09-04
Location: Perth
Posts: 40
Rep Power: 0
seanmac1904 has an average reputation (10+)
Default Re: Solaris Hardening

can you use a serial link ?

connect a serial cable to the ALOM and get the console from there

cheers

Sean
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:58.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0