CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-18
Senior Member
 
Join Date: 2006-02-18
Posts: 103
Rep Power: 3
ChrisA has an average reputation (10+)
Default Anti-Spoofing "Interface leads to DMZ" check box

We're running R62. This checkbox is under the Internal radio button in the Topology tab of the Interface. It seems that you might check this box instead of selecting a radio button under "IP Addresses behind this interface", but I'm not sure, I don't ever recall seeing the option, and I can't find any mention of it in the manuals. Does anyone know how this option works? Better yet, can you point me to the place in the docs where it is described/explained? Thank you all!
Reply With Quote
  #2 (permalink)  
Old 2007-06-18
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: Anti-Spoofing "Interface leads to DMZ" check box

Great question!

The help file is clear as mud. All it says is that the DMZ is considered an internal network. I also searched the PDFs and the SK - nothin.

I have to defer to some of the other, wiser, more knowledgeable folks here - I'm stumped. If no one answers, you should submit a request to the people at CheckPoint who maintain the help files.
Reply With Quote
  #3 (permalink)  
Old 2007-06-19
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Anti-Spoofing "Interface leads to DMZ" check box

Wasn't easy, but I think I "found" it. It's a UTM-1 only thing.

Read this one "CheckPoint_R62_Firewall_SmartDefense_UserGuide.pd f", page 198.

Basically it's informational only, so that when you are defining your Anti-virus policies you can define what traffic flows you want to scan.

If you go to the "Content Inspection" tab and select one of the protocols to be scanned you will see what I mean. The scan is by default based on "File direction" and there are some drop down boxes with a few options. The DMZ checkbox will influence these.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:02.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0