CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Windows
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-08-08
Member
 
Join Date: 2008-08-07
Posts: 40
Rep Power: 0
vbavbalist has an average reputation (10+)
Default Urgent need for hardening Windows 2003 Server for NGX R65 installation

Hi,

Im in an urgent need to have a checklist for hardening windows 2003 server which NGX R65 firewall will be installed . So we need to harden the OS for security but also let the firewall run normally. I found that that there is Checkpoint article which is called sk26458 but i cant access it. Any help (for mostly providing Checkpoints articles content ) will be valuable.


Regards
Reply With Quote
  #2 (permalink)  
Old 2008-08-08
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 582
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Urgent need for hardening Windows 2003 Server for NGX R65 installation

Quote:
Originally Posted by vbavbalist View Post
Hi,

Im in an urgent need to have a checklist for hardening windows 2003 server which NGX R65 firewall will be installed . So we need to harden the OS for security but also let the firewall run normally. I found that that there is Checkpoint article which is called sk26458 but i cant access it. Any help (for mostly providing Checkpoints articles content ) will be valuable.


Regards
Step 1. Insert the SecurePlatform R65 CD-ROM into your CD-ROM drive.

Step 2. Reboot.

Step 3. Follow the instuctions.

You should be all set.

Glad to be of help.

Barry
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
  #3 (permalink)  
Old 2008-08-08
Member
 
Join Date: 2008-08-07
Posts: 40
Rep Power: 0
vbavbalist has an average reputation (10+)
Default Re: Urgent need for hardening Windows 2003 Server for NGX R65 installation

thanks Barry for your answer,

But will the runnning the setup of NGX R65 will also harden the Windows 2003 Server? ı dont think so? I have made Splat installations before so no hardening was required but i have to install on windows this time.

Regards
Reply With Quote
  #4 (permalink)  
Old 2008-08-08
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 255
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Urgent need for hardening Windows 2003 Server for NGX R65 installation

No one will recommend you to use Microsoft Windows for a firewall installation, because:
(1) you have to pay an additional license for it
(2) you have to understand and follow Microsoft's update cycles which may not be in sync with Check Point's updates.
(3) you are taking the risk for incorrectly hardening the Microsoft OS
(4) Check Point only supports its own SPLAT. If you want to receive support for Windows you will have to contact Microsoft.

However. If you are looking for a hardening guide, why not taking the one from NSA? URL: Operating Systems Guides

You have not explained why you won't use the ones publicly available everywhere.
Reply With Quote
  #5 (permalink)  
Old 2008-08-08
Member
 
Join Date: 2008-08-07
Posts: 40
Rep Power: 0
vbavbalist has an average reputation (10+)
Default Re: Urgent need for hardening Windows 2003 Server for NGX R65 installation

Hi dantro,

Firstly this is my 2nd week at this company,though they know my experience they only want me to connect to firewall (read only yet). There (said to be) 2 firewall on windows 2003 server , one is online and one is resting in peace. Windows 2003 server is not my choice of course i prefer to install on SPLAT if the manager says so.

For the Checkpoint article choice as you said i dont want to misharden the OS to cause improper functioning and also maybe a security lack.

Thanks for reminding me the NSA guides, I have found some inf files for bastion host role from Microsofts Windows 2003 server security guide yesterday. But as i said Checkpoints article is i guess came from the Checkpoint's (product experience) so starting with their article will make me feel better.

Thanks and regards
Reply With Quote
  #6 (permalink)  
Old 2008-08-08
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 255
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Urgent need for hardening Windows 2003 Server for NGX R65 installation

Be sure that I've looked for the sk you've mentioned. I've got expert mode access but couldn't find the article. So it's either set to 'Check Point internals only' or you did a typing mistake.
Reply With Quote
  #7 (permalink)  
Old 2008-08-08
Member
 
Join Date: 2008-08-07
Posts: 40
Rep Power: 0
vbavbalist has an average reputation (10+)
Default Re: Urgent need for hardening Windows 2003 Server for NGX R65 installation

Hi,

Thanks for checking , i got the sk number from Windows 2003 Server Hardening guide which i found from googleing. So i dont know if something is wrong with the sk number. But i think that there must be a public available cause there must be many companies which uses the windows version of the firewall (of course the ratio supports SPLAT)

Regards
Reply With Quote
  #8 (permalink)  
Old 2008-08-08
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 255
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Urgent need for hardening Windows 2003 Server for NGX R65 installation

Seems like it has been removed from the Secure KnowledgeBase.
Reply With Quote
  #9 (permalink)  
Old 2008-08-11
Member
 
Join Date: 2008-08-07
Posts: 40
Rep Power: 0
vbavbalist has an average reputation (10+)
Default Re: Urgent need for hardening Windows 2003 Server for NGX R65 installation

Yes that must be occured, what a luck. Thanks for the interest , if you can add something more ill like to go on to the thread
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:32.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0