[fw-wiz] Questions about converting FW-1 ruleset to PIX - sort of...



Hi,

I'm converting a set of rules from a checkpoint fw to a PIX 515e; and
I want to better understand a rule on the checkpoint. The questions
revolve more around thoroughness than the different models.

Both the checkpoint and the pix are three interface units with one dmz
each. For the discussion here the DMZ network address is
172.16.0.0/16.

One of the checkpoint rules denies traffic from all internal networks
for a group of specific ports destined to a group that contains all of
the DMZ servers and also to the DMZ network itself - a DMZ object
group.

My questions is: What is the purpose of having the the servers "and"
the dmz network listed in the destination? Is this necessary?

On the PIX my plan was to replace the above checkpoint rule with one similar to:

access-list deny tcp any 172.16.0.0 255.255.0.0 object-group
denied_dmz_tcp_ports

Am I opening a hole I don't understand by not denying traffic to both
the network and the servers, but instead only using the rule above?

Many thanks,
Nick
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • VPN - Cisco PIX to Checkpoing FW-1 troubleshooting
    ... I was trying to establish VPN between a pix and a checkpoint. ... isakmp policy 10 authentication pre-share ...
    (comp.security.firewalls)
  • Re: Nokia and CheckPoint or Cisco?
    ... Currently use a Nokia IP330 box with CheckPoint on. ... Cisco PDM has a basic GUI for PIX. ... active/standby mode, except when PIX 7.x is configured using multiple ...
    (comp.security.firewalls)
  • RE: Firewall recommendations?
    ... I have run both Checkpoint and PIX in my environment. ... The PIX is a true stateful inspection firewall. ... I am not a big fan of the pix and I have never played with the ISA ...
    (Security-Basics)
  • RE: Firewall recommendations?
    ... Hi at my current job we use checkpoint, and I personally love that firewall ... I am not a big fan of the pix and I have never played with the ISA ...
    (Security-Basics)
  • Re: CheckPoint + ISA2004 Nating
    ... servers.If those servers in DMZ segment have been nated then the Incomming ... You should modify the NATs on your Checkpoint so that all traffic is ... forwarded to the external interface IP of ISA instead of individual ...
    (microsoft.public.isa.configuration)