RE: [fw-wiz] Questions about converting FW-1 ruleset to PIX - sor t of...
- From: Ralf.Zessin@xxxxxxxxxx
- Date: Tue, 24 Jan 2006 13:50:13 +0100
Hi Nick,
> One of the checkpoint rules denies traffic from all internal networks
> for a group of specific ports destined to a group that contains all of
> the DMZ servers and also to the DMZ network itself - a DMZ object
> group.
>
> My questions is: What is the purpose of having the the servers "and"
> the dmz network listed in the destination? Is this necessary?
>
No, the information is redundant. But if there is above a rule which
explizit allows traffic which is blocked by this rule, this traffic
has to go through.
Checkpoint evaluates its rule form top to down and first ( not best )
match is taken.
But what is this for a rule-design where Ports/traffic are explicit denied
if it
was not an alert-rule ? Normaly all traffic has to be forbidden and
I have to *allow* traffic by rules.
- Ralf
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
- Follow-Ups:
- Re: [fw-wiz] Questions about converting FW-1 ruleset to PIX - sor t of...
- From: nick leachman
- Re: [fw-wiz] Questions about converting FW-1 ruleset to PIX - sor t of...
- Prev by Date: Re: [fw-wiz] RE: In defense of non standard ports
- Next by Date: RE: [fw-wiz] False results to DMZ
- Previous by thread: [fw-wiz] Scanning host thru Check Point
- Next by thread: Re: [fw-wiz] Questions about converting FW-1 ruleset to PIX - sor t of...
- Index(es):
Relevant Pages
|