RE: [Full-Disclosure] PIX vs CheckPoint

From: James Patterson Wicks (pwicks_at_oxygen.com)
Date: 06/30/04

  • Next message: Abraham, Antony (Cognizant): "RE: [Full-Disclosure] PIX vs CheckPoint"
    To: "Cyril Guibourg" <plonk-o-matic@teaser.fr>, "Otero, Hernan (EDS)" <HOtero@lanchile.cl>
    Date: Wed, 30 Jun 2004 15:41:26 -0400
    
    

    That is odd. When dealing with a Pix firewall, no traffic can go out an interface without some sort of translation statement.

    Even the default configuration has this:

         nat (inside) 1 0.0.0.0 0.0.0.0 0 0

    There must be either a static or dynamic translation statement in your configuration.

    -----Original Message-----
    From: full-disclosure-admin@lists.netsys.com [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of Cyril Guibourg
    Sent: Wednesday, June 30, 2004 2:18 PM
    To: Otero, Hernan (EDS)
    Cc: full-disclosure@lists.netsys.com
    Subject: Re: [Full-Disclosure] PIX vs CheckPoint

    "Otero, Hernan (EDS)" <HOtero@lanchile.cl> writes:

    > I think you do, because at least a nat 0 itīs needed to get traffic passing
    > through the pix.

    This is odd, I do have a running config under 6.2 without any nat statement.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    This e-mail is the property of Oxygen Media, LLC. It is intended only for the person or entity to which it is addressed and may contain information that is privileged, confidential, or otherwise protected from disclosure. Distribution or copying of this e-mail or the information contained herein by anyone other than the intended recipient is prohibited. If you have received this e-mail in error, please immediately notify us by sending an e-mail to postmaster@oxygen.com and destroy all electronic and paper copies of this e-mail.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Abraham, Antony (Cognizant): "RE: [Full-Disclosure] PIX vs CheckPoint"

    Relevant Pages

    • Re: restore factory defaults
      ... To reset the PIX Firewall to factory default, log into the PIX, erase ... Password Recovery and AAA Configuration Recovery Procedure for the PIX ... fixup protocol http 80 ...
      (comp.dcom.sys.cisco)
    • Re: Problems configuring my PIX525
      ... Your pix configuration seems fine to me. ... You wrote that you have hooked a client directly to the pix interface, ... > no snmp-server location ...
      (comp.security.firewalls)
    • Re: PIX FireWall and SBS
      ... >> PIX. ... >> in controlling access to the internet. ... >> To configure your PIX for use with a DSL PPoE DHCP connection use the ... >> If Earthlink do not use PPoE the configuration above won't be usable. ...
      (microsoft.public.windows.server.sbs)
    • Re: PIX FireWall and SBS
      ... >> PIX. ... >> in controlling access to the internet. ... >> To configure your PIX for use with a DSL PPoE DHCP connection use the ... >> If Earthlink do not use PPoE the configuration above won't be usable. ...
      (microsoft.public.windows.server.sbs)
    • [fw-wiz] The answer to the PIX encryption issue
      ... attack much harder up to the point when they become computational ... In order to prevent interception of the configuration files for the ... PIX particularly during transfer between devices, ... the same configuration file among multiple PIXes should be ...
      (Firewall-Wizards)