RE: CheckPoint remote access

From: Dave Gilmore (Intrusense) (dgilmore_at_intrusense.com)
Date: 09/15/03

  • Next message: Dana Smith: "RE: Comcast and IPSec traffic"
    To: "'Yew Kwee Tan'" <yewkwee@yahoo.com.sg>, <security-basics@securityfocus.com>
    Date: Mon, 15 Sep 2003 12:46:24 -0400
    
    

    Hello,

    It sounds like the firewall policy is getting in your way. If possible,
    I suggest you console in as you did earlier with HyperTerminal and
    unload the locally installed policy. This can be accomplished with the
    following command on Firewall-1 4.1:

    #> fw unload localhost

    This will disable (or unload) the currently installed firewall policy an
    allow you to connect remotely. Please bare in mind that this will also
    disable the install NAT policy.

    I hope that helps,

    Dave Gilmore
    Information Security Analyst

    --
    Intrusense - Securing Business As Usual
    -----Original Message-----
    From: Yew Kwee Tan [mailto:yewkwee@yahoo.com.sg] 
    Sent: Sunday, September 14, 2003 2:01 AM
    To: security-basics@securityfocus.com
    Cc: yewkwee-tan@axvantage.com
    Subject: CheckPoint remote access
    Hi, can some CheckPoint guru provide some advise on
    the following?
    Checkpoint firewall running version 4.1 is facing
    problem of unable to access remotely. Suspect it was
    due to log file overflow as noticed the disk occupancy
    is 99%, have delete the log files by connecting hyper
    terminal to the console port, but still unable to
    access with the following means:-
    1. Connect notebook directly to ethernet port with IP
    address 10.1.2.5, the IP address on firewall ethernet
    port is 10.1.2.2. Tried using both cross UTP
    cable and straight UTP cable with same error of "media disconnected". 2.
    Tried accessing the firewall via ssh but failed with error "connection
    refuse". 3. Tried accessing ther firewall via web browser
    https://ipaddress:10000, with error "The Page Cannot Be Displayed". 4.
    Tried accessing the firewall via Checkpoint Management Client, with
    error "Cannot Connect To Server".
    =====
    Thanks/regards
    Tan Yew Kwee
    __________________________________________________
    Do You Yahoo!?
    Play now and stand a chance to win cash prizes! 
    http://yahoo.com.sg/millionaire
    ------------------------------------------------------------------------
    ---
    Captus Networks 
    Are you prepared for the next Sobig & Blaster? 
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans 
     - Precisely Define and Implement Network Security 
     - Automatically Control P2P, IM and Spam Traffic 
    FIND OUT NOW -  FREE Vulnerability Assessment Toolkit 
    http://www.captusnetworks.com/ads/42.htm
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    Captus Networks 
    Are you prepared for the next Sobig & Blaster? 
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans 
     - Precisely Define and Implement Network Security 
     - Automatically Control P2P, IM and Spam Traffic 
    FIND OUT NOW -  FREE Vulnerability Assessment Toolkit 
    http://www.captusnetworks.com/ads/42.htm
    ----------------------------------------------------------------------------
    

  • Next message: Dana Smith: "RE: Comcast and IPSec traffic"

    Relevant Pages

    • ISA 2004 - Not processing rule?
      ... Edge Firewall template configuration. ... skeptical about letting DHCP Replies come from the External interface - ... The problem I am facing is that when I create a firewall policy with the ... My Custom Protocol is defined as TCP Outbound for port 5000 ...
      (microsoft.public.isa)
    • ISA 2004 - Not processing rule?
      ... Edge Firewall template configuration. ... skeptical about letting DHCP Replies come from the External interface - ... The problem I am facing is that when I create a firewall policy with the ... My Custom Protocol is defined as TCP Outbound for port 5000 ...
      (microsoft.public.isa.configuration)
    • Re: How to find NATed address
      ... > NAT workarounds. ... > response from company Splortsoft who tells me that their ... > to defeat local firewall policy - after all, ... > Splortsoft allows malicious contravention of firewall policy ...
      (comp.security.firewalls)
    • ISA 2004 - Not processing rule?
      ... Edge Firewall template configuration. ... skeptical about letting DHCP Replies come from the External interface - ... The problem I am facing is that when I create a firewall policy with the ... My Custom Protocol is defined as TCP Outbound for port 5000 ...
      (microsoft.public.isaserver)
    • Re: keeping ports open
      ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
      (microsoft.public.security)