Re: RPC Dynamic Ports? Windows 2003 with Checkpoint firewall.

From: Richard H. Miller (rick_at_bcm.tmc.edu)
Date: 08/21/05


Date: 21 Aug 2005 13:54:57 GMT

Volker Birk (bumens@dingens.org) wrote:
: Richard H. Miller <rick@bcm.tmc.edu> wrote:
: > The OP is discussing how to pass Microsoft RPC from one interface to another within
: > the same checkpoint enforcement module. This is what the enforcment modules are
: > designed to do and there is no reason for a VPN since the traffic is only traversing
: > the module and is never on the net.

: Then this type of filtering does not make sense. Why should one filter
: in between one trusted host and another, when they're connected directly?

You do understand the purpose of a 'DMZ' in an enterprise firewall security security
setup? You have multiple interfaces, each with a LAN behind it and a different security
policy for that interface. The classic is a DMZ in which you have a set of machines that
you need to be visible to the internet. They will require some access to specific services
that exist on machines that exist in the internal LAN so the policy needs to be written
to allow those machines to obtain the specific services. In the case of the OP, he has
put a member server into the 'DMZ' and has decided that allowing it to participate in
his domain is an acceptible risk so wants the DCE-RPC traffic to pass from that member
server to his DC. Other traffic between the two is outside of policy and should not
happen.

This is the entire point, you define a policy to specify the appropriate traffic between
host in one zone to another. Bear in mind, Checkpoint with smartdefense is an enterprise
firewall implementation



Relevant Pages

  • Re: Windows XP remember GP when removed from domain
    ... security template ... ... Windows Platform Support Team ... > machines is what I'd ... >>Security policy is an actual registry change that needs ...
    (microsoft.public.windows.group_policy)
  • Re: Can anyone shed some light on what my programmers want me to do?
    ... Essentially what they are asking you to do is deploy .Net security policies on your machines such that someone could run a .Net app from a network drive. ... From there you can adjust Framework security settings to allow any apps run from the Local Intranet Zone to have Full Trust. ... Essentially what that does is create an .MSI file that contains these security policy settings. ...
    (microsoft.public.dotnet.general)
  • Re: Publishing Software...
    ... Are the users on the machines in question, members of the local Administrators group?? ... The Group Policy client-side extension Security failed to execute. ... User Rights configuration was completed with one or more errors. ...
    (microsoft.public.windows.server.sbs)
  • Re: Performance problem when domain security policies are applied
    ... is particularly expensive, such as registry or file system security, esp. ... MS-MVP-Windows Server--Group Policy ... > updating group policy objects on machines in a domain. ... > time during the period of this security update. ...
    (microsoft.public.win2000.group_policy)
  • Re: Advice required for training room setup
    ... # Interface IP Configuration for "Local Area Connection" ... We also use a lot of virtual machines. ... > - Restore trainer's machine to latest Software A image, ...
    (microsoft.public.win2000.setup_deployment)