| Allowing Domain / DNS based objects through a Check Point Firewall |
| Vendor | Check Point |
| Platform | SPLAT |
| Version | R65 NGX |
| Firewalls - Checkpoint |
| Thursday, 01 April 2010 15:43 |
|
In order to to allow domain based objects through a Check Point firewall we need to understand how the domain objects actually work. Below takes a closer look at this process. When a packet hits a rule containing a domain based object the firewall does the following :
Below you can see the DNS process of a domain object using ftp.symantec.com. Note : Firewall IP = 22.19.1.1 | DNS Server = 2.2.2.2. Now this can cause problems if the PTR record doesn't match the domain name of the A Record as the Check Point Firewall will drop the traffic believing that the destination you are trying to reach isnt that of the Domain object. Note : You can also spot the PTR record being displayed rather then the domain name of the object as the destination name within the logs when troubleshooting these kind of issues. This is a quick and easy step to confirm that the PTR record doesn't match your domain name Another way to to check your PTR record is via the following steps : A number of companies will have PTR records that do not match their domain name (A record), which when trying to allow access through a Check Point can cause issues as the Firewall will just drop the traffic. Solution The best solution to resolve this issue is to have your traffic pass via an internal proxy. Proxies are designed and better suited for allowing and denying such traffic compared to a Check Point Firewall. Also there are massive performance issues with using Check Points domain objects and URI resources. FTP Within Check Point you can configure a FTP resource. This allows you to configure a path which can then be denied or allowed within a rule. The problem with this is that you cannot specify the host but only the path. 2. Assign the FTP Resource a name 3. Assign a path and the action method(s). 4. Right click on a new rule and select Service with Resource. 5. Then add the rest of the actions to the rule such as source and destination etc.
HTTP The HTTP security server gives you much more options. Below shows you the steps : 1. Create a new HTTP resource 2. Add a name and the connection method(s). These are based on the following :
3. Select HTTP, the method and the hostname of your server. 4. Right click on a new rule and select Service with Resource. Then add the rest of the actions to the rule such as source and destination etc. |
Latest Articles
- F5 LTM VE 10.2.x - Interfaces not recognised
- Cisco ASA - Security Levels / NAT Control
- F5 LTM - OneConnect
- Django - CSRF verification failed. Request aborted.
- F5 LTM VE - Unable to attach to PCI device 02:01.00 for Interface 1.1
- F5 LTM - Connection Management
- Brocade ADX - FTP
- PKI - Chain of Trust
- Juniper SRX - Site to Site VPN using a Dynamic IP address
- F5 LTM - How do I perform software installations ?
- Juniper SRX - NAT
- Juniper SRX - How to configure a route based VPN
- Juniper SRX - Dynamic VPN
- Juniper SRX - How to configure a policy based VPN
- Brocade ADX - NAT
- Brocade ADX - CSW nested rules
- How do I upgrade a Juniper SRX Series gateway
- Cisco ASA - How do I capture ARP`s ?
- Juniper SRX - Configuring Source NAT with pool
- Running a packet capture on a Juniper SRX
Popular
- Proxy ARP – SPLAT
- Check Point Commands
- IPSO - Commands
- ASA 8.3 - How to configure NAT
- vSphere - Creating User and Group Permissions
- PEMU - Free Cisco PIX Firewall Emulator / Simulator
- Configuring Wireless Connectivity within Backtrack 4 r2
- Juniper Netscreen Commands
- Juniper Netscreen - NAT Explained
- How do I install snmpwalk / snmpget using Yum ?
- Netscreen - NSRP
- ESX Convertor - The session is not authenticated
- Troubleshooting a Netscreen Site 2 Site VPN
- ESX - ViClient Cannot connect to host
- Endpoint Connect Installation / Troubleshooting Guide
- Check Point - How to Reset SIC
- ESXi - Connecting to a named pipe
- Netscreen - Routing Basics / Virtual Routers / PBR
- Check Point Logging Troubleshooting Guide
- Configuring Windows 2008 R2 as an NTP Server
