In the destination, you should put in the FW objects as well as either the Cluster Object, or the VIP object.  This will cover all the Firewall Interfaces, so traffic will be dropped going to any interface (from DMZ, Lan, Public side, etc)
-----Original Message-----
From: Security Guy [mailto:[EMAIL PROTECTED]
Sent: Monday, March 10, 2003 5:26 PM
To: [EMAIL PROTECTED]
Subject: [FW-1] stealth rule questions

To make a long story short the "stealth" rule was removed from our firewall.  It will be re-added this week, however I just want to make sure the rule is setup properly
 
example rule:
Source: Any  Destination: firewalls  Service: Any  Action: Drop  Track:Long  Install on: gateways  Time:any
 
I'm wondering about the destination, to what interface does this apply? 
 
Ext (public IP) 11.7.113.x  [example only]
Dmz: 10.0.0.x & 192.168.1.x  [example only]
Internal: 10.200.130.X  [example only]
 
*FW Specs: twin nokia ip440's, [VRRP mode] checkpoint 4.1, one service pack behind current*
 
So to finally ask the question, does my rule check out & what interface or IPs should I use as my "destination"
 
Thanks
================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================

Reply via email to