You should be able to define a port range by placing a hyphen between
the lower and upper limits in the Port type in box.  Of course the main
stipulation is that you know what the range is.  Place the service for
the initial connection and the port range in the rule and you should be
set.  The best security practice is to be more specific, but you can
limit your exposure by controlling the source address.

-Bob


Iztok Umek wrote:


Yes, but I tunnelled it in IPSEC at both ends first (Windows 2000
servers...)



Anyone successfully use Sun Java RMI calls over Firewall-1?

This "weird" protocol opens random ports once the initial connection





is established.



Interesting solution but...


This will not work. As I have Win2k, Solaris and Linux mixture. Any
other suggestions? To be honest I can't believe CheckPoint doesn't have
solution for it yet.

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================



-- Bob Scipioni <[EMAIL PROTECTED]> Vice President, Product Development Lucid Security Research & Product Development www.lucidsecurity.com



=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to