You should be able to define a port range by placing a hyphen between the lower and upper limits in the Port type in box. Of course the main stipulation is that you know what the range is. Place the service for the initial connection and the port range in the rule and you should be set. The best security practice is to be more specific, but you can limit your exposure by controlling the source address.
-Bob
Iztok Umek wrote:
Yes, but I tunnelled it in IPSEC at both ends first (Windows 2000 servers...)
Anyone successfully use Sun Java RMI calls over Firewall-1?
This "weird" protocol opens random ports once the initial connection
is established.
Interesting solution but...
This will not work. As I have Win2k, Solaris and Linux mixture. Any other suggestions? To be honest I can't believe CheckPoint doesn't have solution for it yet.
================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
-- Bob Scipioni <[EMAIL PROTECTED]> Vice President, Product Development Lucid Security Research & Product Development www.lucidsecurity.com
================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
