Sup FW-Guruz and FW-1 List
 
Platform:
NOKIA IP 350  
NG AI R54
 
Issue:
We are having an Issue a recent upgrade to the 350 with NG has prevented
us from using MS client PPTP and Hide NAT to VPN to client sites.
(https://support.checkpoint.com/kb/public/idsearch.jsp?id=sk12234&QueryT
ext=%28%28sk12234%29%29&resultStart=1)
 
So the only given resolution is to use static mappings for each
workstation to allow VPN transport from house to client's,,, Fine and
dandy... The static mappings expose local system ports to the Internet
leaving MS workstations wide open. I would think that NG would have the
ability to filter the static mappings but I am not that familiar with it
yet and the vendor cannot tell me how.
 
Secure Solution:
Mutli-home each workstation and lock down the public nics with IP
filtering in MS TCP/IP.
Load Desktop firewall such as Black Ice (hella Exploits) Norton Internet
Sec, ect. (any other suggestions would be appreciated).
 
Or Figure out how to secure statically mapped machines with NG?
Anyone?
 
Thanks,
Z.N.
 Network Systems Engineer
Three Rivers Systems Inc.
636-532-2460-voice
636-532-1641-fax
 <mailto:[EMAIL PROTECTED]> [EMAIL PROTECTED]
 
 
The information in this e-mail is confidential and may be legally
privileged. It is intended solely for the addressee and access to this
e-mail by anyone else is unauthorised. If you are not the intended
recipient, any disclosure, copying, distribution or any action taken or
omitted to be taken in reliance on it is prohibited and may be unlawful.
Views and opinions are those of the sender unless clearly stated as
being that of the Company's. The Company can not assure that the
integrity of this communication has been maintained nor that it is free
of errors, virus, interception or interference. No liability, whether
direct or indirect, is accepted by the company, nor the sender should
this e-mail, or any attachment thereto, contain any form or manner of an
error or a virus.
 

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to