Is that really an issue? I thought NG allowed you to specify that a user had
to be authenticated before a topology download would be allowed. I believe
4.1 alowed unauthenticated downloads, though.

Perhaps you're on NG requiring authentication and they are on v4.1 in their
thinking?

You really have to be careful about security audit recommendations. A very
common one is to disable null session logons to NT servers. Although this
usually is benign, Veritas Backup prior to version 8.5 or so required it.
Can't remember the exact version where they fixed this. So, if you were
using Veritas and you followed the recommendation, your backups broke as a
result.

Ray Pesek, CISSP





From: Simon Ashford <[EMAIL PROTECTED]>
Reply-To: Mailing list for discussion of Firewall-1
<[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: [FW-1] Disabling certain Firewall-1 "control connections" ports.
Date: Thu, 5 Feb 2004 21:25:50 -0000

Hello,

In a recent security audit, I was advised to disable external
access to TCP port 264 (FW1_topo) because it could be used to
extract detailed network topology information from my firewall.

So far the only way I found to do this was to disable "Accept
VPN-1 & Firewall-1 control connections" in the Global Properties
pane.  But if I do this, then all my IPSEC VPNs also stop working.

I tried adding a rule to allow specific IKE and IPSEC packets
through, but this didn't appear to work.  In the log it says
"encryption failure: received a cleartext packet within an
encrypted connection" at the start of any IKE negotiation.
Ths is logged against the rule I created specifically to allow
IKE.

Can anyone suggest a way to make this work?


Thanks in advance for any help.



Simon Ashford.



-- Simon J. Ashford, Email: [EMAIL PROTECTED] IT Support Unit Tel: +44 (0)20 8943 7032 National Physical Laboratory, Fax: +44 (0)20 8943 7093 Teddington, Middlesex, UK. WWW: http://www.npl.co.uk/

-------------------------------------------------------------------
This e-mail and any attachments may contain confidential and/or
privileged material; it is for the intended addressee(s) only.
If you are not a named addressee, you must not use, retain or
disclose such information.

NPL Management Ltd cannot guarantee that the e-mail or any
attachments are free from viruses.

NPL Management Ltd. Registered in England and Wales. No: 2937881
Registered Office: Teddington, Middlesex, United Kingdom TW11 0LW.
-------------------------------------------------------------------

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

_________________________________________________________________ Click here for a FREE online computer virus scan from McAfee. http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=3963

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to