Eric,

   Yes this implies another license, but its list price is only $1000 ;-))

Met vriendelijke groeten - Bien � vous - Kind regards
Guy ROELANDTS
EMEA HPS Internet Expertise Centre - CCSE-NG
Hewlett-Packard Belgium B.V.B.A./S.P.R.L.
E-mail : [EMAIL PROTECTED]
Tel: +32(02)729.85.61
Fax: +32(02)729.77.65
==========================================================
This message may contain confidential and/or proprietary information,
and is intended only for the person/entity to whom it was originally
addressed. The content of this message may contain private views and
opinions which do not constitute a formal disclosure or commitment
unless specifically stated. Should you receive this message by mistake
please inform the sender immediately.
==========================================================



-----Original Message-----
From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of 
Eric Appelboom
Sent: Wednesday, February 11, 2004 17:47
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Protecting your splat management station


Guy,

But that would require a fw1 licence right.

I am going to try applying Port-based acls (cisco) and only permitting
the mac addresses of fw1 nodes to chat to the management server port which
means that the fw must have inspected and accepted the traffic.

Regards
Eric


-----Original Message-----
From: Roelandts, Guy [mailto:[EMAIL PROTECTED]
Sent: 11 February 2004 06:11 PM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Protecting your splat management station


Eric,

>With regard to protecting a NG management station. (SecurePlatform)

>If you have a management station behind your firewall(192.168.123.10)
>Nothing prevents hosts on the same protected subnet from connecting
>unrestricted to the management station.
>Obviously no a good thing. Besides moving the management station to its
>own subnet is there any way of locally protecting a SPLAT machine.
>Note there is no ipchains\iptables avail.

   What you could do is make the Management Server a SecureServer, thus
 installing CheckPoint on it, to protect itself ... Just an idea

Met vriendelijke groeten - Bien � vous - Kind regards
Guy ROELANDTS
EMEA HPS Internet Expertise Centre - CCSE-NG
Hewlett-Packard Belgium B.V.B.A./S.P.R.L.
E-mail : [EMAIL PROTECTED]
Tel: +32(02)729.85.61
Fax: +32(02)729.77.65
==========================================================
This message may contain confidential and/or proprietary information,
and is intended only for the person/entity to whom it was originally
addressed. The content of this message may contain private views and
opinions which do not constitute a formal disclosure or commitment
unless specifically stated. Should you receive this message by mistake
please inform the sender immediately.
==========================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to