Clientless VPN -  so router to router mode to setup VPN tunnels
between FW1 and your device?

I started to persue OPSEC so I could do some advanced programming
that the basic rule base doesn't allow for - such as having each
outgoing connection from our LAN verify through a 3rd server that
contains a database of IP addresses, the users using those IP addresses,
and if they are authorized to make outgoing connections.

I know FW1 has those basic products available., but we have a more
complex method of determining who can make outgoing connections.

As an example., if you have laptops connecting out through the
FW1 interface to the internet on your campus., you might want to
verify that the person making the outgoing connection is authorized
based on an SQL database sitting on a mainframe or midrange server.
So you might redirect ANY webtraffic they generate to your intranet
server to have them enter their SSN# and PIN.

That way we can tie back traffic from a specific IP to a person.

Alas, I couldn't find an easy way to get this done via OPSEC.
With time being a luxury I don't have, it remains an idea.

Good luck.


http://www.primeinc.com
**********************************************************************
This email and any files transmitted with it are confidential
and intended solely for the use of the individual or entity to
whom they are addressed.  If you have received this email
in error please reply to the sender of the message.

The views expressed in this correspondence may not
reflect the views of Prime, Inc.

This footnote also confirms that this email message has
been scanned for the presence of computer viruses.
**********************************************************************

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to