Hi Gary,

You need to create a new Service group and put a bunch of services in it (or
specify them individually, which makes for a fat rule). I named mine
ScOutlook. When you specify the DCERPC services separately, Check Point
tracks them better than if you used "any."

Office Mode is highly recommended as well as passing the DNS and WINS
servers via Office Mode for good name resolution. This is what we do.

These are the services you need to specify individually:

MSExchangeSysAttPriv
MSExchangeSysAtt
MSExchangeStoreAdm
MSExchangeMTA
MSExchangeIS
MSExchangeDSXDS
MSExchangeDSRep
MSExchangeDSNSPI
MSExchangeADL
MSExchangeDirRef
MSExchangeDirRep
NBT
domain-udp

I do NOT have this in the desktop policy. This rule is in the main rulebase
using IF VIA Remote Access. Once I added this rule in the main rulebase,
Outlook via SecureClient started up about thirty seconds faster and the
"click retry" box never showed up again. I don't see any reason why you
couldn't put it in the desktop policy, though.

HTH,

Ray Pesek, CISSP





From: "Brett, Gary" <[EMAIL PROTECTED]>
Reply-To: Mailing list for discussion of Firewall-1
<[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: [FW-1] SecureClient - Outlook and Exhange
Date: Wed, 10 Mar 2004 11:56:17 -0000

Hi there

I am attempting to get outlook 2000 clients connecting to a exchange 5.5
server over SecureClient (NG FP3). If i create an outbound `Desktop Policy`
rule that says  - -

[EMAIL PROTECTED] ---> Exchange_box_internal_address - Service=Any

...then every thing works no problem at all. But I have been asked to get
rid of rules with "Any" in the service column and lock it down to the
required tcp/udp ports/services only.

Has anybody configured this to work already? if so which ports do i need to
keep open to get this working, so far i have

tcp 135
tcp 1053
tcp 1068

Can anyone think of any more that outlook potentially might want to use ?

PS: Why, when TCP-135 appears in the log, it resolves to the name "epmap"
but when i look in services listing in NG  there is no "epmap" or in fact
no
service at all for TCP-135 ???, im very confused by this, I want to add the
service to a rule but it doesnt exist , but it does ..! if you see what i
mean. Would i have to create the service and call it something else ??

any help would be greatly appreciated

Cheers
Gary
This electronic message contains information from Halifax Cetelem Credit
Ltd
which may be privileged or confidential. The information is intended to be
for the use of the individual(s) or entity named above. If you are not the
intended recipient be aware that any disclosure, copying, distribution or
use of the contents of this information is prohibited. If you have received
this electronic message in error, please notify us by telephone or email
(to
the numbers or address above) immediately.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

_________________________________________________________________ Get business advice and resources to improve your work life, from bCentral. http://special.msn.com/bcentral/loudclear.armx

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to