You need to create a new Service group and put a bunch of services in it (or specify them individually, which makes for a fat rule). I named mine ScOutlook. When you specify the DCERPC services separately, Check Point tracks them better than if you used "any."
Office Mode is highly recommended as well as passing the DNS and WINS servers via Office Mode for good name resolution. This is what we do.
These are the services you need to specify individually:
MSExchangeSysAttPriv MSExchangeSysAtt MSExchangeStoreAdm MSExchangeMTA MSExchangeIS MSExchangeDSXDS MSExchangeDSRep MSExchangeDSNSPI MSExchangeADL MSExchangeDirRef MSExchangeDirRep NBT domain-udp
I do NOT have this in the desktop policy. This rule is in the main rulebase using IF VIA Remote Access. Once I added this rule in the main rulebase, Outlook via SecureClient started up about thirty seconds faster and the "click retry" box never showed up again. I don't see any reason why you couldn't put it in the desktop policy, though.
HTH,
Ray Pesek, CISSP
From: "Brett, Gary" <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1 <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: [FW-1] SecureClient - Outlook and Exhange Date: Wed, 10 Mar 2004 11:56:17 -0000
Hi there
I am attempting to get outlook 2000 clients connecting to a exchange 5.5 server over SecureClient (NG FP3). If i create an outbound `Desktop Policy` rule that says - -
[EMAIL PROTECTED] ---> Exchange_box_internal_address - Service=Any
...then every thing works no problem at all. But I have been asked to get rid of rules with "Any" in the service column and lock it down to the required tcp/udp ports/services only.
Has anybody configured this to work already? if so which ports do i need to keep open to get this working, so far i have
tcp 135 tcp 1053 tcp 1068
Can anyone think of any more that outlook potentially might want to use ?
PS: Why, when TCP-135 appears in the log, it resolves to the name "epmap" but when i look in services listing in NG there is no "epmap" or in fact no service at all for TCP-135 ???, im very confused by this, I want to add the service to a rule but it doesnt exist , but it does ..! if you see what i mean. Would i have to create the service and call it something else ??
any help would be greatly appreciated
Cheers Gary This electronic message contains information from Halifax Cetelem Credit Ltd which may be privileged or confidential. The information is intended to be for the use of the individual(s) or entity named above. If you are not the intended recipient be aware that any disclosure, copying, distribution or use of the contents of this information is prohibited. If you have received this electronic message in error, please notify us by telephone or email (to the numbers or address above) immediately.
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
_________________________________________________________________ Get business advice and resources to improve your work life, from bCentral. http://special.msn.com/bcentral/loudclear.armx
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
