Greetings!

Eric Appelboom wrote:
> Does anyone know of any tool\script that I can use to convert a fw-1
> inspect script
> to a access list to be temporarily applied on a Cisco router. (IOS firewall)

No, but you can use the a newer version of the FW1Rules script to dump
rules, network entities etc. into CSV and text files for easier
conversion (http://www.wyae.de/software/fwtools.html). A tool that might
go into that direction still is under development (~ mid of this year at
the same address).

Main problem is that Cisco does not do stateful connections for UDP -
please someone do correct me if I am wrong here. So one has to be
careful not to accidentally open up back-ports where not intended.

Bye
        Volker

--

-------------------------------------------------------------------
[EMAIL PROTECTED]                                 discon GmbH
IT-Security Consulting                           Wrangelstrasse 100
http://www.discon.de/                         10997 Berlin, Germany
-------------------------------------------------------------------
PGP-Fingerprint: 5323 a4f7 a7c2 b8ef 4653 05ce d2ea 2b74  b94c c68e

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to