Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Support for IP redirection by CheckPoint Firewall-1 NG |
|---|---|
| Date: | Mon, 25 Apr 2005 10:28:36 -0700 (PDT) |
Certainly, and depending on the OS,it will also attempt to send a ICMP Redirct and be denied by the firewall application without referencing a rule number. You can modify the firewall's kernel behavior to allow ICMP Redirects. This change is different based the firewall's OS, this info can be found on Checkpoint's website via secureknowledge. --- Jarek Sluzewski <jsluzewski@exenet.com> wrote:
Could someone confirm, if CheckPoint NG 4.x can send
packet back out of the same interface which received
it.
In other words, if the firewall receives a packet,
and based on its routing table determines that this
packet should be sent via same interface that
received it, will the NG forward the packet or just
drop it (as PIX would).
Thanks,
Jarek
__________________________________
Do you Yahoo!?
Yahoo! Small Business - Try our new resources site!
http://smallbusiness.yahoo.com/resources/
--------------------------------------------------------------------------
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
--------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Nokia IP440, still useful?, Paris E. Stone |
|---|---|
| Next by Date: | Checkpoint FW Logs, Andy Ha |
| Previous by Thread: | Support for IP redirection by CheckPoint Firewall-1 NG, Jarek Sluzewski |
| Next by Thread: | Re: Most secure small home office firewall under $700, George Kroonder |
| Indexes: | [Date] [Thread] [Top] [All Lists] |