Checkpoint - Deny traceroute through checkpoint firewall

Checkpoint - Deny traceroute through checkpoint firewall

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Checkpoint - Deny traceroute through checkpoint firewall Bjoern 08-10-2004
Posted by Bjoern on August 10, 2004, 3:27 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I have a checkpoint ng r55. I allow a icmp (all types) connection:

Source                Destination        Service
10.1.1.1        20.2.2.2        icmp                permit

The host 10.1.1.1 can ping 20.2.2.2. Okay.
When host 10.1.1.1 traces the route to 20.2.2.2, it get a pesponse from
the firewall internal and external interface!

Host 10.1.1.1\> traceroute 20.2.2.2

10.1.1.1 ok
firewall_ip ok
20.2.2.2 ok

I do not want that the hosts sees the firewall ip adresses. Can I
configure the firewall to drop/reject the icmp (type 8 time exceeded)
packet to the host??

I have tried to make an own rule:

Source                Destination        Service
firewall_ip        10.1.1.1        icmp (type 8)        deny

alternative
any                10.1.1.1        icmp (all types)        deny

The "fw monitor" shows me, that icmp packets type 8 flow from
firewall_ip to host 10.1.1.1, although I have denied it...

Thanks in advance.


Posted by Observer on August 10, 2004, 3:54 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
There is something called "stealth rule" , a rule where you put your fw as
invisible meaning, it drops all traffic directed to it. (except ev. IPsec,
control connections and so on but these are anyway implied rules at
checkpoint, so no need to define them explicitely)

> Hello,
>
> I have a checkpoint ng r55. I allow a icmp (all types) connection:
>
> Source Destination Service
> 10.1.1.1 20.2.2.2 icmp permit
>
> The host 10.1.1.1 can ping 20.2.2.2. Okay.
> When host 10.1.1.1 traces the route to 20.2.2.2, it get a pesponse from
> the firewall internal and external interface!
>
> Host 10.1.1.1\> traceroute 20.2.2.2
>
> 10.1.1.1 ok
> firewall_ip ok
> 20.2.2.2 ok
>
> I do not want that the hosts sees the firewall ip adresses. Can I
> configure the firewall to drop/reject the icmp (type 8 time exceeded)
> packet to the host??
>
> I have tried to make an own rule:
>
> Source Destination Service
> firewall_ip 10.1.1.1 icmp (type 8) deny
>
> alternative
> any 10.1.1.1 icmp (all types) deny
>
> The "fw monitor" shows me, that icmp packets type 8 flow from
> firewall_ip to host 10.1.1.1, although I have denied it...
>
> Thanks in advance.




Posted by Rob Hughes on August 12, 2004, 3:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Bjoern is alleged to have said in comp.security.firewalls:

>
> The "fw monitor" shows me, that icmp packets type 8 flow from
> firewall_ip to host 10.1.1.1, although I have denied it...
>
> Thanks in advance.

Policy, global properties, uncheck accept ICMP to deny all, or set it to
before last if you want to be able to deny specific types of ICMP.

--
Recursion: n. See Recursion.


Similar ThreadsPosted
checkpoint firewall default deny? February 15, 2005, 9:00 pm
Need Help on Checkpoint Firewall NAT January 27, 2005, 8:31 pm
What to choose for CheckPoint Firewall-1? May 13, 2005, 10:59 am
CheckPoint firewall behind DSL router June 28, 2005, 7:55 pm
Issue with Checkpoint Firewall December 29, 2005, 3:01 am
Skype with Checkpoint Firewall NG FP 3 April 6, 2006, 6:57 am
WILL PAY. Need help to setup VPN between a PIX 506 and a Checkpoint 4.1 Firewall April 19, 2006, 9:45 pm
CheckPoint Firewall Monitoring Metrics April 8, 2005, 7:06 am
Checkpoint Firewall 1 Event Types August 3, 2005, 9:54 am
Restarting management on a checkpoint firewall? November 17, 2005, 9:16 pm

The site map in XML format XML site map

Contact Us | Privacy Policy