(Checkpoint NG) Which ports come under Service

(Checkpoint NG) Which ports come under Service "ANY"?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
(Checkpoint NG) Which ports come under Service "ANY"? Subi 01-05-2007
Posted by Subi on January 5, 2007, 11:04 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Admins,

Strange but I have not come across a single document that explains what
are all the services that would come if we enable "ANY" under Service
for a Security Rule.

I started searching for this when users reported that they are unable
to use Terminal services (TCP Port 3389) whilst I can see service "ANY"
has been enabled for their traffic.

"ANY" - allows only Known ports (1-1024)??
Does "ANY" includes ICMP traffic too??

Curious to be enlightened. Thanks in advance.


Posted by Dogbert on January 5, 2007, 12:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Subi wrote:
> Admins,
>
> Strange but I have not come across a single document that explains what
> are all the services that would come if we enable "ANY" under Service
> for a Security Rule.
>
> I started searching for this when users reported that they are unable
> to use Terminal services (TCP Port 3389) whilst I can see service "ANY"
> has been enabled for their traffic.
>
> "ANY" - allows only Known ports (1-1024)??
> Does "ANY" includes ICMP traffic too??
>
> Curious to be enlightened. Thanks in advance.
>

Usually ANY means ANY. There are exceptions that need to be enabled specifically
(usually X11).

Try having a look at the logs. Maybe there is a specific reason for the drop.

--
--------------------------------------------------------
- Togli NO SPAM per rispondermi direttamente -
--------------------------------------------------------
- http://www.riccardofontana.it/ -
--------------------------------------------------------
- -
- Monsieur Perrier: "Lei cosa ne pensa ?" -
- MrWong: "Io perplesso." -
- Alce: "Io SONO perplesso... ci vorra' un -
- verbo qualche volta.... lei mi porta -
- alla PAZZIA !!!!!! -
- -
--------------------------------------------------------

Similar ThreadsPosted
Online Service to "Simulate/Forward" Ports November 11, 2004, 7:26 am
RPC Dynamic Ports? Windows 2003 with Checkpoint firewall. August 20, 2005, 10:12 am
Configure DCOM client to use only a small range of ports (instead of random ports) August 16, 2006, 4:43 am
Checkpoint - Deny traceroute through checkpoint firewall August 10, 2004, 3:27 pm
Truevector Service April 20, 2005, 10:14 pm
NEW Proxy SERVICE October 1, 2007, 6:06 am
Setting up FTP Service August 19, 2008, 6:49 pm
Service Pack 2 for Windows XP February 6, 2005, 12:33 pm
What is a Denial of Service Attack? May 22, 2005, 12:11 pm
What is a Denial of Service Attack? May 22, 2005, 12:12 pm

The site map in XML format XML site map

Contact Us | Privacy Policy