Check Point community forum
May 20, 2012, 09:34:40 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News:
 
  Home   Forum   Help Search Login Register   **
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 20, 2012, 09:34:40 PM

Login with username, password and session length
Pages: [1]
  Print  
Author Topic: Match for Any  (Read 1080 times)
Sauce
Newbie
*
Posts: 1


« on: September 10, 2010, 10:52:58 AM »

Bonjour,

I am troubleshooting a cluster of firewalls FW-1.
I have 175 Service port conflict warnings, and i need to figure it out. I have several questions :

Is it better to uncheck "Match for Any" from port ranges rather than single ports.
for example a conflict between <TCP 111 - 115> and <TCP 112>, I'd better uncheck "Match for Any" from <TCP 111 - 115>. And if so how are the other ports in the range treated 111, 113, 114, 115 when I have an Any rule. (are they treated like normal TCP/UDP connexions, do they pass in the first place Smiley )

I know that we better keep the predefined services as "Match for Any", like FTP, SSH, .....
Because there's some parameters related to the INSPECT engine for these protocols, but what happens if I have another service that uses the same port as a predefined service (FTP for example) in a rule where we have Any service, are they treated like FTP and dropped because they don't confirm to FTP parameters.

And a final question Smiley

How do i change the warning sentivity level, for example to avoid have warning like these and have only warning for more seriuos problems.
Logged
juve
Administrator
Jr. Member
*****
Posts: 92


« Reply #1 on: September 10, 2010, 09:13:39 PM »

Hi,


Quote
I am troubleshooting a cluster of firewalls FW-1.
I have 175 Service port conflict warnings, and i need to figure it out. I have several questions :

Is it better to uncheck "Match for Any" from port ranges rather than single ports.
for example a conflict between <TCP 111 - 115> and <TCP 112>, I'd better uncheck "Match for Any" from <TCP 111 - 115>. And if so how are the other ports in the range treated 111, 113, 114, 115 when I have an Any rule. (are they treated like normal TCP/UDP connexions, do they pass in the first place  )

The match for any should best be set for the more specific services. If you uncheck match for any on your tcp 111-115, it will not be hit on an any rule, only the services in the port range that are defined with match for any. all others will be treated as don't match for any because of the service definition.

Quote
I know that we better keep the predefined services as "Match for Any", like FTP, SSH, .....
Because there's some parameters related to the INSPECT engine for these protocols, but what happens if I have another service that uses the same port as a predefined service (FTP for example) in a rule where we have Any service, are they treated like FTP and dropped because they don't confirm to FTP parameters.
They will be dropped. If you have a second service on port 21, create a new service on port 21 without match for any and put it before the any rule, so the correct service is chosen. On the any rule, the ftp/... inspection will still be performed.

Quote
And a final question

How do i change the warning sentivity level, for example to avoid have warning like these and have only warning for more seriuos problems.

As far as I know, this isn't possible
Logged
Pages: [1]
  Print  
 
Jump to:  

Recent
[May 14, 2012, 10:59:10 AM]

[May 14, 2012, 10:58:46 AM]

[May 14, 2012, 10:58:11 AM]

[May 14, 2012, 10:57:18 AM]

[May 14, 2012, 10:56:41 AM]

[May 14, 2012, 10:56:25 AM]

[May 14, 2012, 10:55:41 AM]

[May 14, 2012, 10:55:12 AM]

[May 14, 2012, 10:54:42 AM]

[May 14, 2012, 10:54:10 AM]
Members
Total Members: 246
Latest: balfaszok
Stats
Total Posts: 281
Total Topics: 174
Online Today: 5
Online Ever: 24
(May 19, 2012, 04:16:58 PM)
Users Online
Users: 0
Guests: 8
Total: 8
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
TinyPortal v0.9.8 © Bloc
Valid XHTML 1.0! Valid CSS!