These are the DCE-RPC services, which are flakey by anyone's definition.
Specifying the services explicitly as opposed to "service any" is supposed
to make Check Point track them better.
That being said, I had to put in a "service-any" rule right above the rule
that defined them explicitly because R55 HFA02 was showing DCE-RPC drops on
pseudo rule 998 and messing up Outlook.
Ray
From: Daniel Samaan <dsamaan AT FORSYTHE DOT COM>
Reply-To: Mailing list for discussion of Firewall-1
<FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Subject: [FW-1] Exchange and Outlook ports
Date: Tue, 30 Mar 2004 10:56:41 -0600
Can someone help explain what the MSExchange Group of service ports vs.
adding tcp-high ports doesn't do?
I noticed by adding MSexchange group also, inherently allows TCP-135
(epmap-135).
I'm running AI
thanks
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
_________________________________________________________________
Find a broadband plan that fits. Great local deals on high-speed Internet
access.
https://broadband.msn.com/?pgmarket=en-us/go/onm00200360ave/direct/01/
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
|