Firewall-1

Re: [FW-1] FTP (put or get)

Subject: Re: [FW-1] FTP (put or get)
From: Matthias Leu <mleu AT AERASEC DOT DE>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Thu, 20 Apr 2006 18:38:39 +0200
Sam Ghannadi wrote:
> hi guys,
> Can I create a rule on R55 checkpoint firewall with
> some restriction on FTPing to some server either PUT
> or GET?
> I looked on FTP services, none of them has that
> option. I just like to give users permission to GET
> not to PUT on a SUNserver (FTP).
> Thanks,
> Sam

Hi Sam,
for accepting 'get only' you will need a FTP Resource which uses the
security server. In the menu of SmartDashboard, go to Manage - Resources
- New - FTP. Here you find the option. Take this resource into a
separate rule and install the rulebase - and test it.
By the way: Get are FTP commands to read, Put is the expression for all
writing commands. So Put means also e.g. mkdir or delete
Hope it helps,
best regards,
Matthias
http://www.fw-1.de
-- 
AERAsec Network Services and Security GmbH
Wagenberger Strasse 1
D-85662 Hohenbrunn, Germany
http://www.aerasec.de

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>