<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Firewall Wizards (firewall-wizards) Mailing List</title>
<link>http://seclists.org/#firewall-wizards</link>
<atom:link href="http://seclists.org/rss/firewall-wizards.rss" rel="self" type="application/rss+xml" />
<description>Tips and tricks for firewall administrators</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Re:  Coding a custom firewall manager for multiple firewall brands. Feasible?</title><description>Posted by Marcin Antkiewicz on Jul 2&lt;p&gt;


&lt;p&gt;
&amp;gt; I just want to know whether the task (interfacing part) is do-able or not.
&lt;br /&gt;
&amp;gt; The brands of firewalls that I&#39;m handling are checkpoint and sidewinder 7. I
&lt;br /&gt;
&amp;gt; don&#39;t mind coding out all the stuff but i really have limited product
&lt;br /&gt;
&amp;gt; knowledge. Really appreciate any advise or help out...</description>
<link>http://seclists.org/firewall-wizards/2009/Jul/0003.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jul/0003.html</guid>
<pubDate>Thu, 2 Jul 2009 17:17:27 -0500</pubDate></item>
<item><title>Re:  Coding a custom firewall manager for multiple firewall brands. Feasible?</title><description>Posted by plopz on Jul 1&lt;p&gt;


&lt;p&gt;
Thank you guys for all your responses.
&lt;br /&gt;
&lt;p&gt;I kinda feel the same as david about commercial firewall management tools.
&lt;br /&gt;
There also a lot of trouble and fuss to bring and use external software into
&lt;br /&gt;
our corporate network. That&#39;s the main reason why the fw people are still
&lt;br /&gt;
using manual data entry into...</description>
<link>http://seclists.org/firewall-wizards/2009/Jul/0002.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jul/0002.html</guid>
<pubDate>Wed, 1 Jul 2009 08:23:07 -0700 (PDT)</pubDate></item>
<item><title>Re:  Coding a custom firewall manager for multiple firewall brands. Feasible?</title><description>Posted by Marcin Antkiewicz on Jul 1&lt;p&gt;


&lt;p&gt;
&amp;gt; I&#39;d just recently got an extra job role as a firewall administrator and I&#39;m
&lt;br /&gt;
&amp;gt; faced with a network that consists of multitudes of firewall brands (nokia,
&lt;br /&gt;
&amp;gt; sidewinder etc. ) bulging with almost 3000+ rules. The networks are also
&lt;br /&gt;
&amp;gt; segmented and structured in such a way that...</description>
<link>http://seclists.org/firewall-wizards/2009/Jul/0001.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jul/0001.html</guid>
<pubDate>Wed, 1 Jul 2009 00:54:58 -0500</pubDate></item>
<item><title>Re:  Coding a custom firewall manager for multiple firewall brands. Feasible?</title><description>Posted by K K on Jun 30&lt;p&gt;


&lt;p&gt;
Check out Matasano&#39;s &amp;quot;Playbook&amp;quot;:
&lt;br /&gt;
http://runplaybook.com/
&lt;br /&gt;
&lt;p&gt;I tried it about a year ago, was impressed.
&lt;br /&gt;
&lt;p&gt;Kevin
&lt;br /&gt;
&lt;p&gt;On 6/30/09, plopz &amp;lt;minggyang_at_gmail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; Hi everyone,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; I&#39;d just recently got an extra job role as a firewall administrator and I&#39;m
&lt;br /&gt;
...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0034.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0034.html</guid>
<pubDate>Tue, 30 Jun 2009 21:40:14 -0500</pubDate></item>
<item><title>Coding a custom firewall manager for multiple firewall brands. Feasible?</title><description>Posted by plopz on Jun 30&lt;p&gt;


&lt;p&gt;
Hi everyone,
&lt;br /&gt;
&lt;p&gt;I&#39;d just recently got an extra job role as a firewall administrator and I&#39;m
&lt;br /&gt;
faced with a network that consists of multitudes of firewall brands (nokia,
&lt;br /&gt;
sidewinder etc. ) bulging with almost 3000+ rules. The networks are also
&lt;br /&gt;
segmented and structured in such a way that adding a...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0033.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0033.html</guid>
<pubDate>Tue, 30 Jun 2009 09:52:56 -0700 (PDT)</pubDate></item>
<item><title>Re:  firewall-wizards Digest, Vol 38, Issue 11</title><description>Posted by pkc_mls on Jun 26&lt;p&gt;


&lt;p&gt;
Paul Hutchings a écrit :
&lt;br /&gt;
&amp;gt; I have split tunnelling disabled, but being frank my low level 
&lt;br /&gt;
&amp;gt; knowledge of TCP/IP isn&#39;t sufficient to know if it&#39;s sufficient 
&lt;br /&gt;
&amp;gt; mitigation for lack of a software firewall.
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; Frustratingly, the Juniper Host Checker comes with a firewall but you...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0032.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0032.html</guid>
<pubDate>Fri, 26 Jun 2009 08:38:24 +0200</pubDate></item>
<item><title>Re:  Pix 520 tunnels</title><description>Posted by Paul Melson on Jun 24&lt;p&gt;


&lt;p&gt;
On Tue, Jun 23, 2009 at 12:08 PM, Halchishak, John&amp;lt;jhalchishak_at_ciber&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; We have two pix (actually three, one failover) 520s that Im trying to setup
&lt;br /&gt;
&amp;gt; multiple tunnels. The two office locations have a tunnel up between them
&lt;br /&gt;
&amp;gt; with 2 peer address on the main end...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0031.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0031.html</guid>
<pubDate>Wed, 24 Jun 2009 07:47:36 -0400</pubDate></item>
<item><title>Re:  Pix 520 tunnels</title><description>Posted by Farrukh Haroon on Jun 24&lt;p&gt;


&lt;p&gt;
Hello John
&lt;br /&gt;
&lt;p&gt;You need to make sure that the dynamic crypto map entry is higher than the
&lt;br /&gt;
static crypto map(s).
&lt;br /&gt;
&lt;p&gt;Please have a look at the below link:
&lt;br /&gt;
&lt;p&gt;http://supportwiki.cisco.com/ViewWiki/index.php/How_to_configure_Site-to-Site_VPN_client_connection_on_the_same_PIX
&lt;br /&gt;
&lt;p&gt;Regards
&lt;br /&gt;
&lt;p&gt;Farrukh
&lt;br /&gt;
On Tue, Jun...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0030.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0030.html</guid>
<pubDate>Wed, 24 Jun 2009 09:24:34 +0300</pubDate></item>
<item><title>Re:  firewall-wizards Digest, Vol 38, Issue 11</title><description>Posted by Paul Hutchings on Jun 23&lt;p&gt;


&lt;p&gt;
I have split tunnelling disabled, but being frank my low level  
&lt;br /&gt;
knowledge of TCP/IP isn&#39;t sufficient to know if it&#39;s sufficient  
&lt;br /&gt;
mitigation for lack of a software firewall.
&lt;br /&gt;
&lt;p&gt;Frustratingly, the Juniper Host Checker comes with a firewall but you  
&lt;br /&gt;
need admin rights simply to enable/disable...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0029.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0029.html</guid>
<pubDate>Tue, 23 Jun 2009 17:54:16 +0100</pubDate></item>
<item><title>Pix 520 tunnels</title><description>Posted by Halchishak John on Jun 23&lt;p&gt;


&lt;p&gt;
We have two pix (actually three, one failover) 520s that I&#39;m trying to
&lt;br /&gt;
setup multiple tunnels. The two office locations have a tunnel up
&lt;br /&gt;
between them with 2 peer address on the main end and a single on the
&lt;br /&gt;
other. We have need to establish other tunnels at various times to
&lt;br /&gt;
clients. I can&#39;t...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0028.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0028.html</guid>
<pubDate>Tue, 23 Jun 2009 09:08:48 -0700</pubDate></item>
<item><title>Re:  VPN and XP Firewall GPO settings</title><description>Posted by Chris Hughes on Jun 23&lt;p&gt;


&lt;p&gt;
I&#39;m with Victor disable split tunneling.  I used to have connectivity issues
&lt;br /&gt;
using Juniper network connect vpn with no split-tunneling.  Very poor
&lt;br /&gt;
implementation.  Certain drivers used by the clients was causing repeated
&lt;br /&gt;
connection resets and disaster seemed imminent during rollout.  Juniper...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0027.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0027.html</guid>
<pubDate>Tue, 23 Jun 2009 06:54:13 -0400</pubDate></item>
<item><title>Re:  Cisco AnyConnect Remote Access to L2L tunnels</title><description>Posted by Todd Simons on Jun 22&lt;p&gt;


&lt;p&gt;
Adding the dynamic NAT on the outside interface fixed it!  Thanks!
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;
&lt;br /&gt;
&lt;p&gt;From: firewall-wizards-bounces_at_listserv&amp;#46;icsalabs.com
&lt;br /&gt;
[mailto:firewall-wizards-bounces_at_listserv&amp;#46;icsalabs.com] On Behalf Of
&lt;br /&gt;
Eric Gearhart
&lt;br /&gt;
Sent: Friday, June 19, 2009 7:13 PM
&lt;br /&gt;
To: Firewall Wizards Security...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0026.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0026.html</guid>
<pubDate>Mon, 22 Jun 2009 20:52:44 -0400</pubDate></item>
<item><title>Re:  VPN and XP Firewall GPO settings</title><description>Posted by Victor Williams on Jun 22&lt;p&gt;


&lt;p&gt;
Isn&#39;t the catch-all to just leave it on all the time?  What is the value of not having it on if the laptop is connected to your immediate network?
&lt;br /&gt;
&lt;p&gt;I leave ours on all the time.  We don&#39;t allow workstations/laptops to share files or printers...all that is handled on our servers.  So, it works...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0025.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0025.html</guid>
<pubDate>Mon, 22 Jun 2009 13:16:50 -0500</pubDate></item>
<item><title>Re:  firewall-wizards Digest, Vol 38, Issue 11</title><description>Posted by rjdriscoll_at_comcast.net on Jun 22&lt;p&gt;


&lt;p&gt;
Are you allowing split tunneling? I have worked at companies that have disabled split tunneling, which in effect turned off routing except 
&lt;br /&gt;
through the VPN server. We then would check for things like current AV def&#39;s and patch compliance. 
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;----- Original Message ----- 
&lt;br /&gt;
From:...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0024.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0024.html</guid>
<pubDate>Mon, 22 Jun 2009 19:42:19 +0000 (UTC)</pubDate></item>
<item><title>Re:  VPN and XP Firewall GPO settings</title><description>Posted by Paul Hutchings on Jun 22&lt;p&gt;


&lt;p&gt;
Sorry, I may have explained badly so just to clarify:
&lt;br /&gt;
&lt;p&gt;Our default GPO is set to enable the XP Firewall when the laptops are  
&lt;br /&gt;
on &amp;quot;Standard Profile&amp;quot; and disable it when using &amp;quot;Domain  
&lt;br /&gt;
Profile&amp;quot; (going from &amp;quot;netsh firewall show currentprofile&amp;quot;).
&lt;br /&gt;
&lt;p&gt;What seems to...</description>
<link>http://seclists.org/firewall-wizards/2009/Jun/0023.html</link><guid isPermaLink="true">http://seclists.org/firewall-wizards/2009/Jun/0023.html</guid>
<pubDate>Mon, 22 Jun 2009 17:19:18 +0100</pubDate></item>
</channel></rss>