Re: [FW-1] A question about dynamic objects

2011-12-19 Thread Independent IT Consultant
Then all you need is the domain object for smtp.gmail.com. Make that your destination and you should be fine. If you're still having problems, then run a zdebug on the gateway and test. On Wed, Dec 14, 2011 at 3:26 AM, C. L. Martinez carlopm...@gmail.comwrote: Thanks, but not: I am not trying

Re: [FW-1] A question about dynamic objects

2011-12-14 Thread C. L. Martinez
Thanks, but not: I am not trying to do URL filtering ... I am trying to allow to four servers to access only to smtp.gmail.com to send some emails a day ... Nothing more. And yes, this rules is at the end of the ruleset. On Tue, Dec 13, 2011 at 10:53 PM, Independent IT Consultant

Re: [FW-1] A question about dynamic objects

2011-12-14 Thread Warrington Bruce - bwarri
] On Behalf Of C. L. Martinez Sent: Wednesday, December 14, 2011 02:27 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] A question about dynamic objects Thanks, but not: I am not trying to do URL filtering ... I am trying to allow to four servers to access only to smtp.gmail.com

Re: [FW-1] A question about dynamic objects

2011-12-14 Thread Folnagy, Tamas
for discussion of Firewall-1 [mailto:FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM] On Behalf Of C. L. Martinez Sent: Wednesday, December 14, 2011 9:27 AM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] A question about dynamic objects Thanks, but not: I am not trying to do URL

Re: [FW-1] A question about dynamic objects

2011-12-14 Thread Folnagy, Tamas
Message- From: Mailing list for discussion of Firewall-1 [mailto:FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM] On Behalf Of Alexey Baltacov Sent: Wednesday, December 14, 2011 6:33 PM To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] A question about dynamic objects The dynamic

[FW-1] A question about dynamic objects

2011-12-13 Thread carlopmart
Hi all, I am very confused about dynamic objects pourpose. According to this sk: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=solutionid=skI1915js_peid=P-114a7ba5fd7-10001partition=Generalproduct=Security, I need to configure every dynamic

Re: [FW-1] A question about dynamic objects

2011-12-13 Thread Alexey Baltacov
You should use domain object instead. Dynamic objects used for edges dynamic policy On Dec 13, 2011 9:33 PM, carlopmart carlopm...@gmail.com wrote: Hi all, I am very confused about dynamic objects pourpose. According to this sk:

Re: [FW-1] A question about dynamic objects

2011-12-13 Thread carlopmart
On Tue, 13 Dec 2011, Alexey Baltacov wrote: You should use domain object instead. Dynamic objects used for edges dynamic policy Thanks Alexei, but can I use domain objects to resolve hostnames unde rules?? Thanks. --- CL Martinez carlopmart {at} gmail {d0t} com

Re: [FW-1] A question about dynamic objects

2011-12-13 Thread Alexey Baltacov
Hi. The domain objects are used to resolve hostnames in rules. It's also not recommended to use such objects in beginning of rulebase because it can hardly affect the perfomance. In order to use it you should configure DNS servers on OS level. Please use nearest DNS's as possible (located in

Re: [FW-1] A question about dynamic objects

2011-12-13 Thread C. L. Martinez
Uhmm ... It doesn't works, because smtp.gmail.com is resolved as a wi-in-f108.1e100.net Then, do I need to create another domain object with 1e100.net domain?? If it yes, I prefer to use IP's, although some alerts are triggered ... On Tue, Dec 13, 2011 at 9:16 PM, Alexey Baltacov

Re: [FW-1] A question about dynamic objects

2011-12-13 Thread Independent IT Consultant
What exactly are you trying to do? Domain objects work (even with cnames), but are *VERY* resource intensive. There is *NO* caching done, so *EVERY* new session will require a new lookup. For services like GMAIL, this may become problematic. This is why CP strongly advocates that any rules