Re: [FW-1] CP UTM-1 R70.5 policy question

2013-01-30 Thread Clive Luk
29, 2013 16:29 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] CP UTM-1 R70.5 policy question thanks! what if I only want public internal to access internet on http and https but not the web servers on dmz or staff internal. I can't really define a group for internet right

Re: [FW-1] CP UTM-1 R70.5 policy question

2013-01-29 Thread Independent IT Consultant
Indirectly, you can accomplish this. Create a group with the relevant wireless nets, then define a single rule as follows: Source: {wireless nets} Destination: NOT {Internal nets} Service: HTTP, HTTPS Action: Allow Bear in mind that you're talking about fundamental differences in architecture

Re: [FW-1] CP UTM-1 R70.5 policy question

2013-01-29 Thread Clive Luk
thanks! what if I only want public internal to access internet on http and https but not the web servers on dmz or staff internal. I can't really define a group for internet right? So does that mean I need to have a bunch of drop rules setting at the very beginning? Thanks! On 30/01/13

Re: [FW-1] CP UTM-1 R70.5 policy question

2013-01-29 Thread Warrington Bruce - bwarri
29, 2013 16:29 To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM Subject: Re: [FW-1] CP UTM-1 R70.5 policy question thanks! what if I only want public internal to access internet on http and https but not the web servers on dmz or staff internal. I can't really define a group for internet right