Fredy,

You may want to invest in the book Hacking Exposed by Stuart McClure, Joel
Scambray, and George Kurtz.  I have the 2nd edition, but looks like they
have a third edition out.  It's got some insightful info on securing
Checkpoint and Cisco routers and firewalls.  It has some practical
techniques to implement and good examples to follow also.  I found this
resource helpful when in a mixed vendor environment.  Not super in depth on
one particular product, but enough info to be effective.

You may also want to poke around on Dameon D. Welch's website,
www.phoneboy.com.  I have found a few new things there that people have
brought up about Checkpoint.

As far as running Checkpoint on the Nokia's.  You'll need to know some Unix
as Nokia's use a proprietary version called IPSO.  If you know little to no
Unix at all, you could fumble through with the initial setup, then simply
use the Policy Editor from then on.  But plan on doing this as a lesson to
yourself for a few days to get familiar with IPSO.  Although IPSO can be
run from Voyager in a browser, so that helps things a little.  I think I
confused myself in this response!

Good luck,
Kevin



Date: Wed, 26 Dec 2001 10:11:42 -0400
Subject: Security Checklist for Firewall-1
To: [EMAIL PROTECTED]
From: "Fredy Santana" <[EMAIL PROTECTED]>

I Everybody:

I'm making some research to make a kind of "Security checklist" for
Firewall-1 over Nokia. Does anyone have some recommendations to secure a
Firewall-1? or information abou it?. I mean, by example, to disable the
ports 256 and 258 to Internet if your firewall is not being managed from
Internet.

I hope your help


Thanks in advance

Regards from Chile
Fredy R. Santana V.
Ingeniero Civil El�ctrico - CCSA - CCDA
Orion 2000 - Servicios Profesionales en Seguridad Inform�tica
La Concepcion 322 piso 12, Providencia.
Santiago, Chile
Fono: 56-2-6403944, Fax: 56-2-6403990
e-mail: [EMAIL PROTECTED]
http://www.orion.cl





_______________________________________________
Firewalls mailing list
[EMAIL PROTECTED]
http://lists.gnac.net/mailman/listinfo/firewalls

Reply via email to