
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 46
ACleanFW1Installation
AcleanFW1installationgivesagoodstart.Forourproject,everyFW1systemuses
two100MBitNICs.Belowisapointformsummaryoftheinstallationprocess:
1. FromtheinstallationCD,installonlyFirewall1andtheUserInterface.
2. ChoosetheVPN1andFirewall1SINGLEGATEWAYinstallation.
3. InstallthefollowingGUIs:SecurityPolicy,LogViewer,SystemStatus
4. ConfigureasingleadministratoraccountwithRead/Writeprivileges.
5. DonotconfiguretoallowremoteGUItoconnect.TheGUImustberunfromthe
samelocalmachine.
6. AllowFW1tocontrolIPForwarding.Thiswillensurethatnotrafficcanpass
throughthesystembeforeFW1isupandrunning.Thisisespeciallyusefulina
situationwheretheserverisstartedbuttheFirewallserviceshavenotfinished
loading.
7. EnsurethattheFW1serviceistobestartedautomaticallyeverytimethesystem
startsbycheckingControlPanel –Services.
SecuringtheFW1Installation
Nothingisperfect.FW1version4.0mand4.1bothsufferfrombugsand
vulnerabilities.Belowisalistofversion4.0vulnerabilitiesextractedfrom
SecurityFocus
11
:
n 20020308: CheckPointFW1SecuClient/SecuRemoteClientDesign
Vulnerability
n 20020219: MultipleVendorHTTPCONNECTTCPTunnelVulnerability
n 20010912: CheckPointFirewall1GUILogViewerVulnerability
n 20010908: CheckPointFirewall1PolicynameTemporaryFileCreation
Vulnerability
n 20010908: CheckPointFirewall1GUIClientLogViewerSymbolicLink
Vulnerability
n 20010718: CheckPointFirewall1SecureRemoteNetworkInformationLeak
Vulnerability
11
http://online.securityfocus.com/cgibin/vulns.pl
Comentarios a estos manuales