<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LOM question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LOM-question/m-p/169857#M30787</link>
    <description>&lt;P&gt;Every customer I know does it on the LAN side, so if we ever need it, it has to be accessed via remote access VPN. In all honesty, in all my years dealing with CP, I had to use it probably 4 times max. Personally, but this is just me, I would not put it on publicly accessible IP address. The reason I say that is simply due to the fact you wont have a need for anyone to access the LOM portal often enough in the first place.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2023 03:55:42 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-02-01T03:55:42Z</dc:date>
    <item>
      <title>LOM question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LOM-question/m-p/169849#M30785</link>
      <description>&lt;P&gt;Wondering where most folks put the LOM port for an appliance - private network, publicly reachable but post firewall, or directly on the public network, flat to the firewall?&lt;/P&gt;&lt;P&gt;For years i've been putting mine on the private side, but i can see a ton of value placing them flat to the firewall on the public side.&amp;nbsp; For instance, at every location the ISP provides me a /29 for the handoff of which i immediately use 4 or the 6 public IPs - their gw, VIP, real-1, real-2.&amp;nbsp; So i have just enough IPs to place the LOM ports there.&amp;nbsp; But....are they hardened enough to be in a free fire zone?&amp;nbsp; Assume i'm using a complex password - any options to harden even more?&lt;/P&gt;&lt;P&gt;Appreciate your feedback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 02:29:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LOM-question/m-p/169849#M30785</guid>
      <dc:creator>D_TK</dc:creator>
      <dc:date>2023-02-01T02:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: LOM question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LOM-question/m-p/169857#M30787</link>
      <description>&lt;P&gt;Every customer I know does it on the LAN side, so if we ever need it, it has to be accessed via remote access VPN. In all honesty, in all my years dealing with CP, I had to use it probably 4 times max. Personally, but this is just me, I would not put it on publicly accessible IP address. The reason I say that is simply due to the fact you wont have a need for anyone to access the LOM portal often enough in the first place.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 03:55:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LOM-question/m-p/169857#M30787</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-01T03:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: LOM question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LOM-question/m-p/169859#M30789</link>
      <description>&lt;P&gt;In theory Yes you could put the LOM on an external public IP. You could potential lock it down via other methods of authentication and provide access to only specific IP addresses (your home IP static and/or jump PC within your organization) Though I'm not sure I still would feel comfortable doing that. I much rather have a true out of band solution for all my hardware (router, switches, FWs, etc)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the LOM guide if you didn't already have it.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://dl3.checkpoint.com/paid/73/733690c295a61c638b41ebd8ce744428/CP_Smart-1_5_6_7_13_15_16_21_23_26_28K_LOM_AdminGuide.pdf?HashKey=1675232349_a5163c3d045b27ae1ffb5b6f65047099&amp;amp;xtn=.pdf" target="_blank"&gt;https://dl3.checkpoint.com/paid/73/733690c295a61c638b41ebd8ce744428/CP_Smart-1_5_6_7_13_15_16_21_23_26_28K_LOM_AdminGuide.pdf?HashKey=1675232349_a5163c3d045b27ae1ffb5b6f65047099&amp;amp;xtn=.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 04:26:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LOM-question/m-p/169859#M30789</guid>
      <dc:creator>CE_SE</dc:creator>
      <dc:date>2023-02-01T04:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: LOM question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LOM-question/m-p/169861#M30790</link>
      <description>&lt;P&gt;Good point&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/69138"&gt;@CE_SE&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 05:03:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LOM-question/m-p/169861#M30790</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-01T05:03:38Z</dc:date>
    </item>
  </channel>
</rss>

