Hi All, I am using Checkpoint 80.40 with take 77 installed. I am attempting to enable the Mobile Access Blade. When we were running 80.30 I started the project. Once I enabled the blade we starting failing PCI compliance. The problem was that all the interfaces on our gateway were suddenly available outside on ports 80 and 443. I disabled the blade and we starting passing pci again.
We have since upgraded to 80.40 and I am trying this process again. And, once again, we are failing pci scans. This is because...
- All of the interfaces (VIPS and actual network addresses) on our gateway cluster are showing outside our network.
- If you try to go to one of the interfaces it gives you a message that there is an untrusted or self signed certificate. (which I expect since there is no site there, but it causes us to fail PCI because it is open)
- Traffic shows in the logs as being accepted on implied rules.
- If you go past the certificate message, you get the page not available message.
I need to either create rules to override the implied rules (which I have heard you have to be EXTREMELY careful doing), or, more likely, figure out what I have misconfigured that makes them available externally . There should be no traffic going to these IP addresses and the certificate will never match since they don't have any names.
On our cluster, on the Mobile Access section, I have..
- Selected Allowed Clients with "Web" and a portal URL listed (with just one IP address)
- Under the Portal Customization I have only the one IP address listed, with one alias which points to that address in DNS
- Accessibility is set to According to the firewall policy.
- In the Mobile Access Blade Section of SmartDashboard I have only a few rules allowing a few testers to get to anything behind the network.
- I found some videos on checkmates for setting up remote access and I am working through those now but have not yet seen anything about this issue.
- Gone through all the settings I can find and cannot find a place to say to get to only the one specific address.
If anyone knows what I need to disable/enable to hide my port addresses it would be very appreciated. I hate the idea of tackling the implied rules but will if that is what is required.
Any help, again, is greatly appreciated.
thanks
terri