Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
FXB
Contributor

How to allow access to a web traffic ressource?

Dear community,

we are currently facing the challenge, that one of our employees is having a software installed which need to connect via MySQL (TCP 3306) to an external internet ressource.

Unfortunately that internet ressource has an ever-changing external IP so allowing the traffic with a static src/dest/port rule is not an option. 

Looking at the log we see that our checkpoint gateway recognized the web traffic ressouce (test.domain.com in this example) to which the software is trying to connect via MySQL (see attachment).

Is there a way to allow the access based on this web ressource? 

The gateway is running R80.20.40, domain objects did not work (probably since its not a http(s) traffic but SQL).

Any hint is appreciated!

Regards,

Franz

0 Kudos
5 Replies
G_W_Albrecht
Legend Legend
Legend

This is Embedded GAiA - why not allow all connections from employees local IP / Access Role using TCP 3306 to Internet ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
FXB
Contributor

Hi,

thanks for your response. 

Allowing all tcp_3306 traffic from the client to the internet would be the fall-back solution. We would like to have an as-tight-as- possible ruleset in regards to internet connections, so if there would be a way to use the web ressouce for the allow-rule that would be the prefered way.

Our mindset was that if checkpoint is detecting this ressouce, surely there could be some way to use this information for the ruleset?

You are correct in assuming its embedded-gaia, if this is the wrong section of the forum, please move the topic to the correct one if possible 🙂

0 Kudos
PhoneBoy
Admin
Admin

I’ve moved it. 

You mentioned you’re using an SMB device but the log card suggests it’s being managed by a Smart-1..correct?
The correct way to do this is with a Domain Object with the FQDN checkbox tagged in the relevant access policy rule, which will use DNS to determine what the IP will be.
Even if the device is locally managed, you can create a similar domain object for the policy.

the_rock
Legend
Legend

I agree with advice @PhoneBoy gave you. Domain object is way to go here.

0 Kudos
FXB
Contributor

Thanks for your replies.

Yes, the device is beeing managed by a central security management server (even tho its not a smart-1 but openserver based, makes no difference here). We actually tried making it work with domain objects like "domain.com" with FQDN set, had no success with it however. Since the external IP address in the destination field of the log is beeing resolved to sth different than what is displayed in the web traffic ressouce field , I assume we need to create a domain object which relates to the destination IP, rather than the ressouce shown.

We gonna try it out and give feedback here.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events