Snort mailing list archives

RE: Checkpoint FW-1


From: "Davis, Scott" <Scott_Davis () troweprice com>
Date: Wed, 20 Jun 2001 15:07:54 -0400


One way I know to do this would be to look into Checkpoint's opsec API's.
Check out www.opsec.com. The only other way would be on the Management
Station, modify the rulebase file (*.W) then compile it (fw gen) and load
the new config to the firewall module (fw load).  But I would be careful
about modifying the *.W files, Checkpoint can be very strange about manual
edits to this file.  

Thanks, 
Scott Davis
Internet Security Specialist
T.Rowe Price 
(410) 345-3153 Work

-----Original Message-----
From: Lucie Hall [mailto:LucieH () snetworking com]
Sent: Wednesday, June 20, 2001 1:04 PM
To: 'snort-users () lists sourceforge net'
Subject: [Snort-users] Checkpoint FW-1




Has anyone been able to interface with a Checkpont Firewall-1 firewall to
have it block IPs when snort detects a clear intrusion attempt?

Thanks,

John Hall


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: