[Snort-users] Checkpoint FW-1

Davis, Scott Scott_Davis at ...1915...
Wed Jun 20 15:07:54 EDT 2001


One way I know to do this would be to look into Checkpoint's opsec API's.
Check out www.opsec.com. The only other way would be on the Management
Station, modify the rulebase file (*.W) then compile it (fw gen) and load
the new config to the firewall module (fw load).  But I would be careful
about modifying the *.W files, Checkpoint can be very strange about manual
edits to this file.  

Thanks, 
Scott Davis
Internet Security Specialist
T.Rowe Price 
(410) 345-3153 Work

-----Original Message-----
From: Lucie Hall [mailto:LucieH at ...2355...]
Sent: Wednesday, June 20, 2001 1:04 PM
To: 'snort-users at lists.sourceforge.net'
Subject: [Snort-users] Checkpoint FW-1




Has anyone been able to interface with a Checkpont Firewall-1 firewall to
have it block IPs when snort detects a clear intrusion attempt?

Thanks,

John Hall


_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users




More information about the Snort-users mailing list