[Snort-users] Checkpoint FW-1

Davis, Scott Scott_Davis at ...1915...
Wed Jun 20 15:07:54 EDT 2001

One way I know to do this would be to look into Checkpoint's opsec API's.
Check out www.opsec.com. The only other way would be on the Management
Station, modify the rulebase file (*.W) then compile it (fw gen) and load
the new config to the firewall module (fw load).  But I would be careful
about modifying the *.W files, Checkpoint can be very strange about manual
edits to this file.  

Scott Davis
Internet Security Specialist
T.Rowe Price 
(410) 345-3153 Work

-----Original Message-----
From: Lucie Hall [mailto:LucieH at ...2355...]
Sent: Wednesday, June 20, 2001 1:04 PM
To: 'snort-users at lists.sourceforge.net'
Subject: [Snort-users] Checkpoint FW-1

Has anyone been able to interface with a Checkpont Firewall-1 firewall to
have it block IPs when snort detects a clear intrusion attempt?


John Hall

Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

More information about the Snort-users mailing list