Re: Checkpoint Front End server - ISA Back End server - OWA Setup



Volki has it correct, depending on a few things.

What version of FW-1? If it's a reasonably current version, at a minimum NG
with Application Intelligence (R54 or R55) and preferably in the NGX series
(R60 or later), it's OK. If FW-1 is an earlier version, it is a bigger risk
by itself. Anything prior to R54 goes end of life in June 2007 or is already
expired. http://www.checkpoint.com/services/lifecycle/support_periods.html

What version of ISA? If it's ISA 2004 or 2006, you're OK. If it's ISA 2000,
you need to upgrade.

I run the same configuration as your #1. ISA 2004 & 2006 are fully aware of
what proper OWA traffic looks like and, unlike FW-1, can provide SSL
termination. Without SSL termination, FW-1 is blind to the HTTPS traffic
coming in from the Internet. You are using HTTPS for OWA, aren't you?

If your figure 2 is done correctly, yes, it can work. But FW-1 is inspecting
the traffic between ISA's internal interface and the Exchange server. The
only way FW-1 can inspect it is if you pass the traffic from ISA to the
Exchange server in plain HTTP format, not HTTPS. That's a bigger risk to me.

Check Point now has SSL termination in their R65 release, but since it's
scheduled to start shipping today, I am confident you do not have it. :-)

We've found that Check Point and ISA together are a very powerful
combination. They each have their strengths and weaknesses and complement
each other nicely.

Ray
Check Point Certified Security Expert


"ICTUser" <ictuser2002@xxxxxxxxxxxxxxxxx> wrote in message
news:no6dnU592ZYmu2TYRVnytAA@xxxxxxxxxxxxxxx
We currently use checkpoint firewall as our front end firewall. We are
looking to use owa with an ISA Server used as a back end firewall. My
understanding from articles I have read is to setup the following.

Client/Internet
|
|
Checkpoint Firewall - - - - - -DMZ
| |
| |
| External
interface
Internal Lan ISA Server
\ Interal
interface
\ |
\ |
- - - - - - -- Exchange server

I am not a firewall expert, but our firewall guy tells me this is a risk,
as we dont want the Isa Server internal interface bypassing the checkpoint
firewall. He is suggesting the following.


Client/Internet
|
|
Checkpoint Firewall - - - - - -DMZ
| | |
| - - - - - | |
| | External
interface
Internal Lan | ISA Server
| | Internal
interface
Exchange server - - - - - - |

To clarify the request comes through the firewall then to the external
interface on the ISA server in the dmz and then through the internal
interface back through the checkpoint firewall and forwarded onto the
exchange server. Is this way overcomplicated and would it even work?

Thanks in advance

Ictuser








.



Relevant Pages

  • Re: [SLE] Re: Stopping open mail relay in SuSE standard server.
    ... >>There is only one interface in use, connected to the firewall, via local ... Beyond the firewall is an ADSL connection. ... I haven't yet confirmed that there is a proxy, ... No, there's no Exchange server. ...
    (SuSE)
  • Re: ANY OPINIONS ON THE S-BOX?
    ... Actually I think it's manufactured by Sofaware and runs Checkpoint FW-1. ... this is even possible with the S-box, but if it is, it would cost you extra ... subscribe to a third party ISP that would remotely manage your firewall. ...
    (comp.security.firewalls)
  • R: Questions about fw-1
    ... > 1- FW-1 works with Statefull inspection technology, ... > SecureWay Firewall does, but does anybody know some CheckPoint ... It's good for enforcing bastions, natting, implementing security rules, ...
    (Security-Basics)
  • Re: SonicWall Pro 300 vs CheckPoint 4.0
    ... As far as comparing a Pro300 to FW-1 for the setup you've described, ... right infront of the firewall (and if you say pcAnywhere, ... blah blah blah. ...
    (comp.security.firewalls)
  • Re: Firewall choice for web hosting
    ... > joined which hosts a very large volume web site. ... > flaws int he OS may expose the firewall to attack. ... Does the Nokia FW-1 ... If you're concerned about number of flaws, I think FW-1 has so far tended to ...
    (comp.security.firewalls)