Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

TREND Interscan CVP & Nokia/Checkpoint NG FW 1

Status
Not open for further replies.

ansellrk

Technical User
Joined
Oct 24, 2002
Messages
135
Location
GB
I would like to run TREND Interscan CVP alongside a cluster of Nokia Firewalls running Checkpoint NG FW (Feature Pack 3). Has anyone else done this? Does it work well? Is there anything I should be aware of when going for it? We have recently upgraded from a Raptor Firewall to the Nokia cluster and our existing version of Interscan TREND requires a dual proxy config to work, which we don't want to do so CVP is really the answer... Any suggestions / advice would be welcome - Thanks.
 
This is the config we use. But we have limited it to SMTP scanning (be carefull when setting this up there are 2 size limits of files one in the CVP settings on the resource and one in the firewall object both default to 1k)


For HTTP we found some sites were not working properly (yahoo, excite...)


For FTP you have the pain of it requiring the full download before it can do a scan so it uses "trickle" it passes some data through unscanned (about 1k in 500) to stop the session timing out we found this to not always work and sessions timing out anyway. It is also very anoying as you have no idea on how long a download will take since you are only receiving a small amount of data then when the whole file has been scaned it sends the rest through. so it sits at 1% for ages then zooms to 100% (this is an anoyance factor and not a problem)
 
When you say that you have limited it to SNMP scanning does that mean that you have disabled FTP and HTTP scanning?!
 
it disabled in the FW1 rules so we allow ftp and http but dont use the CVP resource
(We have other AV layers inside the firewall)

 
If you do implement them i found that if you dont restrict the file types (even if the restricting list is large) performance nose dives.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top