NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW1] FW-1 and AOL




It's not HTTPS. I have the same problems. Something screwed up in the
security server. I'm on 4.1 SP3 by the way. I kludged a workaround by
allowing http only to aol server IP addresses without using any URI filters
nor websense. I know it will break if AOL changes their IP addresses but
hey, I said it was a workaround not a fix.

----------------------------------------------------------------------------------------

Greg Winkler
Systems Manager, IT&S
Huntsman Corporation
Internet Mail: [email protected]
Voice:Fax:Chris F <[email protected]>                                                                                       
                    Sent by:                                    To:     Greg Gonzalez <[email protected]>,                            
                    [email protected]        [email protected]                              
                    kpoint.com                                  cc:                                                                       
                                                                Subject:     Re: [FW1] FW-1 and AOL                                       
                                                                                                                                          
                    05/03/2001 02:07 PM                                                                                                   
                                                                                                                                          
                                                                                                                                          




I think once you login AOL -- it uses HTTPS. I don't
use AOL, so I could be mistaken.

Do you allow HTTPS?

Put a rule to allow access to AOL site(s) before your
Websense rule for AOL as destination and HTTPS as
service.

My guess is it will work :)

HTH -- Chris

--- Greg Gonzalez <[email protected]> wrote:
>
> Hello Everyone. Here is  my dilema.
>
> I run Checkpoint Fw-1 4.1 on NT 4.0. I also use
> Websense to block certain sites. When I activate a
> rule that blocks certain web sites, I can get to the
> AOL home page on IE but no futher that that on AOL's
> site. Any other AOL link after I enter my name a
> password comes up with a white screen "The PAGE
> CANNOT BE DISPLAYED". If I disable the websense,
> everything browses fine. This only seems to be with
> AOL. I thought It was something with WEBSENSE.
>
> After futher troubleshooting, I created a rule as
> follows:
>
> Source      Destination   Service
> Action       Track
> SSLNET   ANY              http->Wildcard      Accept
>       Long
>
> The wildcard is nothing more than URI that allows
> FW-1 to behave as if Websense was in place without
> actually making any calls via UFP. It simply uses
> the Security server to contact sites in the same
> manner it would with Websense in place.
>
> After doing this, AOL stopped working again. It
> seems that if I use ANY URI, AOL stops working so
> its NOT websense but something with Checkpoint FW-1.
>
> If I added a rule to use HTTP ALLOW, AOL would not
> work since a URI is in effect. If I change it it:
> SSLNET  ANY ANY, then HTTP and AOL works fine. ANY
> IDEAS?????
>
> UUNET/Checkpoint  is stumped!
>
>
>
> Greg Gonzalez
> Network Systems Manager
> Stroock & Stroock & Lavan, LLP
> 180 Maiden Lane
> New York, NY 10038
>>
>
>
>
================================================================================

>      To unsubscribe from this mailing list, please
> see the instructions at
>
> http://www.checkpoint.com/services/mailing.html
>
================================================================================

>


__________________________________________________
Do You Yahoo!?
Yahoo! Auctions - buy the things you want at great prices
http://auctions.yahoo.com/


================================================================================

     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================








================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.