Configuring a 'CheckPoint Firewall-1' for use with LapLink - Search Again

 

SUMMARY

I'm concerned about using LapLink on my corporate network, and want to understand LapLink's Security features. Also, I'm also looking for information about how I can configure my CheckPoint Firewall-1 to allow LapLink to make secure connections. Can you help me?

 

SOLUTION

Currently there is no proxy or stateful inspection mechanism for LapLink. Access is allowed by opening TCP port 1547 to specific hosts or the network at the discretion of the security administrator. For sites using NAT with private address space or NAT with port multiplexing, you will be unable to allow incoming LapLink connections. Sites using NAT and mapping their internal IP addresses to valid public addresses can, if they choose, set up static mappings for particular LapLink hosts to be reached from the outside.

For demonstration purposes we will be referencing the private network 192.168.100.0/24 as our internal trusted network with all filtering relative to the public Internet. Implementation is similar for any external network.

For this example we show how to permit LapLink to connect to the host 192.168.100.45; permitting LapLink to connect to multiple hosts or an entire network is a trivial modification. This does not imply that hosts with private addresses can actually be reached from outside the trusted network, but is a safe example to use.

CheckPoint Firewall-1 is accessed primarily through a GUI interface. To create a rule through the GUI interface you will need to define a Network Object corresponding to the host or network you wish to allow LapLink access to then define an access rule. Also, create the LapLink service as a TCP/IP service on Port 1547. Consult your Firewall-1 documentation for additional information

To add an access rule:

  1. Log in to the Firewall-1 GUI.

  2. From the Edit menu, click Add Rule. Choose the desired insertion point.

  3. Leave the Source as Any.

  4. Set the destination to 192.168.100.45 (you may need to create an object for the endpoint).

  5. Set the Service to LapLink.

  6. Change the Action to Accept.

  7. Set any additional options as desired.


For additional information about LapLink's security features, see Technical Document 38, LapLink in a Secure Environment

 

 Related Articles

  Configuring a 3Com Home Connect Wireless Gateway for LapLink
  Configuring a Cisco PIX Firewall for use with LapLink
  Configuring a Cisco Router using Access Lists for use with LapLink
  Configuring a Linksys Broadband Etherfast Cable/DSL Router for use with LapLink
  Configuring a NetGear Cable/DSL Router for use with LapLink
  Configuring a Network Associates Gauntlet Firewall for use with LapLink

 

Last updated: Friday, August 10, 2001

Article #43

Legacy Article #2023