Objects are the central piece of most of the firewalls that currently
exist – be it the traditional stateful firewalls or the over-used term
“Next-Generation” firewall. Objects are the containers for IP addresses,
subnets, services i.e. ports. The rationale being:
- Create an object
- Use that object in the Firewall rules, NAT policies, VPN communities
etc. - In case the IP address / port needs to be changed, simple make that
change in the object , so that the changes get automatically reflected in all
the firewall rules, NAT policies, VPN communities that use the object. This is
the sole purpose of the objects’ existence (besides making the IP addresses or
ports, more admin friendly) - Multiple network or service objects are grouped together in a Network or
Service group
Depending on the type of the value
that goes into the object, Checkpoint has multiple types of objects.
- Network Object
- Host Object
- Network Group
- Service Object
The Checkpoint objects in R80.x can be created from the main work pane, via “Object Categories” (located in a pane, towards the right of the dashboard), as below. The steps to create the objects remains the same as its predecessors.
1. Network Object
2. Host Object
Optional: In case of automatic NAT configuration for the object, behind a particular gateway. In the below example host object with the original IP of 1.1.1.1 (created above) will be NATted to the IP address of 2.2.2.2 and apply for the Gateway “BranchOffice”
3. Network Group
4. Service Objects – The ports can be single (just mention the number) or a range of ports (hyphen separated lower and upper port numbers)
Comments
Post a Comment