The Firewall Hardening Guide v0.1 - Checkpoint Firewall-1 Specific Requirements - Services

Enable FTP PORT Data Connections

This setting enables the use of FTP through Firewall-1.
We recommend that this setting should be enabled, provided internal users are allowed to do file downloading using FTP clients.

Enable FTP PASV Connections

This setting enables web browsers to do FTP downloads. Most (if not all) web browsers today, including Internet Explorer and Netscape uses FTP PASV connections for their file transfers (FTP://…..).   FTP PASV connections represent a higher security risk under certain conditions, and should be applied carefully.
We recommend that this setting should be enabled, provided internal users are allowed to do file downloading using their web browsers.

Enable RSH/REXEC Reverse stderr Connections

Allows RSH and REXEC to open reverse connections for the stderr file. Enabling these services may represent certain security risks, and should be applied carefully.
This setting should be disabled, unless there exists a documented need for these services.

Enable RPC control

Enabling Remote Procedure Call may represent certain security risks, and should be applied carefully. RPC may be used to obtain information on what services are running (=available) on a given host.
This setting should be disabled, unless there exists a documented need for these services.
 

Share this article

Receive all the latest articles by email!

Get all articles delivered directly to your mailbox as and when they are released on WindowSecurity.com! Choose between receiving instant updates with the Real-Time Article Update, or a monthly summary with the Monthly Article Update.



Receive all the latest articles by email!

Receive Real-Time & Monthly WindowSecurity.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowSecurity.com member!

Discuss your security issues with thousands of other network security experts. Click here to join!

Community Area

Log in | Register

Solution Center

Readers' Choice

Which is your preferred Authentication solution?