With FW-1 4.1, I used a rule at the top of the rule base - any any remadmin accept (remadmin service is TCP port 4899)This worked fine but not with NG - any clues?
change it to FW-1_mgmt (port 258)this is what fw-1 uses
you may find that when you went from 4.1 to NG it changed rrom inbound analasys to eitherbound (NG only works in eitherbound) analasys so your admin rule wouldnt have been needed so it worked anyway.
i would also strongly advise changing your rule to
management clients group - firewall - fw1_mgmt - accept
Actually, on NG the GUI port is 18190 and you should start by making sure that your firewall is listening on this port (use 'netstat -an' to check for TCP port 18190 in LISTEN mode).
Then unload your policy (you should unplug the external interface first to be safe) using the NG command 'fw unloadlocal'.
Now connect your GUI client and make sure that your policy includes the right services in the first rule for admin.
Alternatively, and perhaps more correctly, simply install a good SSH client (I prefer Vandyke SecureCRT, but PuTTY is pretty good now) and port forward port 18190. Connect to the firewall on port 22 (SSH) and then run the GUI to connect to localhost (127.0.0.1). Hey Presto, a secure tunnelled GUI connection *and* you dont need to mess around with the GUI-Clients files.
shaggerTM
(Fascist Security Consultant and all-round nice guy).
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.