<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy verification fails with Data Center objects in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Policy-verification-fails-with-Data-Center-objects/m-p/122341#M1353</link>
    <description>&lt;P&gt;I am guessing rule 300 NSGs contain IP addresses from rule 100 and 200 NSGs.&lt;/P&gt;
&lt;P&gt;try moving rule 300 over 100 and 200 , especially when the Service is ANY&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jun 2021 09:34:34 GMT</pubDate>
    <dc:creator>Nir_Shamir</dc:creator>
    <dc:date>2021-06-28T09:34:34Z</dc:date>
    <item>
      <title>Policy verification fails with Data Center objects</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Policy-verification-fails-with-Data-Center-objects/m-p/122332#M1352</link>
      <description>&lt;P&gt;We noticed a strange issue with policy verification (R80.40). The policy is heavily AWS dependent, more than 50% of all rules are using AWS security groups either as a source or a destination. Here is example of some of the rules:&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="12.5%" height="25px"&gt;Rule#&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;Source&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;Destination&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;Service&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;Action&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="12.5%" height="25px"&gt;100&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;10.0.0.0/8&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;sg-aaa, sg-bbb&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;Any&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;Accept&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="12.5%" height="25px"&gt;...&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="12.5%" height="25px"&gt;200&lt;/TD&gt;&lt;TD width="12.5%" height="25px"&gt;10.0.0.0/8&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;sg-ccc&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;Any&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;Accept&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="25px"&gt;...&lt;/TD&gt;&lt;TD height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="25px"&gt;300&lt;/TD&gt;&lt;TD height="25px"&gt;10.0.0.0/8&lt;/TD&gt;&lt;TD height="25px"&gt;sg-ddd, sg-eee&lt;/TD&gt;&lt;TD height="25px"&gt;Any&lt;/TD&gt;&lt;TD height="25px"&gt;Drop&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Verifier complains that rules 100 and 200 conflict with rule 300. Security groups are different, and they are not empty.&lt;/P&gt;&lt;P&gt;Strangely, policy installation succeeds. Furthermore, running policy verification after installation succeeds as well.&lt;/P&gt;&lt;P&gt;Any ideas why is this happening and how to avoid it? Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 08:11:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Policy-verification-fails-with-Data-Center-objects/m-p/122332#M1352</guid>
      <dc:creator>Srdjan_B</dc:creator>
      <dc:date>2021-06-28T08:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Policy verification fails with Data Center objects</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Policy-verification-fails-with-Data-Center-objects/m-p/122341#M1353</link>
      <description>&lt;P&gt;I am guessing rule 300 NSGs contain IP addresses from rule 100 and 200 NSGs.&lt;/P&gt;
&lt;P&gt;try moving rule 300 over 100 and 200 , especially when the Service is ANY&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 09:34:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Policy-verification-fails-with-Data-Center-objects/m-p/122341#M1353</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2021-06-28T09:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Policy verification fails with Data Center objects</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Policy-verification-fails-with-Data-Center-objects/m-p/123567#M1354</link>
      <description>&lt;P&gt;Thank you, but that is not the case. Rule 100 is related to one application, rule 200 is related to another and rule 300 is related to third application. They are not sharing any VMs, there are no IPs from rule 300 which belong to SGs referenced in rules 100 and 200.&lt;/P&gt;&lt;P&gt;It happened multiple times (example is simplified, there are 50+ rules like the examples above as there are 50+ applications).&lt;/P&gt;&lt;P&gt;Basically, for application CCC, we have detailed, specific rules 190-199 and the permissive rule 200. Rules 190-199 are there to permit what we know is required. Rule 200 is temporary rule, we use it to check if something was missed.&amp;nbsp;Once we are confident that rules 190-199 are sufficient for that application, we will change action on rule 200 to drop. And after that, if we do explicit verify, it complains that 200 conflicts 100. If we push policy, it gets verified and installed on gateways. Next verify is successful too.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If something was wrong with the policy, I would expect installation to fail too. Also, doing explicit verify after policy push is successful and policy is identical to the one when it failed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And last, customer has upgraded management to R81 and we see the same behaviour.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 06:39:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Policy-verification-fails-with-Data-Center-objects/m-p/123567#M1354</guid>
      <dc:creator>Srdjan_B</dc:creator>
      <dc:date>2021-07-12T06:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Policy verification fails with Data Center objects</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Policy-verification-fails-with-Data-Center-objects/m-p/123579#M1355</link>
      <description>&lt;P&gt;If anything, we liberalized the policy verification rules in R80.40 and above.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk161574" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk161574&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The fact it's failing at all in this instance is a bug (worse, it's doing so inconsistently).&lt;BR /&gt;Looks similar to this bug:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk168272" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk168272&lt;/A&gt;&lt;BR /&gt;Recommend a TAC case.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 07:40:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Policy-verification-fails-with-Data-Center-objects/m-p/123579#M1355</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-12T07:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: Policy verification fails with Data Center objects</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Policy-verification-fails-with-Data-Center-objects/m-p/123589#M1356</link>
      <description>&lt;P&gt;Thank you, this looks very similar to what we have seen few months back (with actual IA rules and access roles). But it happened once and never came back, so we did not continue investigation.&lt;/P&gt;&lt;P&gt;Since Data Center objects are based on IA, it is quite possible this is related. I will check if customer is willing to invest time in further investigation and opening SR.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 10:41:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Policy-verification-fails-with-Data-Center-objects/m-p/123589#M1356</guid>
      <dc:creator>Srdjan_B</dc:creator>
      <dc:date>2021-07-12T10:41:46Z</dc:date>
    </item>
  </channel>
</rss>

