<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rules I created is not working in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193007#M4300</link>
    <description>&lt;P&gt;I am sorry, the version is R81.10&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Sep 2023 04:07:58 GMT</pubDate>
    <dc:creator>Nidhi01</dc:creator>
    <dc:date>2023-09-19T04:07:58Z</dc:date>
    <item>
      <title>Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192889#M80</link>
      <description>&lt;P&gt;&lt;FONT face="book antiqua,palatino"&gt;I have configured the checkpoint firewall in Azure. I have used Checkpoint Security Manager and Cloud Guard single gateway plan for this environment.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="book antiqua,palatino"&gt;The environment is like this - I have created one Virtual network and there are two subnets in the Vnet. I have deployed Server Manager in the Subnet 1 and Cloud guard single gateway where its first NIC is connected to Subnet 1 and the second NIC is connected to Subnet 2. I have deployed two Azure Virtual machines in the same network only but in different Subnets like VM01 in Subnet 1 and VM02 in Subnet 2. Now I wanted to block RDP service from VM01 to Vm02 as by default they can communicate with each other. However, the rule I created in the Checkpoint Server Manager does not block the RDP from the source to the destination. what could be the possible reason behind this? why is my rule not hitting the source and destination?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="book antiqua,palatino"&gt;&lt;SPAN&gt;I am expecting that I can block RDP for VM01 and VM02 through the rules I created in checkpoint smart Console.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 10:25:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192889#M80</guid>
      <dc:creator>Nidhi01</dc:creator>
      <dc:date>2023-09-18T10:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192944#M81</link>
      <description>&lt;P&gt;What version?&lt;BR /&gt;Did you deploy from one of our templates or manually?&lt;BR /&gt;What shows in the logs when VM01 attempts to access VM02?&lt;BR /&gt;Have you confirmed the traffic is actually traversing the gateway (via tcpdump or similar)?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 15:15:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192944#M81</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-18T15:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192946#M82</link>
      <description>&lt;P&gt;I am using R80.10 version,&lt;/P&gt;&lt;P&gt;I have deployed the security manager and gateway from the Azure portal.&lt;/P&gt;&lt;P&gt;I am not sure how to confirm that the traffic is traversing through the gateway or not. Can you please let me know how can I check that and how to fix it?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 15:21:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192946#M82</guid>
      <dc:creator>Nidhi01</dc:creator>
      <dc:date>2023-09-18T15:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192949#M83</link>
      <description>&lt;P&gt;Can you send screenshot of the rule thats not working (please blur out any sensitive info)?&lt;/P&gt;
&lt;P&gt;Also, as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;mentioned, its important to verify that traffic is indeed traversing the firewall, otherwise, if not, its totally logical why rule would never get hit.&lt;/P&gt;
&lt;P&gt;Makes sense?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 15:37:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192949#M83</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-18T15:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192968#M84</link>
      <description>&lt;P&gt;Please check the version again as R80.10 is End of Support.&lt;BR /&gt;Easiest way I know to check: with tcpdump on the gateway itself.&lt;BR /&gt;If the gateway isn't seeing the traffic, it can't enforce any sort of policy on it.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 18:03:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192968#M84</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-18T18:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192975#M85</link>
      <description>&lt;P&gt;Very easy...anyway, R80.10 is totally unsupported, but regardless of version, command is the same. Say interface is eth2 and IP is 10.10.10.10&lt;/P&gt;
&lt;P&gt;you can run below:&lt;/P&gt;
&lt;P&gt;tcpdump -enni any host 10.10.10.10&lt;/P&gt;
&lt;P&gt;or/and&lt;/P&gt;
&lt;P&gt;fw monitor -e "accept host(10.10.10.10);"&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 18:33:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/192975#M85</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-18T18:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193006#M4299</link>
      <description>&lt;P&gt;Thanks Andy,&lt;/P&gt;&lt;P&gt;I have attached a screenshot of the rules I created.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 04:06:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193006#M4299</guid>
      <dc:creator>Nidhi01</dc:creator>
      <dc:date>2023-09-19T04:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193007#M4300</link>
      <description>&lt;P&gt;I am sorry, the version is R81.10&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 04:07:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193007#M4300</guid>
      <dc:creator>Nidhi01</dc:creator>
      <dc:date>2023-09-19T04:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193045#M4303</link>
      <description>&lt;P&gt;The rule works 100%, you can clearly see that from your screenshot. There are even logs showing that at the bottom.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 10:19:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193045#M4303</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-19T10:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193046#M4304</link>
      <description>&lt;P&gt;Yeah it's generating logs but the main purpose to create a rule is to block the RDP of the virtual machines but I am able to take RDP of the VM01 and VM02. its not blocking.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 10:22:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193046#M4304</guid>
      <dc:creator>Nidhi01</dc:creator>
      <dc:date>2023-09-19T10:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193051#M4306</link>
      <description>&lt;P&gt;I would suggest you involve TAC to resolve this issue !&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 11:36:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193051#M4306</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-09-19T11:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193061#M4307</link>
      <description>&lt;P&gt;RDP from where exactly? Remember what both&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;and myself mentioned in previous responses, run captures to make sure that traffic even hits the firewall, because if not, it will never work.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 12:37:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193061#M4307</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-19T12:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193375#M4316</link>
      <description>&lt;P&gt;Check your Azure VMs. &amp;nbsp;The VMs are deployed automatically with a public IP address attached to their NICs. &amp;nbsp;This IP is directly reachable to the Internet, not via your VNET. &amp;nbsp;The VM also has a local IP on the subnet, but that's a private IP. &amp;nbsp;Are you trying to reach your VM via the Azure public DNS name of "vm01-asdfadsf.&amp;lt;region&amp;gt;.cloudapp.azure.com" ? &amp;nbsp;If so, then you're reaching the VM's direct-attached public IP; which will not pass through your CloudGuard firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 16:27:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193375#M4316</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2023-09-22T16:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: Rules I created is not working</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193383#M4317</link>
      <description>&lt;P&gt;Good point, I totally missed the config was in Azure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 19:10:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Rules-I-created-is-not-working/m-p/193383#M4317</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-22T19:10:05Z</dc:date>
    </item>
  </channel>
</rss>

