<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inline Layers in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers/m-p/2256#M102656</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please see the topics &lt;A href="https://community.checkpoint.com/thread/1092"&gt;Layers in R80&lt;/A&gt; and &lt;A href="https://community.checkpoint.com/thread/1201"&gt;How do I create an Access Policy for Pre-R80 GWs?&lt;/A&gt;&amp;nbsp; for the list of the supported features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R80 Management has the support for inline layers, however like you said, when using them for a pre-R80.10 GW, install policy will fail. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setting an inline layer is done by clicking a rule's action and selecting the "Inline Layer" option. You can either select an existing layer (if it's marked as &lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/1091"&gt;shared&lt;/A&gt;) or create a new one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="set-inline-layer.png" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/52490_set-inline-layer.png" style="width: 620px; height: 174px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way that inline layers work is the following: When the connection matches a parent rule that its action is an inline layer, the inline layer rules get evaluated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Every inline layer (and also every layer) has an implicit cleanup rule that is either "any any accept" or "any any drop" set in its properties under "advanced". This means that once you go inside an inline layer, you cannot go outside back to the main layer, therefore rules in the inline layer cannot block rules that reside below the parent rule that holds them. Giving an admin the permission to only edit an inline layer will not affect the main layer that holds it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To see the list of all layers, open the Manage Layers view from this location:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="open-manage-layers.png" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/52491_open-manage-layers.png" style="width: 620px; height: 547px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Apr 2016 07:40:21 GMT</pubDate>
    <dc:creator>Tomer_Sole</dc:creator>
    <dc:date>2016-04-27T07:40:21Z</dc:date>
    <item>
      <title>Inline Layers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers/m-p/2255#M102655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know that inline layers are not supported for pre-R80 gateways, but can I even create them (for testing purposes) in R80 SmartConsole? It seems that only ordered layers are supported now?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Apr 2016 16:33:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers/m-p/2255#M102655</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2016-04-26T16:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers/m-p/2256#M102656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please see the topics &lt;A href="https://community.checkpoint.com/thread/1092"&gt;Layers in R80&lt;/A&gt; and &lt;A href="https://community.checkpoint.com/thread/1201"&gt;How do I create an Access Policy for Pre-R80 GWs?&lt;/A&gt;&amp;nbsp; for the list of the supported features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R80 Management has the support for inline layers, however like you said, when using them for a pre-R80.10 GW, install policy will fail. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setting an inline layer is done by clicking a rule's action and selecting the "Inline Layer" option. You can either select an existing layer (if it's marked as &lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/1091"&gt;shared&lt;/A&gt;) or create a new one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="set-inline-layer.png" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/52490_set-inline-layer.png" style="width: 620px; height: 174px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way that inline layers work is the following: When the connection matches a parent rule that its action is an inline layer, the inline layer rules get evaluated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Every inline layer (and also every layer) has an implicit cleanup rule that is either "any any accept" or "any any drop" set in its properties under "advanced". This means that once you go inside an inline layer, you cannot go outside back to the main layer, therefore rules in the inline layer cannot block rules that reside below the parent rule that holds them. Giving an admin the permission to only edit an inline layer will not affect the main layer that holds it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To see the list of all layers, open the Manage Layers view from this location:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="open-manage-layers.png" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/52491_open-manage-layers.png" style="width: 620px; height: 547px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Apr 2016 07:40:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers/m-p/2256#M102656</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2016-04-27T07:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers/m-p/2257#M102657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Query: when we add the Target gateway in the InLine layer then we need to explicitly add the same targets in the rules inside? I think we need not as the InLine says for which target the rules are also even if we add any other gateway as the target inside then it will not work (traffic will not match the Inline).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is my understanding correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 06:51:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers/m-p/2257#M102657</guid>
      <dc:creator>Mohammed_Omin_B</dc:creator>
      <dc:date>2019-02-21T06:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers/m-p/2258#M102658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, that is not necessary to do.&lt;/P&gt;&lt;P&gt;In fact, it would be redundant to do so and make it difficult to reuse the layer on a different gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Feb 2019 02:45:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers/m-p/2258#M102658</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-24T02:45:05Z</dc:date>
    </item>
  </channel>
</rss>

