<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBR limitations in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15792#M1127</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the "ip rule" command is described in the SK for debugging PBR on Secure Gateway.&lt;/P&gt;&lt;P&gt;obviously I implemented PBR from clish.&lt;/P&gt;&lt;P&gt;In reply at your question "Are you using the security gateway as the explicit proxy in this case?", the response is NO, I have an external proxy gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Sep 2018 07:12:20 GMT</pubDate>
    <dc:creator>GG27</dc:creator>
    <dc:date>2018-09-03T07:12:20Z</dc:date>
    <item>
      <title>PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15788#M1123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;reading the sk100500 I was very surprised when it described&lt;/P&gt;&lt;P&gt;The following features/blades are &lt;EM&gt;not&lt;/EM&gt; supported with PBR:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;IPv6&lt;/LI&gt;&lt;LI&gt;Locally-generated traffic&lt;/LI&gt;&lt;LI&gt;Security Servers&lt;/LI&gt;&lt;LI&gt;Data Loss Prevention (DLP) blade&lt;/LI&gt;&lt;LI&gt;Anti-Spam blade&lt;/LI&gt;&lt;LI&gt;Mail Transfer Agent (MTA) (relevant for Threat Emulation/Threat Extraction/Data Loss Prevention/Anti-Spam blades)&lt;/LI&gt;&lt;LI&gt;ISP Redundancy&lt;/LI&gt;&lt;LI&gt;The following applications (which use Check Point Active Streaming [CPAS]):&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;VoIP (H323, SIP, Skinny, etc.)&lt;/LI&gt;&lt;LI&gt;HTTPS Inspection&lt;/LI&gt;&lt;LI&gt;HTTP Header Spoofing&lt;/LI&gt;&lt;LI&gt;HTTP Proxy&lt;/LI&gt;&lt;LI&gt;IMAP in IPS&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Despite my idea where, routing feature on the gateway musn't influence the security features, at the moment I need to have a PBR on a gateway where MTA is active for the TEX blade.&lt;/P&gt;&lt;P&gt;In the enviroment where I'd like to implement PBR and I have MTA enabled on a R80.10 gateway, the PBR doesn't work.&lt;/P&gt;&lt;P&gt;Does someone face the same scenario ?&lt;/P&gt;&lt;P&gt;Does someone know a workaround/solution?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2018 15:08:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15788#M1123</guid>
      <dc:creator>GG27</dc:creator>
      <dc:date>2018-08-03T15:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15789#M1124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Locally generated traffic accounts for most of the limitations, including MTA.&lt;/P&gt;&lt;P&gt;It would be useful to hear about your specific use case in a little more detail.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2018 22:18:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15789#M1124</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-03T22:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15790#M1125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the idea shoud be implement a PBR to move internet browsing from a proxy server inside the network throught out a new provider.&lt;/P&gt;&lt;P&gt;I implemented the PBR as I made in the past for other costumers, but it the first time the PBR doesn't work.&lt;/P&gt;&lt;P&gt;I mean running "IP RULE" command in expert mode on the gateway, I see the matches at my PBR.&lt;/P&gt;&lt;P&gt;Dumping the traffic, instead, the packets are forwarded by the route in the main route tables&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Aug 2018 08:11:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15790#M1125</guid>
      <dc:creator>GG27</dc:creator>
      <dc:date>2018-08-06T08:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15791#M1126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Routing configuration changes needs to be done via clish and not using the ip command via expert mode.&lt;/P&gt;&lt;P&gt;Are you using the security gateway as the explicit proxy in this case?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 02:07:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15791#M1126</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-14T02:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15792#M1127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the "ip rule" command is described in the SK for debugging PBR on Secure Gateway.&lt;/P&gt;&lt;P&gt;obviously I implemented PBR from clish.&lt;/P&gt;&lt;P&gt;In reply at your question "Are you using the security gateway as the explicit proxy in this case?", the response is NO, I have an external proxy gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Sep 2018 07:12:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15792#M1127</guid>
      <dc:creator>GG27</dc:creator>
      <dc:date>2018-09-03T07:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15793#M1128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So how is the traffic flowing from your clients to the Internet?&lt;/P&gt;&lt;P&gt;Since proxies are involved, need to understand where the TCP connections are terminating.&lt;/P&gt;&lt;P&gt;And are you using the Transparent proxy option?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Sep 2018 16:50:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15793#M1128</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-03T16:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15794#M1129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the browser on client is configured to use explicit proxy and the communication starts from client and terminate at the proxy end.&lt;/P&gt;&lt;P&gt;The proxy, then, initiates the connection to the web site&lt;/P&gt;&lt;P&gt;in other words, running tcpdump on gateway I see as source IP, the IP of proxy server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2018 05:32:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15794#M1129</guid>
      <dc:creator>GG27</dc:creator>
      <dc:date>2018-09-04T05:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15795#M1130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So do the packets from your internal proxy server terminate on another proxy server or just go to the Internet sites directly?&lt;/P&gt;&lt;P&gt;Also, my question about proxy mode, which you didn't answer.&lt;/P&gt;&lt;P&gt;The setting is here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70025_pastedImage_1.jpg" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2018 14:24:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15795#M1130</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-04T14:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15796#M1131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon&lt;/P&gt;&lt;P&gt;The internal proxy goes out to the internet directly. No more proxy are in the middle between internal proxy and internet.&lt;/P&gt;&lt;P&gt;In reply CKP proxy configuration, the gateways are not configured as a proxy and the box on the property is not tricked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2018 15:51:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15796#M1131</guid>
      <dc:creator>GG27</dc:creator>
      <dc:date>2018-09-06T15:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15797#M1132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I recommend opening a TAC case to troubleshoot this as, to the best of my knowledge, this should work.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2018 22:30:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/15797#M1132</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-06T22:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/64594#M4935</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I also have a questions to the Limitations stated in SK100500.&lt;/P&gt;&lt;P&gt;We use URLFilter and IPS so the limitation is that those two features are not working for traffic that is handled by the PBR OR are&amp;nbsp; those features without function for every traffic?&lt;/P&gt;&lt;P&gt;KR&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 07:42:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/64594#M4935</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2019-10-09T07:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/64627#M4936</link>
      <description>&lt;P&gt;According to&amp;nbsp;&lt;SPAN&gt;sk100500, IPS &amp;nbsp;and URLF are not working with PBR.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 13:06:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/64627#M4936</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-10-09T13:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/64628#M4937</link>
      <description>&lt;P&gt;Yes this SK100500 is telling us that but my question is if the whole IPS and URLF is not working/supported or only not supported/working for the PBR traffic?!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 13:09:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/64628#M4937</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2019-10-09T13:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/64639#M4938</link>
      <description>&lt;P&gt;I think that the limitations are pointing that you cannot make routing decisions based on those blades.&lt;/P&gt;&lt;P&gt;If not I would be really confused, I have many customers with PBRs and IPS and both blades are working like a charm.&lt;/P&gt;&lt;P&gt;Would be nice that someone from Check Point clarifies it, it's true that the sk is not clear enough.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 13:50:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/64639#M4938</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-10-09T13:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/75009#M5800</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Does anyone know if it is possible to configure Mobile Access with PBR?&lt;/P&gt;&lt;P&gt;I have two ISP in two different firewall's interfaces and we would like to publish only the Mobile Access portal with the ISP which is NOT the default gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've performed some traffic captures and fw monitor, and I clearly see that traffic is reaching through ISP2 but the returning traffic is being routed through ISP2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you to everyone in advance, I really really like this community.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 16:59:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/75009#M5800</guid>
      <dc:creator>Enrique</dc:creator>
      <dc:date>2020-02-12T16:59:32Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/75878#M5861</link>
      <description>&lt;P&gt;It would be great if someone from Check Point could clarify this.&lt;/P&gt;&lt;P&gt;We have two open TAC cases for different customers and we cannot move forward as TAC are saying the blades you have enabled will not work with PBR.&lt;/P&gt;&lt;P&gt;It would be really helpful if someone could answer why, rather than just pointing us to this ambiguous SK&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 12:33:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/75878#M5861</guid>
      <dc:creator>Peter_Lyndley</dc:creator>
      <dc:date>2020-02-20T12:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/77472#M5937</link>
      <description>&lt;P&gt;see sk76281&amp;nbsp; -&lt;BR /&gt;did you select &lt;STRONG&gt;Reply from the same interface ?&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;When Responding to a Remotely Initiated Tunnel&lt;/P&gt;&lt;P class="tpbodytext"&gt;When responding to a remotely initiated tunnel, there are two options for selecting the interface and next hop that are used. &lt;EM&gt;These settings are only relevant for IKE and RDP sessions.&lt;/EM&gt;&lt;/P&gt;&lt;P class="tpbodytext"&gt;These settings are configured in &lt;STRONG&gt;Link Selection &amp;gt; Outgoing Route Selection &amp;gt; Setup &amp;gt; Link Selection - Responding Traffic&lt;/STRONG&gt; window.&lt;/P&gt;&lt;UL class="listbullet"&gt;&lt;LI&gt;&lt;STRONG&gt;Use outgoing traffic configuration&lt;/STRONG&gt; - Select this option to choose an interface using the same method selected in the &lt;STRONG&gt;Outgoing Route Selection&lt;/STRONG&gt; section of the &lt;STRONG&gt;Link Selection&lt;/STRONG&gt; page.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Reply from the same interface&lt;/STRONG&gt; - This option sends the returning traffic through the same interface and next hop it that it arrived in.&lt;/LI&gt;&lt;/UL&gt;&lt;TABLE border="0" width="642" cellspacing="0" cellpadding="2"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="60"&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD width="582"&gt;&lt;P class="note"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt; - When Route Based Probing is enabled, &lt;STRONG&gt;Reply from the same interface &lt;/STRONG&gt;is the selected method and cannot be changed.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Niky&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 15:35:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/77472#M5937</guid>
      <dc:creator>Nicolas_Vanhoek</dc:creator>
      <dc:date>2020-03-06T15:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: PBR limitations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/85737#M6615</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;the post is long ago, but at the moment I'm facing some problems regarding pbr. I just wanted to ask you if you got any response from officials regarding the mentioned incompatibility with PBR and some core features?&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 06:38:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-limitations/m-p/85737#M6615</guid>
      <dc:creator>Gro_Tea</dc:creator>
      <dc:date>2020-05-19T06:38:24Z</dc:date>
    </item>
  </channel>
</rss>

