<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Two Layers - Order rule issues in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Two-Layers-Order-rule-issues/m-p/84781#M11277</link>
    <description>When it was matching on a different rule (before you added the specific rule) what rule did it match on?&lt;BR /&gt;Note that evaluation against the rulebase is a continual process and if the stream looks like a different app later on, and a different, earlier rule matches, it will apply instead.&lt;BR /&gt;This is by design.</description>
    <pubDate>Mon, 11 May 2020 01:59:33 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-05-11T01:59:33Z</dc:date>
    <item>
      <title>Two Layers - Order rule issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Two-Layers-Order-rule-issues/m-p/84773#M11276</link>
      <description>&lt;P&gt;Hi Checkmaters.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I had a very strange problem. I have a firewall policy with two layers, one for firewall rules and other for app control and url filtering. (layer.jpeg)&lt;/P&gt;&lt;P&gt;The CleanUp rule in the second layer is Accept. (cleanup_accept.jpeg)&lt;/P&gt;&lt;P&gt;A specific traffic was being accepted in the cleanup rule, but it was intermittent, sometimes working, sometimes not. (cleanup_accept_log.jpeg).&lt;/P&gt;&lt;P&gt;In a desperate attempt to solve the problem, I created a specific rule in the top of the second layer to deal with this traffic. For my surprise, the problem was solved, the traffic worked perfectly. (specific_rule.jpeg and specific_rule_log.jpeg)&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;What happened?&lt;/SPAN&gt; &lt;SPAN class=""&gt;I have no idea!&lt;/SPAN&gt; &lt;SPAN class=""&gt;Has anyone had this problem?&lt;/SPAN&gt; &lt;SPAN class=""&gt;Do you have any idea why this happened?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;PS: version R80.30, take 111.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 May 2020 23:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Two-Layers-Order-rule-issues/m-p/84773#M11276</guid>
      <dc:creator>carlosgeib</dc:creator>
      <dc:date>2020-05-10T23:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Two Layers - Order rule issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Two-Layers-Order-rule-issues/m-p/84781#M11277</link>
      <description>When it was matching on a different rule (before you added the specific rule) what rule did it match on?&lt;BR /&gt;Note that evaluation against the rulebase is a continual process and if the stream looks like a different app later on, and a different, earlier rule matches, it will apply instead.&lt;BR /&gt;This is by design.</description>
      <pubDate>Mon, 11 May 2020 01:59:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Two-Layers-Order-rule-issues/m-p/84781#M11277</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-11T01:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Two Layers - Order rule issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Two-Layers-Order-rule-issues/m-p/84802#M11278</link>
      <description>&lt;P&gt;It was matching in the CleanUp Rule, whose action is Accept.&lt;/P&gt;&lt;P&gt;There was no policy change that could impact.&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 07:28:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Two-Layers-Order-rule-issues/m-p/84802#M11278</guid>
      <dc:creator>carlosgeib</dc:creator>
      <dc:date>2020-05-11T07:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Two Layers - Order rule issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Two-Layers-Order-rule-issues/m-p/84834#M11279</link>
      <description>The policy didn't change but the traffic stream clearly did in how it was identified.&lt;BR /&gt;I'm also not clear from your explanation either what rule it was supposed to match or what rule was matching instead when things stopped working.</description>
      <pubDate>Mon, 11 May 2020 13:16:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Two-Layers-Order-rule-issues/m-p/84834#M11279</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-11T13:16:44Z</dc:date>
    </item>
  </channel>
</rss>

