<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Accessing the firewalls directly once VPN-ed in in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108637#M14691</link>
    <description>&lt;P&gt;Coming up on 25 years myself...this April&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":flushed_face:"&gt;😳&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Jan 2021 03:31:45 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-01-24T03:31:45Z</dc:date>
    <item>
      <title>Accessing the firewalls directly once VPN-ed in</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108621#M14676</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im sorry if this may seem like a silly inquiry, but its baffling to me why it fails. So I was trying to test something with the customer and we cant seem to figure it out. So, here is the situation...what we would like to be able to do is get direct ssh access to the firewalls once you connect via vpn endpoint client.&lt;/P&gt;&lt;P&gt;We created a rule on top saying from office mode net to the cluster, allow on ssh, but that does not seem to work. There are few layers below and on vpn layer, parent rule is simply office mode net to any on vpn layer itself and then one of rules below allows the access. Same for internal layer...here is the kicker...the 2nd rule we created, which is to block pings from anywhere to firewall also does not seem to do anything, as it has 0 hits, but pings to cluster are blocked by the last implicit clean up rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, they simply want to be able to give ssh access to certain people when they connect to vpn, so they dont need to remote desktop further into anything. I checked office mode community and it shows that vpn domain is set for everything behind the gateways based on topology, so that seems correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions/insight would be helpful. I talked to TAC about it and they have no clue and to make it worse, they dont even want to bother trying...such a waste of time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tx!&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 21:52:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108621#M14676</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-23T21:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing the firewalls directly once VPN-ed in</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108622#M14677</link>
      <description>&lt;P&gt;Send me the SR in a PM.&lt;BR /&gt;The funny thing is the Security Gateway is always in the encryption domain, so you should be able to reach the Security Gateway, assuming there's a rule in place.&lt;BR /&gt;Is there ANY attempts showing in the logs when you try to connect to the Security Gateway via ssh? (Search on the destination IP, not the source)&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 22:50:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108622#M14677</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-23T22:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing the firewalls directly once VPN-ed in</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108628#M14683</link>
      <description>&lt;P&gt;See, thats another hot mess problem with this...its a **bleep** cloud instance and its so useless when it comes to parsing logs (thats the case I opened with TAC). The thing is, I get it has to go through whole rulebase, even layers, so if the very first rule, which is NOT layered rule, allows ssh and then same rule exists in vpn AND internal layer, then it makes no sense at all why it fails and all I see in the logs when I filter is ssh is blocked on clean up rule, which makes no sense at all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 01:25:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108628#M14683</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-24T01:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing the firewalls directly once VPN-ed in</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108630#M14685</link>
      <description>&lt;P&gt;If the rulebase uses multiple ordered layers, the traffic must hit an accept rule in each ordered layer.&lt;BR /&gt;If you're hitting a cleanup rule in a specific layer, that means no other rule in that layer is matching the traffic.&lt;BR /&gt;Which points to either the appropriate rule being missing or a bug.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 02:51:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108630#M14685</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-24T02:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing the firewalls directly once VPN-ed in</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108632#M14686</link>
      <description>&lt;P&gt;Well, below is what I did to fix it...I showed TAC clearly how it was configured and they said "that looks fine", thought thats their typical response for 99% of the things...:). Anyway, looks good now, Man, sometimes I miss old ipso and Nokia days, so nice and simple...&lt;/P&gt;&lt;P&gt;To fix it, I added layer towards the top that said from anywhere to cluster, created new layer and then added allow rule to cluster from accessrole vpn group on desired services and explicit clean up as 2nd layered rule...done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks D.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 02:56:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108632#M14686</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-24T02:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing the firewalls directly once VPN-ed in</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108634#M14688</link>
      <description>&lt;P&gt;I remember the days before Nokia IPSO &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 03:01:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108634#M14688</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-24T03:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing the firewalls directly once VPN-ed in</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108635#M14689</link>
      <description>&lt;P&gt;Im sure both you and Jason Ingram, hehe &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 03:05:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108635#M14689</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-24T03:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing the firewalls directly once VPN-ed in</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108637#M14691</link>
      <description>&lt;P&gt;Coming up on 25 years myself...this April&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":flushed_face:"&gt;😳&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 03:31:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108637#M14691</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-24T03:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing the firewalls directly once VPN-ed in</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108638#M14692</link>
      <description>&lt;P&gt;Thats quite something...but, it also makes you an "old" man at the same time ;))&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2021 03:35:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108638#M14692</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-24T03:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing the firewalls directly once VPN-ed in</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108710#M14709</link>
      <description>&lt;P&gt;Experienced. Seasoned. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 05:43:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/108710#M14709</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-25T05:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing the firewalls directly once VPN-ed in</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/139205#M21230</link>
      <description>&lt;P&gt;Hey was he not chap that developed ghost?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2022 18:57:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Accessing-the-firewalls-directly-once-VPN-ed-in/m-p/139205#M21230</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-01-23T18:57:55Z</dc:date>
    </item>
  </channel>
</rss>

