<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enforce RFC compliance for the services protocol in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116536#M16432</link>
    <description>&lt;P&gt;Application Control is about letting you use "Facebook Games" and such in a rule. It's like URL Filtering.&lt;/P&gt;
&lt;P&gt;Basic RFC compliance (like FTP verbs and HTTP verbs) is enforced by a feature called protocol inspection. That does not involve Application Control or any subscription, it's just built right into the firewall.&lt;/P&gt;
&lt;P&gt;Deeper RFC compliance is more the domain of IPS. Still not Application Control, but a subscription feature commonly covered together.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Apr 2021 15:13:15 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2021-04-21T15:13:15Z</dc:date>
    <item>
      <title>Enforce RFC compliance for the services protocol</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116534#M16430</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to Enforce RFC compliance for the services protocols (for example ftp,http,allow ssh v2 only and block ssh v1 ) do i need application control enabled or not?&lt;/P&gt;&lt;P&gt;BR&lt;BR /&gt;Kostas&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 14:34:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116534#M16430</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2021-04-21T14:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Enforce RFC compliance for the services protocol</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116535#M16431</link>
      <description>&lt;P&gt;I would say no - protocols are mostly analyzed by IPS Core protections. APCL enables you to differentiate between Apps, also ones that use the same protocols.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 14:47:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116535#M16431</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-04-21T14:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: Enforce RFC compliance for the services protocol</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116536#M16432</link>
      <description>&lt;P&gt;Application Control is about letting you use "Facebook Games" and such in a rule. It's like URL Filtering.&lt;/P&gt;
&lt;P&gt;Basic RFC compliance (like FTP verbs and HTTP verbs) is enforced by a feature called protocol inspection. That does not involve Application Control or any subscription, it's just built right into the firewall.&lt;/P&gt;
&lt;P&gt;Deeper RFC compliance is more the domain of IPS. Still not Application Control, but a subscription feature commonly covered together.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 15:13:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116536#M16432</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-21T15:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Enforce RFC compliance for the services protocol</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116538#M16433</link>
      <description>&lt;P&gt;As Gunther said the IPS Core Protections enforce this, along with "Inspection Settings" located under Shared Policies.&amp;nbsp; The IPS blade is not necessary unless you are using an R77.30 or older gateway, where Core Protections and Inspection Settings were originally part of the IPS Blade.&amp;nbsp; In R80.10 and later they are part of the standard Access Policy (Firewall blade) as mentioned in my IPS Immersion video class.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 15:17:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116538#M16433</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-04-21T15:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Enforce RFC compliance for the services protocol</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116650#M16450</link>
      <description>&lt;P&gt;Hello again&lt;/P&gt;&lt;P&gt;The below is from admin guide for security management r80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Service Matching&lt;BR /&gt;The Security Gateway identifies (matches) a service according to IP protocol, TCP and UDP port number,&lt;BR /&gt;and protocol signature.&lt;BR /&gt;To make it possible for the Security Gateway to match services by protocol signature, you must enable&lt;BR /&gt;Application &amp;amp; URL Filtering on the Security Gateway and on the Ordered Layer.&lt;BR /&gt;You can configure TCP and UDP services to be matched by source port.&lt;/P&gt;&lt;P&gt;BR,&lt;BR /&gt;Kostas&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 15:30:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116650#M16450</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2021-04-22T15:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: Enforce RFC compliance for the services protocol</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116652#M16451</link>
      <description>&lt;P&gt;Protocol inspection is about enforcing some protocol compliance.&lt;/P&gt;
&lt;P&gt;Protocol signatures are more about differentiating between multiple application-level protocols used over the same port.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 15:35:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enforce-RFC-compliance-for-the-services-protocol/m-p/116652#M16451</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-22T15:35:43Z</dc:date>
    </item>
  </channel>
</rss>

