<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R80.40 - Policy Layers change in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Policy-Layers-change/m-p/119469#M16889</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Apologies in case this comms as general knowledge to some.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Checkpoint R80.40 implemented where it has one policy, and this policy under Access Control has separated layers. One layer called Network with Firewall blade selected and one layer called Application with Applications &amp;amp; URL Filtering blade selected.&lt;/P&gt;&lt;P&gt;This leaves me with two policy section to manage.&lt;/P&gt;&lt;P&gt;I do see that there is nothing preventing me to update first Layer to include Applications &amp;amp; URL Filtering blade.&lt;/P&gt;&lt;P&gt;What I am not clear is what would be the consideration to be taken if I do this.&lt;/P&gt;&lt;P&gt;Would I be required to go about replicating existing Applications &amp;amp; URL Filtering policy after I enable the blade and publish/install the policy on gateways? Or will it still operate in layers as long first one explicitly does not deny something allowed in second layer?&lt;/P&gt;&lt;P&gt;I am looking at doing consolidation of both blades and minimise policies to manage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Wed, 26 May 2021 13:56:13 GMT</pubDate>
    <dc:creator>AigarsK</dc:creator>
    <dc:date>2021-05-26T13:56:13Z</dc:date>
    <item>
      <title>R80.40 - Policy Layers change</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Policy-Layers-change/m-p/119469#M16889</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Apologies in case this comms as general knowledge to some.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Checkpoint R80.40 implemented where it has one policy, and this policy under Access Control has separated layers. One layer called Network with Firewall blade selected and one layer called Application with Applications &amp;amp; URL Filtering blade selected.&lt;/P&gt;&lt;P&gt;This leaves me with two policy section to manage.&lt;/P&gt;&lt;P&gt;I do see that there is nothing preventing me to update first Layer to include Applications &amp;amp; URL Filtering blade.&lt;/P&gt;&lt;P&gt;What I am not clear is what would be the consideration to be taken if I do this.&lt;/P&gt;&lt;P&gt;Would I be required to go about replicating existing Applications &amp;amp; URL Filtering policy after I enable the blade and publish/install the policy on gateways? Or will it still operate in layers as long first one explicitly does not deny something allowed in second layer?&lt;/P&gt;&lt;P&gt;I am looking at doing consolidation of both blades and minimise policies to manage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 13:56:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Policy-Layers-change/m-p/119469#M16889</guid>
      <dc:creator>AigarsK</dc:creator>
      <dc:date>2021-05-26T13:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 - Policy Layers change</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Policy-Layers-change/m-p/119478#M16892</link>
      <description>&lt;P&gt;Two things:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If you are pushing this policy to any Pre-R80 gateways then you need to maintain the two layers as is (FW only in first layer, App Control in second layer)&lt;/LI&gt;
&lt;LI&gt;If these layers are only used on R80+ gateways, then you can theoretically merge these layers together.&lt;/LI&gt;
&lt;LI&gt;The main consideration in either case is to make sure that both layers accept the traffic you wish to pass. By matching a drop rule in either layer, traffic will not pass.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 15:29:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Policy-Layers-change/m-p/119478#M16892</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-26T15:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 - Policy Layers change</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Policy-Layers-change/m-p/119481#M16893</link>
      <description>&lt;P&gt;Thanks PhoneBoy,&lt;/P&gt;&lt;P&gt;My deployment does not contain any Pre-R80.&lt;/P&gt;&lt;P&gt;I will look at updating layers and duplicating rules from Applications layer.&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 15:35:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Policy-Layers-change/m-p/119481#M16893</guid>
      <dc:creator>AigarsK</dc:creator>
      <dc:date>2021-05-26T15:35:12Z</dc:date>
    </item>
  </channel>
</rss>

