<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Another way to filter out a network from pdp instead of idc configuration? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/130710#M19201</link>
    <description>&lt;P&gt;Hello Community&lt;/P&gt;&lt;P&gt;Is any other way to filter out a network from pdp instead of idc configuration?&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;</description>
    <pubDate>Thu, 30 Sep 2021 14:32:03 GMT</pubDate>
    <dc:creator>KostasGR</dc:creator>
    <dc:date>2021-09-30T14:32:03Z</dc:date>
    <item>
      <title>Another way to filter out a network from pdp instead of idc configuration?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/130710#M19201</link>
      <description>&lt;P&gt;Hello Community&lt;/P&gt;&lt;P&gt;Is any other way to filter out a network from pdp instead of idc configuration?&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 14:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/130710#M19201</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2021-09-30T14:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Another way to filter out a network from pdp instead of idc configuration?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/130840#M19242</link>
      <description>&lt;P&gt;You mean on the gateways themselves?&lt;BR /&gt;I don't believe so.&lt;BR /&gt;Can you explain why this is relevant in your situation?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2021 18:14:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/130840#M19242</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-01T18:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Another way to filter out a network from pdp instead of idc configuration?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/130903#M19258</link>
      <description>&lt;P&gt;Hello PhoneBoy&lt;/P&gt;&lt;P&gt;I mean the Identity awareness gateways themselves.&lt;/P&gt;&lt;P&gt;After updating the IDCs to latest version it seems that filter out doesn't work as expected.&lt;/P&gt;&lt;P&gt;Is it a known issue?&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 08:08:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/130903#M19258</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2021-10-04T08:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Another way to filter out a network from pdp instead of idc configuration?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/130977#M19272</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;what say you?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 00:24:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/130977#M19272</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-05T00:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Another way to filter out a network from pdp instead of idc configuration?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/131009#M19277</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54611"&gt;@KostasGR&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;To answer your initial question:&lt;/P&gt;
&lt;P&gt;In Identity Broker, there is a way to filter by network.&lt;/P&gt;
&lt;P&gt;However, I'm more concerned about your statement &lt;EM&gt;"After updating the IDCs to latest version it seems that filter out doesn't work as expected."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I'm not aware of such issue - can you open ticket with TAC and share IDC service debugs (sk122686)?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 10:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/131009#M19277</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2021-10-05T10:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Another way to filter out a network from pdp instead of idc configuration?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/131013#M19279</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are not using identity broker. We solved our issue by importing again the exclusions on IDC.&lt;/P&gt;&lt;P&gt;The upgrade procedure we followed is the below. You can replicate easily on your lab.&lt;/P&gt;&lt;P&gt;1)Export configuration of&amp;nbsp;IDC&lt;/P&gt;&lt;P&gt;2)Uninstall old&amp;nbsp;version of&amp;nbsp;IDC&lt;/P&gt;&lt;P&gt;3)Reboot the windows server&lt;/P&gt;&lt;P&gt;4)Install the&amp;nbsp;latest version of&amp;nbsp;IDC&lt;/P&gt;&lt;P&gt;5)Import config of&amp;nbsp;IDC&lt;/P&gt;&lt;P&gt;6)Establish connectivity with PDP&lt;/P&gt;&lt;P&gt;7)Check IDC status/logs/filters&lt;/P&gt;&lt;P&gt;8)Check PDP status&lt;/P&gt;&lt;P&gt;9)Check the registry value for monitor functionality that is present&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;10)import again the user exception filter&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems that step 10 is also needed for exception filters to work as expected. Even though we could see them on IDC&amp;nbsp; configuration the exclusions for service accounts weren't working..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 10:48:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/131013#M19279</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2021-10-05T10:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Another way to filter out a network from pdp instead of idc configuration?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/131014#M19280</link>
      <description>&lt;P&gt;Thanks for the fast reply. I will certainly test it.&lt;/P&gt;
&lt;P&gt;A question - in step 7, have you noticed if the relevant filters were exist on the IDC configuration?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By the way, there is an easier way to update IDC in my opinion:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Export configuration of&amp;nbsp;IDC - same&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Install the&amp;nbsp;latest version of&amp;nbsp;IDC on top of the old one - same as step 4 on your procedure&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;after that, no other steps are needed (no need to import the config / re-establish PDP communication).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 10:55:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/131014#M19280</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2021-10-05T10:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Another way to filter out a network from pdp instead of idc configuration?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/131016#M19281</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In step 7 the filters were present.&lt;/P&gt;&lt;P&gt;In the next IDC upgrade i will follow your procedure &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 10:58:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Another-way-to-filter-out-a-network-from-pdp-instead-of-idc/m-p/131016#M19281</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2021-10-05T10:58:53Z</dc:date>
    </item>
  </channel>
</rss>

