<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Explicit proxy traffic accepted via implied rule 0 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/137045#M20741</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any updates this topic? we are facing same problem after upgrade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Dec 2021 06:03:43 GMT</pubDate>
    <dc:creator>AykutYILMAZ</dc:creator>
    <dc:date>2021-12-23T06:03:43Z</dc:date>
    <item>
      <title>Explicit proxy traffic accepted via implied rule 0</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/122812#M17580</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;We have R80.40 installation (SMS + GW Cluster), which was migrated from R77.30.&lt;/P&gt;&lt;P&gt;This GW cluster is set up as explicit proxy for some clients.&lt;/P&gt;&lt;P&gt;We have 2 ordered layers: Security and Application.&lt;/P&gt;&lt;P&gt;On both layers we have a rule that allow traffic from client hosts to GW cluster via ports 8080 and 3128 (HTTP &amp;amp;HTTPS proxy and Squid_NTLM).&lt;/P&gt;&lt;P&gt;On Application layer we have rules that allow traffic from client hosts to Intetrnet with specified URLs and applications.&lt;/P&gt;&lt;P&gt;Everything was fine on version R77.30, but after migration we have an issue:&lt;/P&gt;&lt;P&gt;Traffic received by Checkpoint proxy is&amp;nbsp; forwarded to Internet without enforcing URL filtering policy.&lt;/P&gt;&lt;P&gt;I can see in logs 2 different events:&lt;/P&gt;&lt;P&gt;1) Traffic from client host to Checkpoint proxy (port 3128 and 8080) is accepted by correct rules on Security and Application layer (event type Firewall)&lt;/P&gt;&lt;P&gt;2) Traffic from GW to external web resource is accepted on Security layer with Implied rule 0 and no checks on Application layer is performed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried to disable in Global policy "Accept outgoing packets originating from security gateway" parameter and create separate explicit rule to allow GW cluster to communicate with "Any" destinations.&lt;/P&gt;&lt;P&gt;I've checked according to sk112939 "Enable HTTP inspection on non standard ports for the Application Control &amp;amp; URL Filtering Blades" - we have it turned on, but it's not helping.&lt;/P&gt;&lt;P&gt;I've checked Implicit cleanup settings on Security and Application layers - both are set to "Drop".&lt;/P&gt;&lt;P&gt;I've checked Implicit rules in &lt;EM&gt;$FWDIR/state/local/FW1/local.implied_rules&lt;/EM&gt; - there is no rule with ID 0.&lt;/P&gt;&lt;P&gt;I've rebooted SMS and reinstalled the policy - no effect.&lt;/P&gt;&lt;P&gt;Please, can anyone tell me why we are getting this implied rule here? How can we enforce URL filtering policy on proxied traffic again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 12:26:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/122812#M17580</guid>
      <dc:creator>Undel</dc:creator>
      <dc:date>2021-07-02T12:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Explicit proxy traffic accepted via implied rule 0</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/122814#M17581</link>
      <description>&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110013" target="_blank" rel="noopener"&gt;sk110013 - How to configure Check Point Security Gateway as HTTP/HTTPS Proxy&lt;/A&gt;&amp;nbsp;has a comment that seems relevant:&lt;/P&gt;
&lt;TABLE class="footnote" border="1" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Application &amp;amp; URL Filtering with a single interface&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;When Security Gateway is configured as HTTP/HTTPS Proxy with a single interface, define the relevant rules in 'Application &amp;amp; URL Filtering' policy as follows: Source - 'Any'; Destination - 'Any'.&lt;/P&gt;
&lt;P&gt;Refer to &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk80340" target="_blank" rel="noopener"&gt;sk80340&amp;nbsp;&lt;SPAN&gt;Applications and/or URL Filtering Categories are not blocked when Security Gateway is configured as HTTP Proxy with a single interface&lt;/SPAN&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Fri, 02 Jul 2021 12:54:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/122814#M17581</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-07-02T12:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Explicit proxy traffic accepted via implied rule 0</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/122942#M17603</link>
      <description>&lt;P&gt;I don't get it.&lt;/P&gt;&lt;P&gt;If we make URL filtering rules with source:Any and destination:Any - how can we block or deny something for specific users,groups, hosts,networks?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 08:32:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/122942#M17603</guid>
      <dc:creator>Undel</dc:creator>
      <dc:date>2021-07-05T08:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Explicit proxy traffic accepted via implied rule 0</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/122945#M17605</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;mentioned behaviour is problematic with "Internet" as destination. You can use any as destination and defining your "URLs" in the service/application field.&lt;/P&gt;
&lt;P&gt;As another solution you can define your Application-layer rule with source your_client_networks and destination your proxy_IP and&amp;nbsp;your "URLs" in the service/application field.&lt;/P&gt;
&lt;P&gt;In my opinion I would suggest creating a new layer for "Application/URL-filter" and add them as inline layer to the rule allowing the traffic from clients to the proxy.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 09:15:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/122945#M17605</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-07-05T09:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Explicit proxy traffic accepted via implied rule 0</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/137045#M20741</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any updates this topic? we are facing same problem after upgrade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 06:03:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/137045#M20741</guid>
      <dc:creator>AykutYILMAZ</dc:creator>
      <dc:date>2021-12-23T06:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Explicit proxy traffic accepted via implied rule 0</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/139315#M21262</link>
      <description>&lt;P&gt;Curious if you figured out a solution/fix for this one as I am in a similar boat.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 18:58:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Explicit-proxy-traffic-accepted-via-implied-rule-0/m-p/139315#M21262</guid>
      <dc:creator>_Mike_</dc:creator>
      <dc:date>2022-01-24T18:58:20Z</dc:date>
    </item>
  </channel>
</rss>

