<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Implied rule override explicit rule in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rule-override-explicit-rule/m-p/138668#M21080</link>
    <description>&lt;P&gt;&lt;SPAN&gt;We have enabled above option as "before last" &amp;amp; after checking logs we are getting random ip's are still trying to connect external DNS servers.&lt;/SPAN&gt;&lt;SPAN&gt;even though we have explicit rule configured for our internal DNS. Would like to know as per behaviour all DNS logs should hit to explicit rule, but&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;not occurring in this scenario.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;anyone&amp;nbsp; provide me answer why external DNS request's are hitting over Implied rules (Configrued as "before last" under global properties)&lt;/P&gt;
&lt;P&gt;even when an explicit rule has priority.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 125&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ADMIN NOTE: The attachments were removed to protect the confidentiality of our customer.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Dec 2025 09:45:36 GMT</pubDate>
    <dc:creator>Sunray</dc:creator>
    <dc:date>2025-12-10T09:45:36Z</dc:date>
    <item>
      <title>Implied rule override explicit rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rule-override-explicit-rule/m-p/138668#M21080</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have enabled above option as "before last" &amp;amp; after checking logs we are getting random ip's are still trying to connect external DNS servers.&lt;/SPAN&gt;&lt;SPAN&gt;even though we have explicit rule configured for our internal DNS. Would like to know as per behaviour all DNS logs should hit to explicit rule, but&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;not occurring in this scenario.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;anyone&amp;nbsp; provide me answer why external DNS request's are hitting over Implied rules (Configrued as "before last" under global properties)&lt;/P&gt;
&lt;P&gt;even when an explicit rule has priority.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 125&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ADMIN NOTE: The attachments were removed to protect the confidentiality of our customer.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 09:45:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rule-override-explicit-rule/m-p/138668#M21080</guid>
      <dc:creator>Sunray</dc:creator>
      <dc:date>2025-12-10T09:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rule override explicit rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rule-override-explicit-rule/m-p/138701#M21089</link>
      <description>&lt;P&gt;To clarify you have configured a rule specifically to "drop" this DNS traffic higher in the policy that is not matching?&lt;/P&gt;
&lt;P&gt;Perhaps it is easier to work this with TAC if you're uncomfortable with showing the relevant policy rules &amp;amp; log card detail here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 07:27:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rule-override-explicit-rule/m-p/138701#M21089</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-01-18T07:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rule override explicit rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rule-override-explicit-rule/m-p/138715#M21092</link>
      <description>&lt;P&gt;Hello Chris,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had allowed in any for all DNS traffic in explicit rule on higher priority but still traffic for external DNS hitting implicit rule.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 09:26:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rule-override-explicit-rule/m-p/138715#M21092</guid>
      <dc:creator>Sunray</dc:creator>
      <dc:date>2022-01-18T09:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rule override explicit rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rule-override-explicit-rule/m-p/138723#M21094</link>
      <description>&lt;P&gt;As above please provide more details of the policy, log card &amp;amp; matched rules tab so we can help.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 10:08:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rule-override-explicit-rule/m-p/138723#M21094</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-01-18T10:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rule override explicit rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rule-override-explicit-rule/m-p/138914#M21163</link>
      <description>&lt;P&gt;Hello Chris&lt;/P&gt;
&lt;P&gt;Getting SOA packet for which Implied rule action accept. I have attached all logs&lt;/P&gt;
&lt;P&gt;These are VPN user 10.0.0.0 IP range some user hitting external DNS with SOA packet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ADMIN NOTE: The attachments were removed to protect the confidentiality of our customer.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;We are planning to disable Global Properties "Accept Domain Name over UDP (Queries )" will it impact legitimate traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 09:46:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rule-override-explicit-rule/m-p/138914#M21163</guid>
      <dc:creator>Sunray</dc:creator>
      <dc:date>2025-12-10T09:46:04Z</dc:date>
    </item>
  </channel>
</rss>

