<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy-based routing interrupts non-rule hosts in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-based-routing-interrupts-non-rule-hosts/m-p/141542#M21856</link>
    <description>&lt;P&gt;We have adjusted rule 12. Now we only allow certain ports - it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Feb 2022 12:09:40 GMT</pubDate>
    <dc:creator>Exonix</dc:creator>
    <dc:date>2022-02-15T12:09:40Z</dc:date>
    <item>
      <title>Policy-based routing interrupts non-rule hosts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-based-routing-interrupts-non-rule-hosts/m-p/141265#M21798</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;we have got a very strange case. Management Server and Security Gateway (cluster) are R81.10&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;there is a Rule&lt;/STRONG&gt;: a "host group" to "public_internet" - accept, rule number 12. Very common rule.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule12.png" style="width: 698px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15357i0E8BAA7E75AA2107/image-size/large?v=v2&amp;amp;px=999" role="button" title="rule12.png" alt="rule12.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;policy-based routing&lt;/STRONG&gt;: if rule number is 12 - use Table 2, which routes all traffic via an interface&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pbr1.png" style="width: 784px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15360i9E3ED82CDDCB7139/image-size/large?v=v2&amp;amp;px=999" role="button" title="pbr1.png" alt="pbr1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It works, but! There are two hosts, and as long as this PBR is enabled, they cannot communicate with each other. I see that the traffic came to one firewall interface (source server is connected to this interface), but didn't leave the other (target server is connected to the second interface). &lt;STRONG&gt;The hosts are not members of the group in the Rule 12! &lt;/STRONG&gt;As soon as I delete the PRB - everything works again. What is wrong and how to fix it?&lt;/P&gt;&lt;P&gt;The Table PRB&lt;STRONG&gt;Z&lt;/STRONG&gt; is used by another PRB with other Rules - but it doesn't affect the hosts:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule10.png" style="width: 650px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15362iBFC22FFFF19FB4F6/image-size/large?v=v2&amp;amp;px=999" role="button" title="rule10.png" alt="rule10.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 13:28:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-based-routing-interrupts-non-rule-hosts/m-p/141265#M21798</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-02-11T13:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Policy-based routing interrupts non-rule hosts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-based-routing-interrupts-non-rule-hosts/m-p/141283#M21802</link>
      <description>&lt;P&gt;Next step will be to have the PBR rule active and then run &lt;STRONG&gt;fw ctl zdebug + drop&lt;/STRONG&gt; and have the two hosts try to talk to each other that aren't working.&amp;nbsp; The drop reason given should provide a clue.&lt;/P&gt;
&lt;P&gt;If you don't see anything related to those two hosts in the zdebug output at all it is a routing issue, try running tcpdump/cppcap and figure out where the traffic is going that is not coming out on the expected interface, it is I imagine improperly leaving on your PBR rule's interface.&amp;nbsp; &amp;nbsp;Try disabling SecureXL for the two problematic hosts only with the steps in the SK below, if that still doesn't have any effect it is probably time for a TAC case.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL" target="_blank"&gt;sk104468: How to disable SecureXL for specific IP addresses&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 16:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-based-routing-interrupts-non-rule-hosts/m-p/141283#M21802</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-02-11T16:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Policy-based routing interrupts non-rule hosts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-based-routing-interrupts-non-rule-hosts/m-p/141542#M21856</link>
      <description>&lt;P&gt;We have adjusted rule 12. Now we only allow certain ports - it works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 12:09:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-based-routing-interrupts-non-rule-hosts/m-p/141542#M21856</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2022-02-15T12:09:40Z</dc:date>
    </item>
  </channel>
</rss>

