<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inline Layers Question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153602#M25834</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as we went through same exercise few years ago, the way I read/understand&amp;nbsp; "&lt;SPAN&gt;The one thing I can't find is does it matter where to start inline rules when are are starting in an ordered policy and how it affects performance.&amp;nbsp;&lt;/SPAN&gt;" would be&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any problem if my inline layer rule is after some ordered layers ?!!??!!?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If that is the question, then I can say that you will combine ordered with inline layers, when building your policy .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our case we moved from ~300-400 lines ordered layer to ~250 lines (in total) using inline layers .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ty,&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jul 2022 06:37:38 GMT</pubDate>
    <dc:creator>Sorin_Gogean</dc:creator>
    <dc:date>2022-07-22T06:37:38Z</dc:date>
    <item>
      <title>Inline Layers Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153504#M25832</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;We are starting to use inline layers and I'm researching best practices etc. The one thing I can't find is does it matter where to start inline rules when are are starting in an ordered policy and how it affects performance. Any feedback is appreciated.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Anthony&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 21:27:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153504#M25832</guid>
      <dc:creator>antsvett3</dc:creator>
      <dc:date>2022-07-20T21:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layers Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153517#M25833</link>
      <description>&lt;P&gt;What might be beneficial for migration from one policy construct to the next in a given environment and what performs most optimally aren't necessarily the same thing. To understand this further it may help to review the policy matching mechanism i.e.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Unified-Policy-Column-based-Rule-Matching/td-p/9888" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Management/Unified-Policy-Column-based-Rule-Matching/td-p/9888&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also Tomer previously consolidated some good links on Layers here for reference:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Layers-Best-Practices/m-p/21023" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Management/Layers-Best-Practices/m-p/21023&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 08:16:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153517#M25833</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-21T08:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layers Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153602#M25834</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as we went through same exercise few years ago, the way I read/understand&amp;nbsp; "&lt;SPAN&gt;The one thing I can't find is does it matter where to start inline rules when are are starting in an ordered policy and how it affects performance.&amp;nbsp;&lt;/SPAN&gt;" would be&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any problem if my inline layer rule is after some ordered layers ?!!??!!?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If that is the question, then I can say that you will combine ordered with inline layers, when building your policy .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our case we moved from ~300-400 lines ordered layer to ~250 lines (in total) using inline layers .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ty,&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2022 06:37:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153602#M25834</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-07-22T06:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layers Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153676#M25835</link>
      <description>&lt;P&gt;When writing my book I did some limited research about the performance of using solely inline layers with one blade enabled in each (Firewall, APCL/URLF) vs. using a single layer inline that invoked the Firewall blade in the top/parent rules (simple services only), then invoked APCL/URLF in the sub-layers via categories/applications.&amp;nbsp; For an identical policy goal, the resulting compiled Unified policy for each approach looked extremely similar and I wasn't able to detect any difference in rulebase lookup performance between the two.&amp;nbsp; So my basic conclusion was that ordered vs. inline is about the same as far as gateway performance especially due to the new Column-based matching, but if anyone from R&amp;amp;D would like to elaborate on this topic that would be great.&amp;nbsp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My general philosophy is that if you still have the straight ordered layers (one blade per layer) which is what you end up with after a R77.30-&amp;gt;R8X upgrade and they are working well for you, there is no urgent need to spend the time converting it into a fully unified inline policy.&amp;nbsp; This is especially true in my opinion if the policy is very large.&amp;nbsp; It doesn't seem to make a difference in gateway performance, but a properly-constructed inline policy can be easier to understand and work with.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;However&lt;/EM&gt;&lt;/STRONG&gt; if you are creating a brand new policy package from scratch for a new gateway/site, I'd strongly recommend using fully inline layers from the get-go and possibly security zone objects as well.&amp;nbsp; This is a piece of cake to do when starting a policy package from scratch, and will be much easier to manage in the long-term as the policy size grows.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 20:54:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153676#M25835</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-07-23T20:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layers Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153699#M25836</link>
      <description>&lt;P&gt;Where I think you might see a performance improvement with inline layers is in dealing with services that aren’t SecureXL friendly.&lt;BR /&gt;Basically, you can bury them in an inline layer so the rest of the policy will template.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 16:08:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153699#M25836</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-24T16:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layers Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153700#M25837</link>
      <description>&lt;P&gt;Another aspect with ordered layer vs inline layer is that with the former, you need to accept a flow in both Network and Application&amp;nbsp; layers&amp;nbsp;(or any other combination) which could double your logs for the same traffic if you log everything. With inline layer, logs are matched only once in either a "top level" network rule or the inline one, reducing log traffic.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 18:03:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-Layers-Question/m-p/153700#M25837</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2022-07-24T18:03:26Z</dc:date>
    </item>
  </channel>
</rss>

