<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: need &amp;quot;initial policy&amp;quot; specifics for R81 distributed gateway (no SIC established) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/need-quot-initial-policy-quot-specifics-for-R81-distributed/m-p/141204#M26945</link>
    <description>&lt;P&gt;After the first-time wizard, you should get InitialPolicy. That one allows management services.&lt;/P&gt;
&lt;P&gt;After a reboot, you probably get defaultPolicy instead. That one drops everything.&amp;nbsp;You can check this with 'fw stat' before the 'fw unloadlocal'.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Feb 2022 19:27:02 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2022-02-10T19:27:02Z</dc:date>
    <item>
      <title>need "initial policy" specifics for R81 distributed gateway (no SIC established)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/need-quot-initial-policy-quot-specifics-for-R81-distributed/m-p/141192#M26944</link>
      <description>&lt;P&gt;Hello --&lt;/P&gt;&lt;P&gt;Initial Policy on model 5800 newly re-imaged with R81 (no jumbo ...yet).&lt;/P&gt;&lt;P&gt;SIC has NOT been established with SmartCenter.&lt;/P&gt;&lt;P&gt;What should we expect with initial policy after Initial Setup Wizard completed?&lt;/P&gt;&lt;P&gt;Immediately after run of Wizard, we can talk to gateway Mgmt IP (192.168.1.1) via both SSH and HTTPS/443.&lt;/P&gt;&lt;P&gt;I know that I can establish SIC at this point, so I know there are subset of secure CP services that are accepted.&lt;/P&gt;&lt;P&gt;At all times, I'm assuming Initial Policy allows full outbound access originated from gateway.&lt;/P&gt;&lt;P&gt;If we gracefully reboot this gateway, the inbound SSH and HTTPS/443 are blocked and we must execute "fw unloadlocal".&lt;/P&gt;&lt;P&gt;why is this true after reboot?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why does Initial Policy "change" from period following Wizard to following reboot?&amp;nbsp; This weird.&lt;/P&gt;&lt;P&gt;The Administrator Guide does NOT delve into specifics on this.&amp;nbsp;&amp;nbsp; &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/The-Initial-Policy.htm" target="_blank" rel="noopener"&gt;Initial-Policy-R81.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I did find the discussed on following thread interesting &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Checkpoint-Security-Gateway-applies-quot-Initial-Policy-quot/td-p/115695" target="_blank" rel="noopener"&gt;Initial Policy after Firmware Upgrade.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;thanks -GA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 17:50:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/need-quot-initial-policy-quot-specifics-for-R81-distributed/m-p/141192#M26944</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2022-02-10T17:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: need "initial policy" specifics for R81 distributed gateway (no SIC established)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/need-quot-initial-policy-quot-specifics-for-R81-distributed/m-p/141204#M26945</link>
      <description>&lt;P&gt;After the first-time wizard, you should get InitialPolicy. That one allows management services.&lt;/P&gt;
&lt;P&gt;After a reboot, you probably get defaultPolicy instead. That one drops everything.&amp;nbsp;You can check this with 'fw stat' before the 'fw unloadlocal'.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 19:27:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/need-quot-initial-policy-quot-specifics-for-R81-distributed/m-p/141204#M26945</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-02-10T19:27:02Z</dc:date>
    </item>
  </channel>
</rss>

