<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBR road-map and URLF/Identity requirements  (policy-based routing) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161079#M28478</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;- thanks for pointing out the right sk (&lt;SPAN&gt;sk167135).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5758"&gt;@Garrett_DirSec&lt;/a&gt;&amp;nbsp;: PBR/ABR does support identity rules. Please contact me directly for further help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Raghu&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Nov 2022 05:07:42 GMT</pubDate>
    <dc:creator>rdevarak</dc:creator>
    <dc:date>2022-11-03T05:07:42Z</dc:date>
    <item>
      <title>PBR road-map and URLF/Identity requirements  (policy-based routing)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161036#M28463</link>
      <description>&lt;P&gt;Hello--&amp;nbsp; larger existing CP customer testing Policy-based Routing (aka "PBR") and disappointed on current incantation.&lt;/P&gt;&lt;P&gt;Based on sk100500, it appears that PBR operates at layer4 and currently can't make any decisions based on upper layers -- nor can higher level blades features be applied to traffic AFTER a PBR decision.&lt;/P&gt;&lt;P&gt;Customer would like to do the following.&amp;nbsp;&amp;nbsp; Both not possible today.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;make PBR decision based on identity&lt;/LI&gt;&lt;LI&gt;apply URLF policy to traffic following PBR decision.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any road-map, work-arounds, or insight would be appreciated.&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks -GA&lt;/P&gt;&lt;P&gt;reference Policy-based Routing -- SK100500&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100500" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100500&lt;/A&gt;&lt;/P&gt;&lt;P&gt;excerpts:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Routing and Firewall Processing&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;It is important to note that routing tables, including PBR tables, are checked &lt;STRONG&gt;after&lt;/STRONG&gt; firewall processing is complete.&lt;BR /&gt;This means that in situations such as NAT, routing rules are checked against the original source address (refer to &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101562" target="_blank" rel="noopener"&gt;sk101562&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;The following features/blades are &lt;EM&gt;not&lt;/EM&gt; supported with PBR:&lt;/P&gt;&lt;P&gt;&amp;lt;basically... everything&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 15:14:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161036#M28463</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2022-11-02T15:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: PBR road-map and URLF/Identity requirements  (policy-based routing)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161041#M28464</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5758"&gt;@Garrett_DirSec&lt;/a&gt;&amp;nbsp;do you know&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167135" target="_blank" rel="noopener"&gt;Policy-Based Routing and Application-Based Routing in Gaia.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;New features allowing PBR based on applications.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 15:30:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161041#M28464</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-11-02T15:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: PBR road-map and URLF/Identity requirements  (policy-based routing)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161045#M28468</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt; -- thanks for your msg and post.&amp;nbsp; I was not aware of this SK.&amp;nbsp;&amp;nbsp; I will post feedback on Sk100500 to reference the newer &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;solutionid=sk167135" target="_blank" rel="nofollow noopener noreferrer"&gt;sk167135&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;While the addition of application to decision logic, this doesn't address customer requirements to operate based on identity and apply URLF to traffic post-decision.&lt;/P&gt;&lt;P&gt;Sincere thanks for the insight.&amp;nbsp;&amp;nbsp; I hope it comes in handy in future.&amp;nbsp;&amp;nbsp; -GA&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 15:43:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161045#M28468</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2022-11-02T15:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: PBR road-map and URLF/Identity requirements  (policy-based routing)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161079#M28478</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;- thanks for pointing out the right sk (&lt;SPAN&gt;sk167135).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5758"&gt;@Garrett_DirSec&lt;/a&gt;&amp;nbsp;: PBR/ABR does support identity rules. Please contact me directly for further help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Raghu&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 05:07:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161079#M28478</guid>
      <dc:creator>rdevarak</dc:creator>
      <dc:date>2022-11-03T05:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: PBR road-map and URLF/Identity requirements  (policy-based routing)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161087#M28484</link>
      <description>&lt;P&gt;In addition to &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/46678"&gt;@rdevarak&lt;/a&gt;&amp;nbsp; snip from sk167135 for support of identities:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The purpose of extending the basic PBR rule criteria to include Firewall rule is to enable users to match on configured Firewall rules and forward traffic accordingly. This extension of PBR functionality forwards the &lt;STRONG&gt;traffic based on application, service, users, time, location, and many more, as supported by FW rules&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But as you mentioned, applying rules after PBR will be problematic.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 06:56:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161087#M28484</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-11-03T06:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: PBR road-map and URLF/Identity requirements  (policy-based routing)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161097#M28488</link>
      <description>&lt;P&gt;It can only be done in hairpin topology (LIG - Legal Interception Gateway) with another peer FW. May be with VSX but it is an interesting scenario to explore it further.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 07:21:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161097#M28488</guid>
      <dc:creator>rdevarak</dc:creator>
      <dc:date>2022-11-03T07:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: PBR road-map and URLF/Identity requirements  (policy-based routing)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161098#M28489</link>
      <description>&lt;P&gt;Out of curiosity, what's the use-case for performing security decisions after the outbound routing?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 07:27:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161098#M28489</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2022-11-03T07:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: PBR road-map and URLF/Identity requirements  (policy-based routing)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161194#M28507</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;-- great question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;customer has various use-case scenarios where one of three uplinks would be used.&amp;nbsp;&lt;/P&gt;&lt;P&gt;when the traffic is from end-user, the requirement is to enforce URLF on traffic, regardless of PBR/PBF decision.&lt;/P&gt;&lt;P&gt;thanks -GA&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 22:25:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-road-map-and-URLF-Identity-requirements-policy-based-routing/m-p/161194#M28507</guid>
      <dc:creator>Garrett_DirSec</dc:creator>
      <dc:date>2022-11-03T22:25:19Z</dc:date>
    </item>
  </channel>
</rss>

