<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP Forwarding R80.10 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Forwarding-R80-10/m-p/166659#M30004</link>
    <description>&lt;P&gt;Which version of management hopefully not R80.10 still as is no longer supported?&lt;/P&gt;
&lt;P&gt;In theory it can be disabled for Management machines (SMS), please consult with TAC for the procedure.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jan 2023 15:50:41 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-01-04T15:50:41Z</dc:date>
    <item>
      <title>IP Forwarding R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Forwarding-R80-10/m-p/87575#M6759</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I just have my vulnerability report for my firewall and it turns out that I need to disable the IP forwarding mechanism in my CP.&lt;/P&gt;&lt;P&gt;Based on my understanding in general computer networks, IP forwarding is the process handling the packet transfers. If we disable it in the Check Point, how will the firewall transfer packets now? Is my understanding correct or is there something more deeper than that as far as Check Point firewall is concerned?&lt;/P&gt;&lt;P&gt;I was told to disable using this command,&lt;/P&gt;&lt;P&gt;&lt;EM&gt;# echo 0 &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Thanks for your replies in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 08:01:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Forwarding-R80-10/m-p/87575#M6759</guid>
      <dc:creator>CyberBreaker</dc:creator>
      <dc:date>2020-06-08T08:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: IP Forwarding R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Forwarding-R80-10/m-p/87653#M6772</link>
      <description>&lt;P&gt;Don't do that, unless you want to cause an outage.&lt;/P&gt;
&lt;P&gt;On a regular Linux server, turning off IP Forwarding in the IP driver is a perfectly valid recommendation in most cases.&amp;nbsp; It is not appropriate to manually manipulate this value on a Check Point firewall.&amp;nbsp; The Check Point code controls the state of IP forwarding, switching it from the default of 0 to 1 when Check Point services have started, and changing it from 1 to 0 when Check Point services are stopped or policy is unloaded.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you manually set it to zero, all traffic attempting to transit the firewall will stop working and be dropped by the IP driver just after inspection point I and just before inspection point o.&amp;nbsp; Traffic to and from the firewall itself (i.e. SSH connections to clish/expert mode), HTTPS connections to the Gaia web interface, and firewall management operations will still work, but little else will.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 19:26:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Forwarding-R80-10/m-p/87653#M6772</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-06-08T19:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: IP Forwarding R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Forwarding-R80-10/m-p/166642#M30000</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;If this&amp;nbsp;&lt;SPAN&gt;vulnerability was on SmartCenter. Should we config&amp;nbsp;&lt;EM&gt;/proc/sys/net/ipv4/ip_forward value to 0?&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Tkanks for a lot.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 05:50:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Forwarding-R80-10/m-p/166642#M30000</guid>
      <dc:creator>Giga_Yang</dc:creator>
      <dc:date>2023-01-04T05:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: IP Forwarding R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Forwarding-R80-10/m-p/166659#M30004</link>
      <description>&lt;P&gt;Which version of management hopefully not R80.10 still as is no longer supported?&lt;/P&gt;
&lt;P&gt;In theory it can be disabled for Management machines (SMS), please consult with TAC for the procedure.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 15:50:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Forwarding-R80-10/m-p/166659#M30004</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-04T15:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: IP Forwarding R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Forwarding-R80-10/m-p/166681#M30012</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;R81 with JFH Take44&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2023 14:29:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IP-Forwarding-R80-10/m-p/166681#M30012</guid>
      <dc:creator>Giga_Yang</dc:creator>
      <dc:date>2023-01-04T14:29:13Z</dc:date>
    </item>
  </channel>
</rss>

