<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBR source port or fwrule in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-source-port-or-fwrule/m-p/170299#M30871</link>
    <description>&lt;P&gt;The functionality of PBR based on Source Port requires a specific software release, most likely.&lt;BR /&gt;Your local Check Point office should be able to get the details of this.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Feb 2023 19:33:26 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-02-03T19:33:26Z</dc:date>
    <item>
      <title>PBR source port or fwrule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-source-port-or-fwrule/m-p/170278#M30863</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I try to setup a PBR rule - but i'm currently stuck...&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Is it possible to use PBR rule matching source port instead of destination port ?&lt;BR /&gt;&lt;BR /&gt;Or, second question - how can we use the match on fwrule ?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;0&amp;gt; set pbr rule priority 300 match fwrule&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Configures the 'firewall rule' match condition for a&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Policy Based Routing (PBR) rule.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Value: Specify which firewall rule to match by&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;entering the rule number or rule name, as&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;it appears in SmartConsole&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The firewall rule must be configured through SmartConsole&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;first before you can use it here. When creating the rule&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;in SmartConsole, it must begin with the prefix 'PBR_'&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;followed by the rule name.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Example: PBR_SSH, PBR_Telnet&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;0&amp;gt; set pbr rule priority 300 match fwrule PBR_test&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;RTGRTG0001 FW rule ID does not exist.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;set pbr rule priority 300 match fwrule PBR_test&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;--------------------------------^^^^^^^^^^^^^^^&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 15:36:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-source-port-or-fwrule/m-p/170278#M30863</guid>
      <dc:creator>Arthur_DENIS1</dc:creator>
      <dc:date>2023-02-03T15:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: PBR source port or fwrule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-source-port-or-fwrule/m-p/170280#M30864</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17200"&gt;@Arthur_DENIS1&lt;/a&gt;&amp;nbsp; How to use firewall rules for application based PBR&amp;nbsp;&lt;A title="Policy-Based Routing and Application-Based Routing in Gaia" href="https://support.checkpoint.com/results/sk/sk167135" target="_blank" rel="noopener"&gt;Policy-Based Routing and Application-Based Routing in Gaia&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use of firewall rules for PBR will be used for ABR (Application Based Routing).&amp;nbsp;&lt;SPAN&gt;PBR for source port is not supported.&amp;nbsp;&lt;BR /&gt;Please explain what do you want, maybe ther‘s another solution.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 16:02:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-source-port-or-fwrule/m-p/170280#M30864</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-02-03T16:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: PBR source port or fwrule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-source-port-or-fwrule/m-p/170285#M30865</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the answer.&lt;BR /&gt;What if I use a firewall rule containing service restricted to a source port ? Can work or not ?&lt;BR /&gt;&lt;BR /&gt;Source port should be possible, based on&amp;nbsp;sk100500 - "&lt;SPAN&gt;The following features&amp;nbsp;are&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;not&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;supported by PBR by default, and are available only as a Request for Enhancement (RFE)&amp;nbsp;via Check Point local office:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;PBR with Source Port routing"&lt;BR /&gt;So I assume that it as already implemented for somes customers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Please find attached a draft of the target design.&lt;BR /&gt;The need: be able to initiate opnvpn from IP public 1 and/or 2 in the same time. I do not find other way to do that without PBR...&lt;BR /&gt;Any ideas are welcome !&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 16:31:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-source-port-or-fwrule/m-p/170285#M30865</guid>
      <dc:creator>Arthur_DENIS1</dc:creator>
      <dc:date>2023-02-03T16:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: PBR source port or fwrule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-source-port-or-fwrule/m-p/170299#M30871</link>
      <description>&lt;P&gt;The functionality of PBR based on Source Port requires a specific software release, most likely.&lt;BR /&gt;Your local Check Point office should be able to get the details of this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2023 19:33:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-source-port-or-fwrule/m-p/170299#M30871</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-03T19:33:26Z</dc:date>
    </item>
  </channel>
</rss>

