<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Published service consumption problems. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Published-service-consumption-problems/m-p/186274#M34278</link>
    <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;
&lt;P&gt;I am currently having a problem with accessing a web service.&lt;/P&gt;
&lt;P&gt;We have an explicit rule that allows any Internet IP to access our published server, which has the domain name zonasegura.bn.com.pe.&lt;/P&gt;
&lt;P&gt;The problem is that the Firewall is not processing the traffic with the explicit rule, and is sending all the traffic to the last rule of the rule base (Implicit rule).&lt;/P&gt;
&lt;P&gt;Does anyone know how to correct this behavior?&lt;BR /&gt;I have a Cluster R81.10 with JHF take 87&lt;/P&gt;
&lt;P&gt;I share images of the explicit rule, the CLEANUP rule, and the output of the command "fw ctl zdebug + drop | grep &amp;lt;ANY&amp;gt;".&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IM4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21720i9547B390C2F43293/image-size/large?v=v2&amp;amp;px=999" role="button" title="IM4.png" alt="IM4.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IM3.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21719iA4B4F29D4C760370/image-size/large?v=v2&amp;amp;px=999" role="button" title="IM3.png" alt="IM3.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IM2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21721i44DB5A5D49D8F3A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="IM2.png" alt="IM2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IM1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21722i90196A2243A46D44/image-size/large?v=v2&amp;amp;px=999" role="button" title="IM1.png" alt="IM1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Cheers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jul 2023 18:36:45 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-07-12T18:36:45Z</dc:date>
    <item>
      <title>Published service consumption problems.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Published-service-consumption-problems/m-p/186274#M34278</link>
      <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;
&lt;P&gt;I am currently having a problem with accessing a web service.&lt;/P&gt;
&lt;P&gt;We have an explicit rule that allows any Internet IP to access our published server, which has the domain name zonasegura.bn.com.pe.&lt;/P&gt;
&lt;P&gt;The problem is that the Firewall is not processing the traffic with the explicit rule, and is sending all the traffic to the last rule of the rule base (Implicit rule).&lt;/P&gt;
&lt;P&gt;Does anyone know how to correct this behavior?&lt;BR /&gt;I have a Cluster R81.10 with JHF take 87&lt;/P&gt;
&lt;P&gt;I share images of the explicit rule, the CLEANUP rule, and the output of the command "fw ctl zdebug + drop | grep &amp;lt;ANY&amp;gt;".&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IM4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21720i9547B390C2F43293/image-size/large?v=v2&amp;amp;px=999" role="button" title="IM4.png" alt="IM4.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IM3.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21719iA4B4F29D4C760370/image-size/large?v=v2&amp;amp;px=999" role="button" title="IM3.png" alt="IM3.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IM2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21721i44DB5A5D49D8F3A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="IM2.png" alt="IM2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IM1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21722i90196A2243A46D44/image-size/large?v=v2&amp;amp;px=999" role="button" title="IM1.png" alt="IM1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Cheers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 18:36:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Published-service-consumption-problems/m-p/186274#M34278</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-12T18:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Published service consumption problems.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Published-service-consumption-problems/m-p/186276#M34279</link>
      <description>&lt;P&gt;Drop logs give you an answer. Its dropping on port 80, NOT 443, so you have to add port 80 to the rule. Make sure NAT is in place as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 18:50:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Published-service-consumption-problems/m-p/186276#M34279</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-12T18:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Published service consumption problems.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Published-service-consumption-problems/m-p/186281#M34280</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The strange thing is that this service has always been consumed by the 443 (You open a browser and put the URL in https).&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV dir="auto"&gt;Suddenly the service stopped working.&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;Some users from the Internet report that the page takes too long to load, and others report that the same thing happens to them as to me, it just doesn't load.&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV dir="auto"&gt;The client tells me that this service should be consumed by the 443 and not by the 80, but in the Firewall nothing has been touched.&lt;/DIV&gt;</description>
      <pubDate>Wed, 12 Jul 2023 19:09:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Published-service-consumption-problems/m-p/186281#M34280</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-12T19:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Published service consumption problems.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Published-service-consumption-problems/m-p/186283#M34281</link>
      <description>&lt;P&gt;I would add port 80 based on what I see in the logs.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 19:10:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Published-service-consumption-problems/m-p/186283#M34281</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-12T19:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Published service consumption problems.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Published-service-consumption-problems/m-p/186418#M34300</link>
      <description>&lt;P&gt;Looks like the destination IP in the debug and the IP in the rule is different...maybe adjust the object OR use an FQDN Domain Object?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 22:18:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Published-service-consumption-problems/m-p/186418#M34300</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-13T22:18:15Z</dc:date>
    </item>
  </channel>
</rss>

