<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reverse Proxy + Access Rules in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-Proxy-Access-Rules/m-p/186953#M34399</link>
    <description>&lt;P&gt;Block services? Nope.&lt;/P&gt;&lt;P&gt;I've published services via Reverse Proxy:&lt;/P&gt;&lt;P data-unlink="true"&gt;1. Service 1: https://example1.domain.com/&amp;nbsp; ---&amp;gt; internal.server.com:8080&lt;/P&gt;&lt;P data-unlink="true"&gt;2. Service 2: https://example2.domain.com/&amp;nbsp;&amp;nbsp;---&amp;gt; anotherinternal.server.com:80&lt;/P&gt;&lt;P data-unlink="true"&gt;So, when there is an external requests to subdomain Service1 it proxies to internal service. I want to create access rule for that https://*.domain.com&amp;nbsp;&amp;nbsp;&amp;nbsp;services. For example, Group of external IP addresses have access to example1.domain.com, or only US IP addresses (Updatable object) have access to example2.domain.com&lt;SPAN&gt;&amp;nbsp;and etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 20 Jul 2023 04:44:32 GMT</pubDate>
    <dc:creator>nemezis_rock</dc:creator>
    <dc:date>2023-07-20T04:44:32Z</dc:date>
    <item>
      <title>Reverse Proxy + Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-Proxy-Access-Rules/m-p/186833#M34376</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;How to restrict access to services that were published via Reverse Proxy? Can someone provide exmaple configuration?&lt;/P&gt;&lt;P&gt;I've already played with Access Rules after checking box Unified Access Policy. But access policy not working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attaching log file showing that rules not working. It is just passing traffic according empty rule... Im confused.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 13:22:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-Proxy-Access-Rules/m-p/186833#M34376</guid>
      <dc:creator>nemezis_rock</dc:creator>
      <dc:date>2023-07-19T13:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse Proxy + Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-Proxy-Access-Rules/m-p/186839#M34377</link>
      <description>&lt;P&gt;What exact services are you trying to block? Can you send a screenshot of the rule you created? Please blur out any sensitive info.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 13:53:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-Proxy-Access-Rules/m-p/186839#M34377</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-19T13:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse Proxy + Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-Proxy-Access-Rules/m-p/186953#M34399</link>
      <description>&lt;P&gt;Block services? Nope.&lt;/P&gt;&lt;P&gt;I've published services via Reverse Proxy:&lt;/P&gt;&lt;P data-unlink="true"&gt;1. Service 1: https://example1.domain.com/&amp;nbsp; ---&amp;gt; internal.server.com:8080&lt;/P&gt;&lt;P data-unlink="true"&gt;2. Service 2: https://example2.domain.com/&amp;nbsp;&amp;nbsp;---&amp;gt; anotherinternal.server.com:80&lt;/P&gt;&lt;P data-unlink="true"&gt;So, when there is an external requests to subdomain Service1 it proxies to internal service. I want to create access rule for that https://*.domain.com&amp;nbsp;&amp;nbsp;&amp;nbsp;services. For example, Group of external IP addresses have access to example1.domain.com, or only US IP addresses (Updatable object) have access to example2.domain.com&lt;SPAN&gt;&amp;nbsp;and etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 20 Jul 2023 04:44:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-Proxy-Access-Rules/m-p/186953#M34399</guid>
      <dc:creator>nemezis_rock</dc:creator>
      <dc:date>2023-07-20T04:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse Proxy + Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-Proxy-Access-Rules/m-p/187046#M34432</link>
      <description>&lt;P&gt;When you say "Reverse Proxy" are you referring to the configuration here?&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk110348" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk110348&lt;/A&gt;&lt;BR /&gt;More details on exactly what you've configured will help.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 12:48:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-Proxy-Access-Rules/m-p/187046#M34432</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-20T12:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse Proxy + Access Rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-Proxy-Access-Rules/m-p/187062#M34445</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for reply, and&lt;/P&gt;&lt;P&gt;Of course I read some topics, how would I publish web service via ReverseProxy without reading docs?&lt;/P&gt;&lt;P&gt;I have published web service:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="proxyrule.png" style="width: 913px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21820i7FA86A48BC5AD451/image-size/large?v=v2&amp;amp;px=999" role="button" title="proxyrule.png" alt="proxyrule.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And it works &lt;STRONG&gt;fine&lt;/STRONG&gt;, it published and I can access it from internet. But I want also create some &lt;STRONG&gt;Access Rules&lt;/STRONG&gt; for published services and give access only known hosts from internet. Some of checkmaters are saying that it is &lt;STRONG&gt;not possible&lt;/STRONG&gt;. But,&lt;/P&gt;&lt;P&gt;After playing with rules and analyzing it, i noticed that Access Rules working but &lt;STRONG&gt;Partially&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you create&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#00FF00"&gt;Accept&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;rule for&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#0000FF"&gt;ExternalIP&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and dst&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#0000FF"&gt;test.domain.com&lt;/FONT&gt;, traffic&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;goes through that rule&lt;/STRONG&gt;. But&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#0000FF"&gt;other External IPs&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;goes through Implied Access Rule 0:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nemezis_rock_0-1689858073026.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21824i6198BFA4E93B5CF9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nemezis_rock_0-1689858073026.png" alt="nemezis_rock_0-1689858073026.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So traffic goes in this order i believe:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nemezis_rock_1-1689858073081.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21823i1F615BB8C79F3934/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nemezis_rock_1-1689858073081.png" alt="nemezis_rock_1-1689858073081.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It just cant reach&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;drop&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;rule. If there is any way to &lt;STRONG&gt;disable&lt;/STRONG&gt; implied rule, or move the order of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#00FF00"&gt;Accept&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;rule of&amp;nbsp;&lt;FONT color="#000000"&gt;Implied Rule&lt;/FONT&gt;&amp;nbsp;and place it after&amp;nbsp;&lt;FONT color="#FF0000"&gt;Drop&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Rule of Access Policy it will work i think.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 13:02:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Reverse-Proxy-Access-Rules/m-p/187062#M34445</guid>
      <dc:creator>nemezis_rock</dc:creator>
      <dc:date>2023-07-20T13:02:52Z</dc:date>
    </item>
  </channel>
</rss>

