<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No change in firewall policy upon re-ordering NAT rules. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-change-in-firewall-policy-upon-re-ordering-NAT-rules/m-p/196026#M36567</link>
    <description>&lt;P&gt;Hardware: 23500&lt;BR /&gt;Version: R81.10 Take 66 (both Gateway and Mgmt)&lt;/P&gt;&lt;P&gt;Summary: NAT rules were re-ordered. There was a hide NAT rule that is moved under 4 static NAT rules. No other changes made to the policy. Publish and push the policy. Found out that the firewall is using the old order of NAT rules. FW stat shows the correct time of policy push that was completed without any errors or warnings. The "rules.C' was showing the last modified date of the previous install not the last install (after re-ordering). Note that all ojects used in all the related NAT rules are local objects, not Global.&lt;/P&gt;&lt;P&gt;It was decided to disable all the relevant static and hide NAT rules (total of 5 rules), re-create the new rules above the disabled rules. After the policy is pushed, the correct order of rules took place and the rules.C file shows the last modified date.&lt;/P&gt;&lt;P&gt;Question is - why in first place a new policy not compiled or what causes where the new set of rules were ignored. Does the rule re-ordering warrant a new policy? Anyone else has similar experience, please share.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2023 12:36:29 GMT</pubDate>
    <dc:creator>Muazzam</dc:creator>
    <dc:date>2023-10-24T12:36:29Z</dc:date>
    <item>
      <title>No change in firewall policy upon re-ordering NAT rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-change-in-firewall-policy-upon-re-ordering-NAT-rules/m-p/196026#M36567</link>
      <description>&lt;P&gt;Hardware: 23500&lt;BR /&gt;Version: R81.10 Take 66 (both Gateway and Mgmt)&lt;/P&gt;&lt;P&gt;Summary: NAT rules were re-ordered. There was a hide NAT rule that is moved under 4 static NAT rules. No other changes made to the policy. Publish and push the policy. Found out that the firewall is using the old order of NAT rules. FW stat shows the correct time of policy push that was completed without any errors or warnings. The "rules.C' was showing the last modified date of the previous install not the last install (after re-ordering). Note that all ojects used in all the related NAT rules are local objects, not Global.&lt;/P&gt;&lt;P&gt;It was decided to disable all the relevant static and hide NAT rules (total of 5 rules), re-create the new rules above the disabled rules. After the policy is pushed, the correct order of rules took place and the rules.C file shows the last modified date.&lt;/P&gt;&lt;P&gt;Question is - why in first place a new policy not compiled or what causes where the new set of rules were ignored. Does the rule re-ordering warrant a new policy? Anyone else has similar experience, please share.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 12:36:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-change-in-firewall-policy-upon-re-ordering-NAT-rules/m-p/196026#M36567</guid>
      <dc:creator>Muazzam</dc:creator>
      <dc:date>2023-10-24T12:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: No change in firewall policy upon re-ordering NAT rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-change-in-firewall-policy-upon-re-ordering-NAT-rules/m-p/196048#M36571</link>
      <description>&lt;P&gt;Are you sure that a new connection was established after the NAT policy was updated?&amp;nbsp; I had a NAT rule that seemed 'stuck' when I changed the NAT on a GRE connection.&amp;nbsp; Ended up having to 'fw tab -x' delete it from the fw connections table to get the connection to match the updated NAT rule.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 15:19:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-change-in-firewall-policy-upon-re-ordering-NAT-rules/m-p/196048#M36571</guid>
      <dc:creator>Lloyd_Braun</dc:creator>
      <dc:date>2023-10-24T15:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: No change in firewall policy upon re-ordering NAT rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-change-in-firewall-policy-upon-re-ordering-NAT-rules/m-p/196051#M36573</link>
      <description>&lt;P&gt;Yes, we have a new traffic that uses the old set of rules.&lt;/P&gt;&lt;P&gt;Also, on the first re-order of NAT rules (where we have no update to policy), we searched some of the NAT rules UID's and they were not found in the "rules.C" file. After the second change (disable and re-create) the rules.C file get updated and I see all the new UID's in the file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 15:44:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-change-in-firewall-policy-upon-re-ordering-NAT-rules/m-p/196051#M36573</guid>
      <dc:creator>Muazzam</dc:creator>
      <dc:date>2023-10-24T15:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: No change in firewall policy upon re-ordering NAT rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-change-in-firewall-policy-upon-re-ordering-NAT-rules/m-p/196052#M36574</link>
      <description>&lt;P&gt;Sounds like it might be worth a TAC case.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 15:53:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-change-in-firewall-policy-upon-re-ordering-NAT-rules/m-p/196052#M36574</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-24T15:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: No change in firewall policy upon re-ordering NAT rules.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-change-in-firewall-policy-upon-re-ordering-NAT-rules/m-p/196056#M36576</link>
      <description>&lt;P&gt;TAC case already opened and under investigation. I was wondering if anyone has the same experience.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 17:04:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-change-in-firewall-policy-upon-re-ordering-NAT-rules/m-p/196056#M36576</guid>
      <dc:creator>Muazzam</dc:creator>
      <dc:date>2023-10-24T17:04:17Z</dc:date>
    </item>
  </channel>
</rss>

