<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Network &amp;amp; Application policy in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-amp-Application-policy/m-p/197774#M36952</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;On the checkpoint how network policy and application work? Is the network policy will take precedence&amp;nbsp; than application policy?&lt;/P&gt;&lt;P&gt;On the network policy i have 2 rule (CP1 picture) :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rule number 17 INTERNET_DC_VLAN301 is to allowing some server under VLAN301 accessing to the internet&lt;/LI&gt;&lt;LI&gt;Rule number 18&amp;nbsp;DC_VLAN301 is to drop rest the server under VLAN301&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;On the application policy i have rule to allowing all servers (all hosts under DC_VLAN301) access to some specific application such as sophos-update.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;With both policy only hosts under group&amp;nbsp;INTERNET_DC_VLAN301 can access to sophos-update even on the source on the application policy set to DC_VLAN301 which contains all host under subnet 301 (10.103.248.0/24)&lt;/P&gt;&lt;P&gt;So i want to know how to make network policy and application policy can work together?&lt;/P&gt;</description>
    <pubDate>Mon, 13 Nov 2023 03:29:52 GMT</pubDate>
    <dc:creator>handiansudianto</dc:creator>
    <dc:date>2023-11-13T03:29:52Z</dc:date>
    <item>
      <title>Network &amp; Application policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-amp-Application-policy/m-p/197774#M36952</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;On the checkpoint how network policy and application work? Is the network policy will take precedence&amp;nbsp; than application policy?&lt;/P&gt;&lt;P&gt;On the network policy i have 2 rule (CP1 picture) :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Rule number 17 INTERNET_DC_VLAN301 is to allowing some server under VLAN301 accessing to the internet&lt;/LI&gt;&lt;LI&gt;Rule number 18&amp;nbsp;DC_VLAN301 is to drop rest the server under VLAN301&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;On the application policy i have rule to allowing all servers (all hosts under DC_VLAN301) access to some specific application such as sophos-update.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;With both policy only hosts under group&amp;nbsp;INTERNET_DC_VLAN301 can access to sophos-update even on the source on the application policy set to DC_VLAN301 which contains all host under subnet 301 (10.103.248.0/24)&lt;/P&gt;&lt;P&gt;So i want to know how to make network policy and application policy can work together?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 03:29:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-amp-Application-policy/m-p/197774#M36952</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2023-11-13T03:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Network &amp; Application policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-amp-Application-policy/m-p/197778#M36954</link>
      <description>&lt;P&gt;With ordered layers traffic must match (accept) in both layers to be allowed, please refer:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm" target="_blank" rel="noopener"&gt;Ordered Layers and Inline Layers (checkpoint.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 08:15:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-amp-Application-policy/m-p/197778#M36954</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-13T08:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Network &amp; Application policy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-amp-Application-policy/m-p/197854#M36975</link>
      <description>&lt;P&gt;You only need to maintain a separate Firewall and App Control policy if you manage any gateways running R77.x (or earlier) code.&lt;BR /&gt;Your best bet is to combine them, though that will require manual effort.&lt;/P&gt;
&lt;P&gt;In general, if you have multiple policy layers, traffic must match an Accept rule in each ordered layer.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 19:16:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-amp-Application-policy/m-p/197854#M36975</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-13T19:16:42Z</dc:date>
    </item>
  </channel>
</rss>

