<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Still drop in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200404#M37605</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have created a rule to allow all IPads to reach to &lt;STRONG&gt;.apple.com&lt;/STRONG&gt; domain. The problem is that not all IPads are reaching to that domain, but some still drop, this is my rule:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ipad to apple.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23637iF76D52A0560C7820/image-size/large?v=v2&amp;amp;px=999" role="button" title="ipad to apple.JPG" alt="ipad to apple.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Source: Ipad network&lt;/P&gt;&lt;P&gt;destination: .apple.com domain&lt;/P&gt;&lt;P&gt;services and application: any&lt;/P&gt;&lt;P&gt;Action:accept&lt;/P&gt;&lt;P&gt;Track:log&lt;/P&gt;&lt;P&gt;The IPad network is 10.10.32.0/19. After adding that rule some IPads are accepted to reach .apple.com:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="accept to 17.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23638i8DDCF9E2F16FF702/image-size/large?v=v2&amp;amp;px=999" role="button" title="accept to 17.JPG" alt="accept to 17.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;And some still drop:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drop to 17..JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23639iC87F7818AFC12228/image-size/large?v=v2&amp;amp;px=999" role="button" title="drop to 17..JPG" alt="drop to 17..JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So why some are still dropping? They are reaching to the Cleanup rule 59.12, where 59.3 is to accept all connections to Apple?!&lt;/P&gt;&lt;P&gt;59 is an Inline layer where IPad network is in the source of it.&lt;/P&gt;&lt;P&gt;What do I miss here?!&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2023 07:31:16 GMT</pubDate>
    <dc:creator>Moudar</dc:creator>
    <dc:date>2023-12-13T07:31:16Z</dc:date>
    <item>
      <title>Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200404#M37605</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have created a rule to allow all IPads to reach to &lt;STRONG&gt;.apple.com&lt;/STRONG&gt; domain. The problem is that not all IPads are reaching to that domain, but some still drop, this is my rule:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ipad to apple.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23637iF76D52A0560C7820/image-size/large?v=v2&amp;amp;px=999" role="button" title="ipad to apple.JPG" alt="ipad to apple.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Source: Ipad network&lt;/P&gt;&lt;P&gt;destination: .apple.com domain&lt;/P&gt;&lt;P&gt;services and application: any&lt;/P&gt;&lt;P&gt;Action:accept&lt;/P&gt;&lt;P&gt;Track:log&lt;/P&gt;&lt;P&gt;The IPad network is 10.10.32.0/19. After adding that rule some IPads are accepted to reach .apple.com:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="accept to 17.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23638i8DDCF9E2F16FF702/image-size/large?v=v2&amp;amp;px=999" role="button" title="accept to 17.JPG" alt="accept to 17.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;And some still drop:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drop to 17..JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23639iC87F7818AFC12228/image-size/large?v=v2&amp;amp;px=999" role="button" title="drop to 17..JPG" alt="drop to 17..JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So why some are still dropping? They are reaching to the Cleanup rule 59.12, where 59.3 is to accept all connections to Apple?!&lt;/P&gt;&lt;P&gt;59 is an Inline layer where IPad network is in the source of it.&lt;/P&gt;&lt;P&gt;What do I miss here?!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 07:31:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200404#M37605</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-12-13T07:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200410#M37606</link>
      <description>&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Apple-and-HTTPS-Inspection/m-p/176039" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Apple-and-HTTPS-Inspection/m-p/176039&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 09:48:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200410#M37606</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-12-13T09:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200449#M37622</link>
      <description>&lt;P&gt;What&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;is your best process to follow...now, IF you dont use urlf blade, then domain objects is fine, but make sure it says .*.apple.com and fqdn option is unchecked, otherwise, it may not match all needed sub-domains.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 11:49:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200449#M37622</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-13T11:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200455#M37625</link>
      <description>&lt;P&gt;When trying to make it *.apple.com i get this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apple.JPG" style="width: 475px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23646i19C98B9293E99B10/image-size/large?v=v2&amp;amp;px=999" role="button" title="apple.JPG" alt="apple.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now my domain object looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apple1.JPG" style="width: 374px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23647iCE7B72CA0E389C18/image-size/large?v=v2&amp;amp;px=999" role="button" title="apple1.JPG" alt="apple1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 12:06:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200455#M37625</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-12-13T12:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200456#M37626</link>
      <description>&lt;P&gt;What if URL and application blades are active, is there any better way to do that ?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 12:08:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200456#M37626</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-12-13T12:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200458#M37628</link>
      <description>&lt;P&gt;Maybe you missed . in my post : -)&lt;/P&gt;
&lt;P&gt;I mentioned .*.apple.com, but you can also do .*apple.com&lt;/P&gt;
&lt;P&gt;Every domain object MUST start with .&lt;/P&gt;
&lt;P&gt;Hope that helps&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;Please refer to below link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk120633" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk120633&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 12:09:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200458#M37628</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-13T12:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200459#M37629</link>
      <description>&lt;P&gt;Yes, if those are enabled, please follow what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;suggested.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 12:10:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200459#M37629</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-13T12:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200465#M37632</link>
      <description>&lt;P&gt;Now it looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apple.JPG" style="width: 375px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23648iA0523A45AE9F41E4/image-size/large?v=v2&amp;amp;px=999" role="button" title="apple.JPG" alt="apple.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But still have drops!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apple1.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23649iDE3211A405D6AB80/image-size/large?v=v2&amp;amp;px=999" role="button" title="apple1.JPG" alt="apple1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I don't really understand what&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294" target="_blank"&gt;@G_W_Albrecht&lt;/A&gt;&amp;nbsp;suggestion is?!&lt;/P&gt;&lt;P&gt;How should I use app and url blades to achieve the same?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 12:24:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200465#M37632</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-12-13T12:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200467#M37633</link>
      <description>&lt;P&gt;Just allow 17.0.0.0/8 subnet, that will fix it, as thats what Apple uses.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://news.ycombinator.com/item?id=3341349" target="_blank"&gt;https://news.ycombinator.com/item?id=3341349&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Otherwise, make sure urlf and appc blades are enabled and follow what Guenther suggested, screenshots are there, its pretty straight forward...you need to use built in applications in smart console, just type apple when adding it in the rule and bunch of stuff will pop up.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 12:29:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200467#M37633</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-13T12:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200469#M37635</link>
      <description>&lt;P&gt;Also, as per below&lt;/P&gt;
&lt;P&gt;&lt;A href="https://developer.apple.com/forums/thread/44549" target="_blank"&gt;https://developer.apple.com/forums/thread/44549&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 12:31:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200469#M37635</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-13T12:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200476#M37636</link>
      <description>&lt;P&gt;It works fine now with 17.0.0.0/8&amp;nbsp;&lt;/P&gt;&lt;P&gt;URL and application, do you mean enable all these?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="apple.JPG" style="width: 289px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23650iE53DE592BF855E7E/image-size/large?v=v2&amp;amp;px=999" role="button" title="apple.JPG" alt="apple.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 12:55:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200476#M37636</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-12-13T12:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200477#M37637</link>
      <description>&lt;P&gt;Could well be that only using 17.0.0.0/8 works for you, i would try before doing any other configuration !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 13:07:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200477#M37637</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-12-13T13:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Still drop</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200478#M37638</link>
      <description>&lt;P&gt;Not really, if that range works, then its good. I would leave it as is then.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 13:11:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Still-drop/m-p/200478#M37638</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-13T13:11:22Z</dc:date>
    </item>
  </channel>
</rss>

