<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall does not block traffic. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202330#M38074</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;By "Hub Mode" do you mean the following option?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="H1.png" style="width: 852px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23990i4275BAE41F4F2B03/image-size/large?v=v2&amp;amp;px=999" role="button" title="H1.png" alt="H1.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;What do you mean by this option "matched rules tab"?&lt;BR /&gt;&lt;BR /&gt;Could you tell me where you see that, please?&lt;BR /&gt;&lt;BR /&gt;Cheers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jan 2024 15:40:43 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2024-01-05T15:40:43Z</dc:date>
    <item>
      <title>Firewall does not block traffic.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202270#M38068</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a Cluster R81.10 which has only the following blades enabled&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;[Expert@SG:0]# enabled_blades&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;fw av ips anti_bot mon&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Client does not want to enable URLF+APPC blades.&lt;BR /&gt;Customer does not want to modify the Cluster object behaviour (&lt;STRONG&gt;Currently AntiBot &amp;amp; Anti-Virus are set to "Detect Only"&lt;/STRONG&gt;)&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="J4.png" style="width: 497px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23955iE3D1627F9B4F63D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="J4.png" alt="J4.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="J3.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23954iB1FC5B9F0DB534BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="J3.png" alt="J3.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="J2.png" style="width: 830px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23956iC28E47F6C8A4E81F/image-size/large?v=v2&amp;amp;px=999" role="button" title="J2.png" alt="J2.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="J5.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23958iA3591D1678B7194E/image-size/large?v=v2&amp;amp;px=999" role="button" title="J5.png" alt="J5.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The only viable option I see to block LAN traffic to the cilkonlay.com domain is to use a per FQDN rule.&lt;BR /&gt;The rule has been created, but the GW does not "obey" the rule.&lt;/P&gt;
&lt;P&gt;Traffic is still allowed. It is relevant to mention that we are now testing access to the URL from remote user connections (RA VPN).&lt;/P&gt;
&lt;P&gt;Does anyone know why traffic is not blocked with the custom FQDN rule?&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 23:55:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202270#M38068</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-04T23:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall does not block traffic.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202271#M38069</link>
      <description>&lt;P&gt;Can you send screenshot of the rule?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 02:48:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202271#M38069</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-05T02:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall does not block traffic.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202276#M38070</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;This is the TP rule you have defined.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="J6.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23959iBB8C76D33F3BCDE2/image-size/large?v=v2&amp;amp;px=999" role="button" title="J6.png" alt="J6.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;And this is the rule we have created in the Firewall layer, so that it works with FQDN.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="J3.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23960iF74C18A316BF98C4/image-size/large?v=v2&amp;amp;px=999" role="button" title="J3.png" alt="J3.png" /&gt;&lt;/span&gt;&lt;BR /&gt;We are trying to block traffic to the domain "&lt;STRONG&gt;cilkonlay.com&lt;/STRONG&gt;", but the Firewall is ignoring our Firewall rule using FQDN&lt;BR /&gt;&lt;BR /&gt;We are testing with a simple PING from our remote VPN user connections, but we are unable to block traffic to that destination.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="J7.png" style="width: 837px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23962i4903EE246630E2D4/image-size/large?v=v2&amp;amp;px=999" role="button" title="J7.png" alt="J7.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 03:58:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202276#M38070</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-05T03:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall does not block traffic.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202277#M38071</link>
      <description>&lt;P&gt;Bro, we been through this many times lol. You need to check according to policy setting in gateway object for TP policy to be applied. Also, security rule has to have fqdn object as a destination.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 04:09:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202277#M38071</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-05T04:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall does not block traffic.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202278#M38072</link>
      <description>&lt;P&gt;What do you see on the matched rules tab?&lt;/P&gt;
&lt;P&gt;Is the RA VPN configured for hub mode&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 04:53:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202278#M38072</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-01-05T04:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall does not block traffic.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202330#M38074</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;By "Hub Mode" do you mean the following option?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="H1.png" style="width: 852px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23990i4275BAE41F4F2B03/image-size/large?v=v2&amp;amp;px=999" role="button" title="H1.png" alt="H1.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;What do you mean by this option "matched rules tab"?&lt;BR /&gt;&lt;BR /&gt;Could you tell me where you see that, please?&lt;BR /&gt;&lt;BR /&gt;Cheers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 15:40:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202330#M38074</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2024-01-05T15:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall does not block traffic.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202331#M38075</link>
      <description>&lt;P&gt;I think Chris was referring to log entry, which would have matched rules tab.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 15:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202331#M38075</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-05T15:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall does not block traffic.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202376#M38083</link>
      <description>&lt;P&gt;Unless "Route All Traffic to Gateway" (i.e. Hub Mode) is enabled, you cannot prevent a Remote Access client from connecting to an externally hosted site.&lt;BR /&gt;This is the kind of thing Harmony Endpoint or Quantum SASE should be able to do.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2024 20:58:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202376#M38083</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-05T20:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall does not block traffic.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202387#M38088</link>
      <description>&lt;P&gt;Correct, since technically all we see is the DNS traffic in the logs above and without hub mode forcing internet traffic via the VPN the Firewall will not be able to block other traffic unless it is in the encryption domain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jan 2024 00:08:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202387#M38088</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-01-06T00:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall does not block traffic.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202415#M38095</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;said, if that option route all gtraffic to gateway is not enabled, then its not really feasable to prevent client to get to external site, since they would technically be using their own ISP for that sort of traffic.&lt;/P&gt;
&lt;P&gt;Makes sense?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 00:44:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-does-not-block-traffic/m-p/202415#M38095</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-08T00:44:06Z</dc:date>
    </item>
  </channel>
</rss>

