<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Smartview in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221415#M42393</link>
    <description>&lt;P&gt;Hi all!&lt;BR /&gt;Please help me solve the problem. I can log into the Smartview Console using my external IP address from anywhere. At the same time, I don’t have a single rule on the gateway that allows this action. I would not like access to Smartview of my gateway to be opened from the Internet. I want this to be possible only from the local network.&lt;BR /&gt;How can I block access to Smartview via a public address?&lt;BR /&gt;I will be grateful for your help&lt;BR /&gt;&lt;BR /&gt;OS Gaia&lt;BR /&gt;Version R81.20&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jul 2024 14:56:14 GMT</pubDate>
    <dc:creator>Dmitriy_K</dc:creator>
    <dc:date>2024-07-19T14:56:14Z</dc:date>
    <item>
      <title>Smartview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221415#M42393</link>
      <description>&lt;P&gt;Hi all!&lt;BR /&gt;Please help me solve the problem. I can log into the Smartview Console using my external IP address from anywhere. At the same time, I don’t have a single rule on the gateway that allows this action. I would not like access to Smartview of my gateway to be opened from the Internet. I want this to be possible only from the local network.&lt;BR /&gt;How can I block access to Smartview via a public address?&lt;BR /&gt;I will be grateful for your help&lt;BR /&gt;&lt;BR /&gt;OS Gaia&lt;BR /&gt;Version R81.20&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 14:56:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221415#M42393</guid>
      <dc:creator>Dmitriy_K</dc:creator>
      <dc:date>2024-07-19T14:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Smartview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221435#M42404</link>
      <description>&lt;P&gt;The only way this would be possible is if you have a Standalone gateway (i.e. no external management).&lt;BR /&gt;This traffic is being accepted on implied rules.&lt;BR /&gt;This can be fixed with:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk105740" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105740&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 20:12:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221435#M42404</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-19T20:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: Smartview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221438#M42405</link>
      <description>&lt;P&gt;As extra you can make ACL here for SmartConsole access:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/GUI-Clients.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/GUI-Clients.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The IP's you put here, only those IP's are allowed to use SmartConsole.&lt;/P&gt;
&lt;P&gt;Extra, you can do the same for portal access and SSH:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/Host-Access.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/Host-Access.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This called host access. It look's similar as GUI client ACL but it is different.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 20:50:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221438#M42405</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-19T20:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: Smartview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221451#M42412</link>
      <description>&lt;P&gt;That should be simple to solve...just create a rule that allows ONLY access from trusted IPs/locations/networks and then right below that rule that blocks access to the IP listening for smartview log in page.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jul 2024 02:35:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221451#M42412</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-20T02:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Smartview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221452#M42413</link>
      <description>&lt;P&gt;Also, forgot to mention, easiest way to block any subnet/IP via smart console is SAM rule through SV monitor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_LoggingAndMonitoring_AdminGuide/Topics-LMG/Monitoring-Suspicious-Activity-Rules.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_LoggingAndMonitoring_AdminGuide/Topics-LMG/Monitoring-Suspicious-Activity-Rules.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jul 2024 02:42:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221452#M42413</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-20T02:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Smartview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221516#M42421</link>
      <description>&lt;P&gt;Thanks a lot for your hint. Yes, I have a Standalone gateway. The decision was right&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 05:45:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221516#M42421</guid>
      <dc:creator>Dmitriy_K</dc:creator>
      <dc:date>2024-07-22T05:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Smartview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221518#M42422</link>
      <description>&lt;P&gt;Your tips helped me. Thank you for sharing your knowledge&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 05:46:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartview/m-p/221518#M42422</guid>
      <dc:creator>Dmitriy_K</dc:creator>
      <dc:date>2024-07-22T05:46:51Z</dc:date>
    </item>
  </channel>
</rss>

