<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Implied rules in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228234#M43897</link>
    <description>&lt;P&gt;Big thanks to everyone! You all are so nice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am just curious. My portal is configured as "Through internal interface" , mobile access is listening on other external interface&lt;/P&gt;&lt;P&gt;No idea why this external interface is still answering http/https&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I could try adding a rule on top to block http/https access to this interface from internet, but just curious why...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand will handle weak ciphe&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bill.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Sep 2024 14:23:55 GMT</pubDate>
    <dc:creator>imservbilllee</dc:creator>
    <dc:date>2024-09-27T14:23:55Z</dc:date>
    <item>
      <title>Implied rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228212#M43893</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am very new to CheckPoint firewall. A recent security scanning flagged one of my External interface saying Weak Cipher.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am surprised why such interface is responding http/https to internet. When I check in the logs it showed "Implied rule" was hit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I have no idea on which implied rule make this happen and so how to mitigate this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please could you shed some light thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running an Open server on Gaia R81.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bill.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 13:00:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228212#M43893</guid>
      <dc:creator>imservbilllee</dc:creator>
      <dc:date>2024-09-27T13:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228220#M43894</link>
      <description>&lt;P&gt;There can be many reasons for your GW to answer on HTTPS on en external interface: multi-portal, Mobile Access Blade, RAS VPN with a Visitor Mode activated, even Gaia WebUI, if you allow connections to all interfaces.&lt;BR /&gt;&lt;BR /&gt;To manage ciphers, look into&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk126613" target="_self"&gt;&lt;SPAN&gt;sk126613&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 13:30:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228220#M43894</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-09-27T13:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228222#M43895</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/117653"&gt;@imservbilllee&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Welcome on board, you have chosen the best manufacturer:-)&lt;/P&gt;
&lt;P&gt;What are you looking for is the #cipher_util tool.&lt;/P&gt;
&lt;P&gt;Here is the complete guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk126613" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk126613&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you have question just drop an update.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 13:33:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228222#M43895</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-27T13:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228224#M43896</link>
      <description>&lt;P&gt;Hey Bill,&lt;/P&gt;
&lt;P&gt;No worries man, we are here to help. Apart from what the boys said, which is true, I also recommend looking at below, might be relevant. Personally, I would NOT recommend playing around with implied_rules.DEF file on the mgmt server, as its there for a reason with default settings, unless TAC ever asked you to modify it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105740" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105740&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If it helps, I also made post about something similar for geo VPN block, not sure if it may help you, but its the link below.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/Geo-VPN-blocking/m-p/214040#M10593" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/Geo-VPN-blocking/m-p/214040#M10593&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 13:43:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228224#M43896</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-27T13:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228234#M43897</link>
      <description>&lt;P&gt;Big thanks to everyone! You all are so nice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am just curious. My portal is configured as "Through internal interface" , mobile access is listening on other external interface&lt;/P&gt;&lt;P&gt;No idea why this external interface is still answering http/https&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I could try adding a rule on top to block http/https access to this interface from internet, but just curious why...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand will handle weak ciphe&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bill.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 14:23:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228234#M43897</guid>
      <dc:creator>imservbilllee</dc:creator>
      <dc:date>2024-09-27T14:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228256#M43901</link>
      <description>&lt;P&gt;For the relevant discussion on implied rules for http/https to the gateway, see:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk105740" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105740&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 16:13:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228256#M43901</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-27T16:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228319#M43912</link>
      <description>&lt;P&gt;If its listening on external interface, 100% implied rule, so you can definitely add rule to block it. Check the post I referenced, sk explains it as well.&lt;/P&gt;
&lt;P&gt;Glad we can help you, thats what we are here for &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 23:10:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Implied-rules/m-p/228319#M43912</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-27T23:10:03Z</dc:date>
    </item>
  </channel>
</rss>

