<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VOIP question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245646#M47859</link>
    <description>&lt;P&gt;Not sure we have to try. Because the documentation is very specific about it.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Apr 2025 20:39:09 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2025-04-03T20:39:09Z</dc:date>
    <item>
      <title>VOIP question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245499#M47827</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Just wondering if someone can clarify this for me and if it is expected because maybe of service (sip) used?&lt;/P&gt;
&lt;P&gt;So, customer has setup as example 7-1 in below sk and all works fine, no issus, BUT, rather than bi-directional rule, they have 2 separate ones and randomly, logs that should show for rule 9, show for rule 10 and other way around.&lt;/P&gt;
&lt;P&gt;Is that expected? We even ran fw up_execute and shows right rule)s).&lt;/P&gt;
&lt;P&gt;Thoughts?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk95369" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk95369&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Tx as always!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 17:43:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245499#M47827</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-02T17:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: VOIP question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245501#M47829</link>
      <description>&lt;P&gt;I suspect that sometimes the traffic hits the VOIP handler (SIP service) and other times the other defined port. If you could share screenshot of the rules I can check it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 18:02:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245501#M47829</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-04-02T18:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: VOIP question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245502#M47830</link>
      <description>&lt;P&gt;Yep, will ask customer for it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 18:04:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245502#M47830</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-02T18:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: VOIP question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245503#M47831</link>
      <description>&lt;P&gt;Here it is.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 19:43:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245503#M47831</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-02T19:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: VOIP question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245546#M47848</link>
      <description>&lt;P&gt;Ah in this way. The my first comment is not relevant.&lt;/P&gt;
&lt;P&gt;Is it not because of this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Security rules can be defined that allow bidirectional calls, or only incoming or outgoing calls.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;So if traffic hits rule 9 it is an incomming call and rule 10 an outgoing call? Do you see something like this in the logs?&lt;/P&gt;
&lt;P&gt;I would not recommend to put it all in one rule. Because then you open traffic between the subnets.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What if you make new rules like below? Then it is still secure and you follow the recommended steps in the guide:&lt;/P&gt;
&lt;P&gt;Source:&lt;BR /&gt;HQ-Voice&lt;BR /&gt;BTC-Edgemark-HQ&lt;BR /&gt;Destination:&lt;BR /&gt;HQ-Voice&lt;BR /&gt;BTC-Edgemark-HQ&lt;/P&gt;
&lt;P&gt;sip-tcp&lt;BR /&gt;sip&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Source:&lt;BR /&gt;DR_VOICE-VLAN&lt;BR /&gt;BTC-Edgemark-HQ&lt;BR /&gt;Destination:&lt;BR /&gt;DR_VOICE-VLAN&lt;BR /&gt;BTC-Edgemark-HQ&lt;/P&gt;
&lt;P&gt;sip-tcp&lt;BR /&gt;sip&lt;/P&gt;
&lt;P&gt;etc&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 08:14:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245546#M47848</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-04-03T08:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: VOIP question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245552#M47851</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I definitely asked them to try, lets see. Do you think though doing it this way would be any different?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 10:40:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245552#M47851</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-03T10:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: VOIP question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245574#M47857</link>
      <description>&lt;P&gt;Btw, spoke with my colleague about this and we asked them to see if they can verify 2 things (well verify 1 and do the 2nd one if willing)&lt;/P&gt;
&lt;P&gt;1) Check if there is an updates smart console to install&lt;/P&gt;
&lt;P&gt;2) If they are willing to install latest jumbo 99 for mgmt ONLY, as I recall seeing people mention about display logs issue via smart console, just cant recall what take it was fixed it&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 12:14:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245574#M47857</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-03T12:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: VOIP question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245646#M47859</link>
      <description>&lt;P&gt;Not sure we have to try. Because the documentation is very specific about it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 20:39:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245646#M47859</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-04-03T20:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: VOIP question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245647#M47860</link>
      <description>&lt;P&gt;Can be done quick, would give this a try. Only log issue I have seen that the interface direction in a log entry was incorrect due bug. Have not seen the issue with rules. This was bug ID:&amp;nbsp;&lt;/P&gt;
&lt;TABLE id="filter1Table" class="TableStyle-TP_Table_Jumbo_Fixes" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Jumbo_Fixes-Body-Grey_Background"&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_ID-Grey_Background"&gt;
&lt;P&gt;PRJ-47984,&lt;BR /&gt;PRHF-29667&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_Product-Grey_Background"&gt;
&lt;P&gt;Logging&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyD-Column_Style_Description-Grey_Background"&gt;
&lt;P&gt;Some Access Rule Base logs may be generated with a wrong interface direction. The issue is cosmetic only.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What version / take you have active now? can give a quick look. Share please gw and mgmt&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 20:41:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245647#M47860</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-04-03T20:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: VOIP question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245654#M47863</link>
      <description>&lt;P&gt;Its on R81.20 just cant recall jumbo now, as we dont manage their equipment.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 21:43:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245654#M47863</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-03T21:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: VOIP question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245734#M47873</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Just to update on this, spoke with TAC on unrelated case and asked them this question and lady said it is purely cosmetic, but its fixed if jumbo 99 installed on the mgmt, which is what we suggested to the customer.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 23:47:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VOIP-question/m-p/245734#M47873</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-04T23:47:39Z</dc:date>
    </item>
  </channel>
</rss>

