<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic Tagged in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245770#M47883</link>
    <description>&lt;P&gt;Hi, Mates.&lt;/P&gt;
&lt;P&gt;Do Check Point devices support MPLS labeled traffic?&lt;/P&gt;
&lt;P&gt;I have a need to be able to perform filtering on some network segments, but the detail is that these segments are labeled as they are part of an L3 VPN MPLS environment.&lt;/P&gt;
&lt;P&gt;Our box is in an MPLS network, specifically in the middle of 2 Routers part of an MPLS network (1 P, and 1PE), and the traffic that is intended to be filtered for example segments like 110.130.x.x/24, are segments that are labeled in the network.&lt;/P&gt;
&lt;P&gt;Our box is in the middle of the Routers working as if it were a SW (Mode Bridge), with the objective of performing access control to applications and websites.&lt;/P&gt;
&lt;P&gt;Is it possible for CP to control MPLS labeled traffic?&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
    <pubDate>Sat, 05 Apr 2025 23:45:33 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2025-04-05T23:45:33Z</dc:date>
    <item>
      <title>Traffic Tagged</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245770#M47883</link>
      <description>&lt;P&gt;Hi, Mates.&lt;/P&gt;
&lt;P&gt;Do Check Point devices support MPLS labeled traffic?&lt;/P&gt;
&lt;P&gt;I have a need to be able to perform filtering on some network segments, but the detail is that these segments are labeled as they are part of an L3 VPN MPLS environment.&lt;/P&gt;
&lt;P&gt;Our box is in an MPLS network, specifically in the middle of 2 Routers part of an MPLS network (1 P, and 1PE), and the traffic that is intended to be filtered for example segments like 110.130.x.x/24, are segments that are labeled in the network.&lt;/P&gt;
&lt;P&gt;Our box is in the middle of the Routers working as if it were a SW (Mode Bridge), with the objective of performing access control to applications and websites.&lt;/P&gt;
&lt;P&gt;Is it possible for CP to control MPLS labeled traffic?&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2025 23:45:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245770#M47883</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-04-05T23:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Tagged</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245771#M47884</link>
      <description>&lt;P&gt;Check Point does not support MPLS tagged traffic.&lt;/P&gt;
&lt;P&gt;You'd need to break out the traffic for inspection.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Apr 2025 00:23:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245771#M47884</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-04-06T00:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Tagged</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245772#M47885</link>
      <description>&lt;P&gt;Is there any official documentation that talks about this?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Apr 2025 00:29:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245772#M47885</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-04-06T00:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Tagged</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245773#M47886</link>
      <description>&lt;P&gt;MPLS is not listed on the datasheet if that's what you are asking.&lt;/P&gt;
&lt;P&gt;Otherwise its a case of needing the traffic to arrive to and traverse the Firewall in a manner / format we can inspect.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Apr 2025 01:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245773#M47886</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-04-06T01:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Tagged</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245777#M47887</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;I could not find any official doc about it, but below is what AI Copilot gave me.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;DIV class="ai-chatbot-conversation-assistant-text css-1m564fq"&gt;
&lt;P&gt;Yes, Check Point supports MPLS tagged traffic. In some network topologies, a clear-text MPLS link (encryption is not required) is deployed in addition to an encrypted Internet link between Check Point VPN Gateways. Customers can configure certain services to be routed through the MPLS link in clear-text, while other services are forwarded encrypted through the Internet link.&lt;/P&gt;
&lt;P&gt;For more detailed information, you can refer to the article on how to create a redundant, service-based MPLS/Encrypted Link VPN&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk56384" target="_blank"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="ai-chatbot-references css-g9n3fs"&gt;
&lt;DIV class="css-131f8vm"&gt;Learn more:&lt;/DIV&gt;
&lt;DIV class="css-zs1iv6"&gt;
&lt;OL class="css-3yupri"&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk56384" target="_blank" rel="noopener"&gt;sk56384 - How To Create a Redundant, Service-based MPLS/Encrypted Link VPN&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk160512" target="_blank" rel="noopener"&gt;sk160512 - Is mLACP protocol supported with Check Point products?&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk119314" target="_blank" rel="noopener"&gt;sk119314 - Long-Term Evolution (LTE) - FAQ&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk106741" target="_blank" rel="noopener"&gt;sk106741 - Traffic with multiple VLAN tags on a packet does not pass through Check Point Security Gateway&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk42943" target="_blank" rel="noopener"&gt;sk42943 - Check Point support for Data Link Switching (DLSw) protocol&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk110096" target="_blank" rel="noopener"&gt;sk110096 - "Invalid number: 1. Not in range 2..4094" error when configuring VLAN in Gaia Clish&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk41961" target="_blank" rel="noopener"&gt;sk41961 - Does Check Point Anti-Spam and Email Security quarantine messages?&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk167215" target="_blank" rel="noopener"&gt;sk167215 - What does Check Point PRO suppo&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sun, 06 Apr 2025 13:42:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245777#M47887</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-06T13:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Tagged</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245788#M47889</link>
      <description>&lt;P&gt;This is not correct in the stated context.&lt;/P&gt;
&lt;P&gt;MPLS as a telco would operate over their backbone is different than the end carriage service consumers might commonly refer to as MPLS.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Apr 2025 22:01:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245788#M47889</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-04-06T22:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic Tagged</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245789#M47890</link>
      <description>&lt;P&gt;Thats fair Chris!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 06 Apr 2025 22:16:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-Tagged/m-p/245789#M47890</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-06T22:16:42Z</dc:date>
    </item>
  </channel>
</rss>

