<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not defined interface topology in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263140#M51634</link>
    <description>&lt;P&gt;To me, suppose no real use, honestly.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Nov 2025 15:22:39 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-11-18T15:22:39Z</dc:date>
    <item>
      <title>Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263119#M51625</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under any interface topology settings we have the option This network (internal), IP addresses behind this interface: Not defined.&lt;/P&gt;
&lt;P&gt;According to the admin guide:&lt;/P&gt;
&lt;P&gt;"&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class="Menu_Options"&gt;Not Defined&lt;/SPAN&gt;&amp;nbsp;- All IP addresses behind this&amp;nbsp;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;interface&lt;/SPAN&gt;&amp;nbsp;are considered a part of the internal network that connects to this&amp;nbsp;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;interface&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;"&lt;/P&gt;
&lt;P&gt;But if i choose that and try to install the policy i get:&lt;/P&gt;
&lt;DIV id="tinyMceEditorMoudar_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="not-defined.png" style="width: 363px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32145iB6CB9B0CCC94FB37/image-size/large?v=v2&amp;amp;px=999" role="button" title="not-defined.png" alt="not-defined.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do i miss here?&lt;/P&gt;
&lt;P&gt;In what case should you use that (no defined) option in production networks?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 13:31:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263119#M51625</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-11-18T13:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263120#M51626</link>
      <description>&lt;P&gt;Can you send a screenshot of how its defined?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 13:46:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263120#M51626</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-18T13:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263122#M51627</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.JPG" style="width: 652px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32146iF58485737B7EF5F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.JPG" alt="kort.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 13:59:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263122#M51627</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-11-18T13:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263123#M51628</link>
      <description>&lt;P&gt;Just tried in the lab, no matter what options I test with non defined, it always fails. I assume must be expected behavior, but not 100% sure.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 14:14:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263123#M51628</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-18T14:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263135#M51630</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;I just worked with TAC on another endpoint issue and mentioned this to the lady I spoke with and she checked with her colleague and indeed confirmed this is expected behavior and they will request documentation be updated, as it does give an impression it should work, but since it expects some some sort of correct topology defined, wording "not defined" would implicate for that not to happen, though it states it would be everything behind that interface.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 15:15:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263135#M51630</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-18T15:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263136#M51631</link>
      <description>&lt;P&gt;That answer will suffice for now, as I mainly wanted to understand why it behaves that way (failing to install the policy).&lt;BR data-start="172" data-end="175" /&gt;The documentation should be updated as well, because it’s the foundation of our knowledge, my friend.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 15:18:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263136#M51631</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-11-18T15:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263138#M51632</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ExcitedSoGIF.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32147i09CFC6C8D2248EC4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ExcitedSoGIF.gif" alt="ExcitedSoGIF.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 15:20:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263138#M51632</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-18T15:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263139#M51633</link>
      <description>&lt;P&gt;and that leave me wonder what is the usage of "not defined", i mean what use case in production or in lab?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 15:21:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263139#M51633</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-11-18T15:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263140#M51634</link>
      <description>&lt;P&gt;To me, suppose no real use, honestly.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 15:22:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263140#M51634</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-18T15:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263164#M51646</link>
      <description>&lt;P&gt;I think there just needs to be a default setting, and picking one of the other options could compromise security as it wouldn't be a default deny configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 01:24:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263164#M51646</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-11-19T01:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263165#M51647</link>
      <description>&lt;P&gt;Makes total sense to me , Emma. It would be cool if there was a pop up if customers picked the less secure option warning them about it. Maybe too much to ask for, but just an idea.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 01:31:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263165#M51647</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-19T01:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263179#M51657</link>
      <description>&lt;P&gt;The other options aren't necessarily less secure, there's not really anything that needs popping up so much as it just needs configuring properly. If anti-spoofing is disabled then it's less secure, and in that case a warning is added to the policy install outcome.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 04:35:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263179#M51657</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-11-19T04:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Not defined interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263180#M51658</link>
      <description>&lt;P&gt;Personally, and I also advise customers to do the same, I find defined by routes the best option, because if topology does change, no need to update anything manually for given interface.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 04:39:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-defined-interface-topology/m-p/263180#M51658</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-19T04:39:29Z</dc:date>
    </item>
  </channel>
</rss>

