<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forcing Comments in Rulebase in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205180#M66006</link>
    <description>&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/SmartTasks/bd-p/SmartTasks" target="_self"&gt;SmartTasks&lt;/A&gt; in our Toolbox.&lt;BR /&gt;You can easily go from there and adjust those to your needs.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Feb 2024 14:18:29 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2024-02-06T14:18:29Z</dc:date>
    <item>
      <title>Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205127#M66002</link>
      <description>&lt;P&gt;Hi Guys.&lt;/P&gt;&lt;P&gt;For auditing reasons my company needs a comment for every rule in the rule base.&lt;/P&gt;&lt;P&gt;The issue is a lot of staff don't put them in, meaning I have to add them before an audit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any option I can enable to enforce the comment field before a rule can be added?&lt;/P&gt;&lt;P&gt;If not, could we look into getting this feature added to future versions?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 09:01:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205127#M66002</guid>
      <dc:creator>Marc0523</dc:creator>
      <dc:date>2024-02-06T09:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205128#M66003</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Maybe you can achieve it using Smart Tasks in SmartConsole.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/SmartTasks.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/SmartTasks.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 09:12:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205128#M66003</guid>
      <dc:creator>delToro1</dc:creator>
      <dc:date>2024-02-06T09:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205133#M66004</link>
      <description>&lt;P&gt;Never knew this existed!&lt;BR /&gt;&lt;BR /&gt;Smart Tasks could trigger a script to check, but I'd still need the script. Writing one which checked for comments in all rule bases is beyond me.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 10:07:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205133#M66004</guid>
      <dc:creator>Marc0523</dc:creator>
      <dc:date>2024-02-06T10:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205158#M66005</link>
      <description>&lt;P&gt;To confirm you are already using the Compliance Blade?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="compliance comment.jpg" style="width: 698px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24381iF7AA28E25621DE7B/image-size/large?v=v2&amp;amp;px=999" role="button" title="compliance comment.jpg" alt="compliance comment.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 12:50:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205158#M66005</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-02-06T12:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205180#M66006</link>
      <description>&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/SmartTasks/bd-p/SmartTasks" target="_self"&gt;SmartTasks&lt;/A&gt; in our Toolbox.&lt;BR /&gt;You can easily go from there and adjust those to your needs.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 14:18:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205180#M66006</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2024-02-06T14:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205183#M66007</link>
      <description>&lt;P&gt;Let me test this in my lab, I believe it can be achieved with compliance blade as Chris indicated.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 15:01:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205183#M66007</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-06T15:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205204#M66008</link>
      <description>&lt;P&gt;K, got it, here is what you need to do. I attached all the screenshots to this reply.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 18:45:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205204#M66008</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-06T18:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205225#M66009</link>
      <description>&lt;P&gt;You would actually check the rules modified by the current session to see if they have a comment or not.&lt;BR /&gt;However, if you're looking for an out-of-the-box feature, then you should use Compliance Blade which has this built in.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 19:41:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205225#M66009</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-06T19:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205321#M66010</link>
      <description>&lt;P&gt;Sadly no, we don’t have the compliance blade.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 13:56:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205321#M66010</guid>
      <dc:creator>Marc0523</dc:creator>
      <dc:date>2024-02-07T13:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205322#M66011</link>
      <description>&lt;P&gt;This looks perfect, but involves the compliance blade.&amp;nbsp;&lt;BR /&gt;I’ll have to see if we are allowed to purchase it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 13:57:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205322#M66011</guid>
      <dc:creator>Marc0523</dc:creator>
      <dc:date>2024-02-07T13:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205323#M66012</link>
      <description>&lt;P&gt;You can apply eval and test it for 30 days.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 13:57:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205323#M66012</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-07T13:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205349#M66013</link>
      <description>&lt;P&gt;Im sure if you approached your local Sales person, they would be willing to help you out with this. Compliance blade is really good, I strongly recommend it.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 15:16:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205349#M66013</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-07T15:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205356#M66014</link>
      <description>&lt;P&gt;Hi Andy, does this work for all policy types?&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Access Control&lt;/LI&gt;
&lt;LI&gt;NAT&lt;/LI&gt;
&lt;LI&gt;Threat Prevention&lt;/LI&gt;
&lt;LI&gt;HTTPS Inspection&lt;/LI&gt;
&lt;LI&gt;Mobile Access&lt;/LI&gt;
&lt;LI&gt;DLP&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;etc.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 15:50:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205356#M66014</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2024-02-07T15:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205358#M66015</link>
      <description>&lt;P&gt;Hey Danny,&lt;/P&gt;
&lt;P&gt;I tested it yesterday and worked for any rule type, correct.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 15:53:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/205358#M66015</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-07T15:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/208833#M66016</link>
      <description>&lt;P&gt;I don't like this.&amp;nbsp; Every auditor checks for this and you get dinged without it.&amp;nbsp; This is such a simple thing to do and every other FW vendor allows this.&amp;nbsp; The compliance work around is not an answer its a band aid.&amp;nbsp; How hard is it to get an RFE for this considering its a standard requirement, best practice and basic good hygiene?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 02:19:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/208833#M66016</guid>
      <dc:creator>Paul_Warnagiris</dc:creator>
      <dc:date>2024-03-15T02:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/208905#M66017</link>
      <description>&lt;P&gt;You are correct in saying other fw vendors allow it, BUT, there is a hack to get around it, an easy one too, mind you : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 22:12:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/208905#M66017</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-15T22:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/208913#M66018</link>
      <description>&lt;P&gt;RFE process is well known, please discuss with your local SE.&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;SPAN&gt;With R81.20 the SmartWorkflow / Approval Cycle could also help if you have challenges with change management policy conformance, please refer:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Session-flow-for-Administrators.htm?cshid=ID103#ApprovalCycle" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Session-flow-for-Administrators.htm?cshid=ID103#ApprovalCycle&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;SPAN&gt;Further more, you can enforce session descriptions should you so choose.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;SPAN&gt;Navigate to Advance Session settings and check the "All Session must have a name and description" check box.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;SPAN&gt;See also:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/SmartTasks/Session-description-check/td-p/177546" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/SmartTasks/Session-description-check/td-p/177546&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 15:02:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/208913#M66018</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-03-16T15:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing Comments in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/208917#M66019</link>
      <description>&lt;P&gt;Will do.&amp;nbsp; Because something that should be a simple click box is turned into a whole new workflow doesn't make sense and its not a good answer.&amp;nbsp; I could live with the session enforcement mechanism if it could enforce rule comments.&amp;nbsp; That would be an acceptable work around.&amp;nbsp; But to create a 7 step work flow and require multiple people to do something that a click box could accomplish is silly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 16:55:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forcing-Comments-in-Rulebase/m-p/208917#M66019</guid>
      <dc:creator>Paul_Warnagiris</dc:creator>
      <dc:date>2024-03-16T16:55:33Z</dc:date>
    </item>
  </channel>
</rss>

