<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ordered Layers - Logging shows wrong Access Rule/Layer in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/188773#M67723</link>
    <description>&lt;P&gt;It says "cleanup rule", and I assume, it is a clean-up rule of your sublayer. How does that sublayer look?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Aug 2023 11:38:51 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-08-07T11:38:51Z</dc:date>
    <item>
      <title>Ordered Layers - Logging shows wrong Access Rule/Layer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/188772#M67722</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;while testing ordered layers for a customer, i ran over a behaviour i cannot explain to myself - perhaps someone else can (?):&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;at top layer:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Accept communication "any to any with any service" but "tracking: none"&lt;/P&gt;&lt;P&gt;(cleanup rule of a small policy to block traffic from/to defined ips)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;subordinated layer:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;communication is allowed with tracking enabled (log)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my understanding is now, that in logs i get rulename and number of the access rule hit at the subordinated layer.. instead i get the cleanup allow rule of the top layer with tracking set to "none"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-08-07_12-59-14.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21986i7BAB34C1DF1DF157/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-08-07_12-59-14.png" alt="2023-08-07_12-59-14.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Looking into SmartTracker no informations regarding the matched rule is being given&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-08-07_13-31-33.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21987i122D5B78BF955A71/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-08-07_13-31-33.png" alt="2023-08-07_13-31-33.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Setup:&lt;/P&gt;&lt;P&gt;Virtual Management Server, virtual Check Point Gateway (GAiA) and physical smb device. all updated to las recent versions. behaviour can be seen with logs of both gateways&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Someone has an idea what is wrong? or is this kind of an expected behaviour?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 11:35:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/188772#M67722</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2023-08-07T11:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Ordered Layers - Logging shows wrong Access Rule/Layer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/188773#M67723</link>
      <description>&lt;P&gt;It says "cleanup rule", and I assume, it is a clean-up rule of your sublayer. How does that sublayer look?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 11:38:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/188773#M67723</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-07T11:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: Ordered Layers - Logging shows wrong Access Rule/Layer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/188776#M67724</link>
      <description>&lt;P&gt;Hi Val,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Cleanup rule" of first ordered layer is set to Accept Any any Tracking: none&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-08-07_13-40-29.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21989iBCE54245A3A47A40/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2023-08-07_13-40-29.png" alt="2023-08-07_13-40-29.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;("Cleanup Rule of "lyr_block")&lt;/P&gt;&lt;P&gt;There are two layers in this policy package&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-08-07_13-43-45.png" style="width: 245px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21990iAF298357453397FE/image-dimensions/245x98?v=v2" width="245" height="98" role="button" title="2023-08-07_13-43-45.png" alt="2023-08-07_13-43-45.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;subordinated layer is meaning the "normal" policy rule set (pol_xyz) - where the communication is allowed (or not) with Tracking set to "log"&lt;/P&gt;&lt;P&gt; for instance&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/image/serverpage/image-id/21986i7BAB34C1DF1DF157/image-size/medium?v=v2&amp;amp;px=400" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/image/serverpage/image-id/21986i7BAB34C1DF1DF157/image-size/medium?v=v2&amp;amp;px=400&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 11:48:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/188776#M67724</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2023-08-07T11:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Ordered Layers - Logging shows wrong Access Rule/Layer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/188782#M67725</link>
      <description>&lt;P&gt;Hmm, this is a bit odd. Do I see correctly that you have two network policy layers in this security policy package? Why is that?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 12:23:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/188782#M67725</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-07T12:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: Ordered Layers - Logging shows wrong Access Rule/Layer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/188786#M67726</link>
      <description>&lt;P&gt;this is to address a requirement in being able to rapidly block communication to/from several networks if needed. if used in the same network policy layer you&amp;nbsp;would run into policy verification errors, because those objects are used somewhere else in the policy. resolving these errors is not possible within the term "rapid"&lt;/P&gt;&lt;P&gt;Using an inline layer would workaround the policy verification error too, but is not possible here for now. so i went towards ordered layers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 12:30:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/188786#M67726</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2023-08-07T12:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Ordered Layers - Logging shows wrong Access Rule/Layer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/189041#M67727</link>
      <description>&lt;P&gt;I observed exactly this behaviour with the same layered policy approach for the same reason (block unwanted traffic) and opened a support ticket.&lt;/P&gt;&lt;P&gt;Support have advised this is expected behaviour, although I think it is a bug.&lt;/P&gt;&lt;P&gt;If you select the rule in the lower layer that the traffic hits and look at 'logs' at the bottom of the console window, it shows the traffic as hitting the rule on the upper layer. The 'logs' view in smartconsole has a predefined filter which is supposed to match 'current rule' but in this scenario it matches a different rule in a different layer...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: I forgot to add, the reason we decided to use a layered policy is that is how Playblocks are implemented, so if they display the same behaviour that will be a problem&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 10:27:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/189041#M67727</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2023-08-09T10:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Ordered Layers - Logging shows wrong Access Rule/Layer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/189044#M67728</link>
      <description>&lt;P&gt;I think the behaviour may be different in R81.20 also&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 10:48:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/189044#M67728</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2023-08-09T10:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: Ordered Layers - Logging shows wrong Access Rule/Layer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/189045#M67729</link>
      <description>&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;i am afraid not - i am on 81.20&lt;/P&gt;&lt;P&gt;an additional layer is also added, when using IOT Protect...&amp;nbsp;&lt;/P&gt;&lt;P&gt;nevertheless, if with or without it (IOT Protect / PlayBlocks), the behaviour is the same - logging shows the wrong rule. (which has logging disabled)&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 10:56:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/189045#M67729</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2023-08-09T10:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Ordered Layers - Logging shows wrong Access Rule/Layer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/189230#M67730</link>
      <description>&lt;P&gt;...when deleting the cleanup rule (policy is set to implicit accept), the only thing that changed is, logs are now shown with "implicit cleanup" as matched rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;SmartTracker does not show a matched rule, so SmartLog inserts the first matching rule for a communication? Someone knows a possibility, so SmartLog adds the "last matching" rule instead of "first"?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 06:38:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Ordered-Layers-Logging-shows-wrong-Access-Rule-Layer/m-p/189230#M67730</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2023-08-11T06:38:46Z</dc:date>
    </item>
  </channel>
</rss>

