<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maximum layers support 231 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198033#M69040</link>
    <description>&lt;P&gt;This shows you the number of layers you've defined across your SMS.&lt;BR /&gt;It doesn't tell you how many of those layers are being used in a given policy package (which is where the limit comes into play).&lt;BR /&gt;However, this is useful none the less.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2023 17:59:41 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-11-15T17:59:41Z</dc:date>
    <item>
      <title>Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/174937#M69029</link>
      <description>&lt;P&gt;We currently use more then 231 layers and are unable to install the policy it seems not to be supported.&lt;/P&gt;&lt;P&gt;Are there any ways to increase this value perhaps in R81.20 or perhaps on the roadmap?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 11:03:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/174937#M69029</guid>
      <dc:creator>dehaasm</dc:creator>
      <dc:date>2023-03-15T11:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/175027#M69030</link>
      <description>&lt;P&gt;I thought this limit was higher (251), but this goes back to R80.10.&lt;BR /&gt;The current limit appears to be&amp;nbsp;231:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk171551" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk171551&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In the last several years, this question has come up only a few times.&lt;BR /&gt;That leads me to believe few customers actually encounter this limit.&lt;BR /&gt;Therefore, I'm not sure there are any specific plans to increase it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;What is the precise use case for this many layers?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 18:27:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/175027#M69030</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-15T18:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/175036#M69031</link>
      <description>&lt;P&gt;The use case is basically to divide the policies into specific flows, for example each partner has its own layer, user flows to specific vlans/security domains have dedicated layers, application flow for each environment (DEV, TEST, QA and PROD) have specific layers. Within each layer a customer can easily go into blocking more for the specific layer/traffic flow. It also makes the policy very organized like a explorer folder structure.&lt;/P&gt;&lt;P&gt;I agree it is perhaps a lot of layers but I don't understand what would be the technical limitation on the system, i guess something that could be easily extended to lets say 1000.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 19:05:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/175036#M69031</guid>
      <dc:creator>dehaasm</dc:creator>
      <dc:date>2023-03-15T19:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/175039#M69032</link>
      <description>&lt;P&gt;Seems like a sensible approach to me.&amp;nbsp;&lt;BR /&gt;Tagging&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9372"&gt;@Tomer_Noy&lt;/a&gt;&amp;nbsp;for visibility of this interesting use case.&lt;/P&gt;
&lt;P&gt;I could see there being limits in both the gateway and the management related to this, making it a less simple matter to increase the limit.&lt;BR /&gt;Recommend approaching your local Check Point office with this RFE.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 19:19:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/175039#M69032</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-15T19:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/175041#M69033</link>
      <description>&lt;P&gt;We are able to create more than 231 layers on the SMS without an issue, it seems that the gateway does not allow it and therefor does not load the policy with installation error. Sure we can contact our local SE contact to consider this and address a RFE.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 19:22:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/175041#M69033</guid>
      <dc:creator>dehaasm</dc:creator>
      <dc:date>2023-03-15T19:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/175046#M69034</link>
      <description>&lt;P&gt;The layer number limitation is indeed on the gateway side. Adding&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7484"&gt;@Nachum_Moshe&lt;/a&gt;&amp;nbsp;for visibility.&lt;/P&gt;
&lt;P&gt;An RFE is probably a good way to promote such a request.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 20:43:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/175046#M69034</guid>
      <dc:creator>Tomer_Noy</dc:creator>
      <dc:date>2023-03-15T20:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198014#M69035</link>
      <description>&lt;P&gt;Is there a way to get the number of layers in use in a policy Package without counting manually ?&lt;/P&gt;&lt;P&gt;KR, Peter&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 15:02:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198014#M69035</guid>
      <dc:creator>Peter_Thome</dc:creator>
      <dc:date>2023-11-15T15:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198026#M69036</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; ACL=$(mgmt_cli -r true show-access-layers -f json | jq -r '.total');TPL=$(mgmt_cli -r true show-threat-layers -f json | jq -r '.total');HIL=$(mgmt_cli -r true show-https-layers -f json | jq -r '.total');echo "$ACL Access layers, $TPL Threat Prevention layers, $HIL HTTPS Inspection layers. "; echo -e "Total $(expr $ALC + $TPL + $HIL)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 17:42:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198026#M69036</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-11-15T17:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198027#M69037</link>
      <description>&lt;P&gt;We don't provide a mechanism that gives you a direct count of the number of layers in use in a given policy package.&lt;/P&gt;
&lt;P&gt;It is possible to programmatically count the number of layers in use via&amp;nbsp;the API.&lt;BR /&gt;Start with the policy package in use: &lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-package~v1.9%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-package~v1.9%20&lt;/A&gt;&lt;BR /&gt;This will list the top-level policy layers in use for both Access Policy and Threat Prevention.&lt;BR /&gt;&lt;BR /&gt;Most likely it is the Access Policy where you are using a number of layers...and most likely they are inline layers.&lt;BR /&gt;These will not be listed directly via show-package, they must be found through parsing the individual rules in the layer, which will have the action "Apply Layer" if an inline-layer is used.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-access-rulebase~v1.9%20" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-access-rulebase~v1.9%20&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 17:40:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198027#M69037</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-15T17:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198028#M69038</link>
      <description>&lt;P&gt;That will only give you the number of top-level "Ordered" layers.&lt;BR /&gt;To find the inline layers in use, you will have to parse the policy layer(s) involved.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 17:43:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198028#M69038</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-15T17:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198031#M69039</link>
      <description>&lt;P&gt;I have an SMS with only inline layers in the Access policies and no ordered layer and with the show-x-layers I see them all in the JSON output with show-x-layers.&lt;/P&gt;&lt;P&gt;[Expert@SomeSMS:0]# ACL=$(mgmt_cli -r true show-access-layers -f json | jq -r '.total');TPL=$(mgmt_cli -r true show-threat-layers -f json | jq -r '.total');HIL=$(mgmt_cli -r true show-https-layers -f json | jq -r '.total');echo "$ACL Access layers, $TPL Threat Prevention layers, $HIL HTTPS Inspection layers. "; echo -e "Total $(expr $ACL + $TPL + $HIL)"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;41 Access layers, 8 Threat Prevention layers, 1 HTTPS Inspection layers.&lt;BR /&gt;Total 50&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 19:58:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198031#M69039</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-11-15T19:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198033#M69040</link>
      <description>&lt;P&gt;This shows you the number of layers you've defined across your SMS.&lt;BR /&gt;It doesn't tell you how many of those layers are being used in a given policy package (which is where the limit comes into play).&lt;BR /&gt;However, this is useful none the less.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 17:59:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198033#M69040</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-15T17:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum layers support 231</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198035#M69041</link>
      <description>&lt;P&gt;You're absolutely right, I stand corrected.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 18:01:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-layers-support-231/m-p/198035#M69041</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-11-15T18:01:39Z</dc:date>
    </item>
  </channel>
</rss>

