<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Check point policy base coversion to inline layers in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152412#M71629</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I've recently used the SmartMove to move rules from ASA to CP.&lt;BR /&gt;I saw that it puts rules automatically with inline layers.&lt;/P&gt;&lt;P&gt;Is that a way to do same, like group automatically the rules for an existing Check Point policy base (R80.40)?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jul 2022 08:40:54 GMT</pubDate>
    <dc:creator>lmorocz</dc:creator>
    <dc:date>2022-07-06T08:40:54Z</dc:date>
    <item>
      <title>Check point policy base coversion to inline layers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152412#M71629</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I've recently used the SmartMove to move rules from ASA to CP.&lt;BR /&gt;I saw that it puts rules automatically with inline layers.&lt;/P&gt;&lt;P&gt;Is that a way to do same, like group automatically the rules for an existing Check Point policy base (R80.40)?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 08:40:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152412#M71629</guid>
      <dc:creator>lmorocz</dc:creator>
      <dc:date>2022-07-06T08:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Check point policy base coversion to inline layers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152425#M71630</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To make sure I understood this correctly "&lt;SPAN&gt;Is that a way to do same, like group automatically the rules for an existing Check Point policy base (R80.40)?&amp;nbsp;&lt;/SPAN&gt;" -&amp;nbsp; you mean you want to move existing ordered layers (R80.40 - it doesn't matter) to in-line layer format in an automated way ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we moved from ordered to in-line layer a bit more than a year ago, I can tell you that we did that exercise manually, going over each rule-line from ordered layer policy. (we had from 40 lines to 700 lines in our old rulebase)&lt;/P&gt;
&lt;P&gt;By doing that we cleared the "debris"&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt; and checked once again what is allowed and what is not allowed, and other stuff like that.&lt;/P&gt;
&lt;P&gt;Doing this exercise once every few years, is a good thing in my opinion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 10:36:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152425#M71630</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-07-06T10:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Check point policy base coversion to inline layers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152433#M71631</link>
      <description>&lt;P&gt;Yes exactly, I would like to move ordered layers to be inlines.&lt;BR /&gt;The automatic part would be more like a guideline, then we would overseer the outcome of course.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 13:07:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152433#M71631</guid>
      <dc:creator>lmorocz</dc:creator>
      <dc:date>2022-07-06T13:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Check point policy base coversion to inline layers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152434#M71632</link>
      <description>&lt;P&gt;I did this for customers few times with smart move and I can tell you that its so much better when you have inline layers. Its more secure, traffic gets handled much faster. Here is a good example...say, for argument sake, you have 1000 rules in your rulebase and no layers at all, inline or ordered. Well, policy will have to be checked until needed rule is hit, but with layers, if it does not hit whats called "parent rule", then it wont bother checking "child rules" inside that inline layer, will just move to next inline layer and so on, until it hits the right one and if nothing matches, then will hit implicit clean up rule, so traffic handling works way better that way.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 13:10:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152434#M71632</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-06T13:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: Check point policy base coversion to inline layers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152439#M71633</link>
      <description>&lt;P&gt;For existing Check Point policies, not aware of a tool.&lt;BR /&gt;We also have not published any guidelines for converting.&lt;/P&gt;
&lt;P&gt;If you still have a legacy App Control layer, it’s easy enough to make that an inline layer either by copy paste or converting the ordered layer to an inline one.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 14:09:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152439#M71633</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-06T14:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Check point policy base coversion to inline layers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152443#M71634</link>
      <description>&lt;P&gt;Honestly, just going through them would be the best recommended way from my side, as that is what we did before.&lt;/P&gt;
&lt;P&gt;There are several recommendation out there that you can follow, on how to sketch your in-line layer policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;(I can search them once again and point them to you)&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 14:38:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152443#M71634</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-07-06T14:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Check point policy base coversion to inline layers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152513#M71635</link>
      <description>&lt;P&gt;Thanks a lot, that's why I have not found anything!&amp;nbsp;&lt;BR /&gt;I've thought a way, but I have some questions about it too, will post it as a different after some digging.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 14:18:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-point-policy-base-coversion-to-inline-layers/m-p/152513#M71635</guid>
      <dc:creator>lmorocz</dc:creator>
      <dc:date>2022-07-07T14:18:09Z</dc:date>
    </item>
  </channel>
</rss>

