<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: in line layer without cleanup in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56590#M85376</link>
    <description>Last weekend we resolved a lot of problems that were still pending a SR that we had open for validation errors. It seems this also resolved the problems I had with the scripts as the same script is now running again.</description>
    <pubDate>Tue, 25 Jun 2019 05:57:06 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-06-25T05:57:06Z</dc:date>
    <item>
      <title>in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56242#M85364</link>
      <description>&lt;P&gt;Ok, here is my understanding of inline layers and I really doubt in the mean time if this is correct.&lt;/P&gt;
&lt;P&gt;I have a number of /29 networks that are part of a /24 and all need access to some specified services.&lt;/P&gt;
&lt;P&gt;Each of these /29's has it's own specific access in-line layer with in and outbound cleanup rules.&lt;/P&gt;
&lt;P&gt;Now I added a access rule with in-line layer to allow the centralized services of which a part is based on URLs and part on specific IP's.&lt;/P&gt;
&lt;P&gt;Now my assumption was, that when you do NOT add a cleanup rule in the /24 in-line layer, the matching will continue thru the rest of the rulebase, thus hitting the specific rules for the /29. Today someone told me that traffic was allowed that should not be allowed, all I can think of is that the message on the /24 in-line layer that says:&lt;/P&gt;
&lt;P&gt;"Missing Cleanup-rule - Unmatched traffic will be accepted and not logged"&lt;/P&gt;
&lt;P&gt;So the main question here is, is this really true?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 07:44:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56242#M85364</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-06-20T07:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56246#M85365</link>
      <description>&lt;P&gt;Hi Maarten,&lt;/P&gt;&lt;P&gt;If it my understanding that if you match the parent rule - say rule 2, then you will never get beyond the rule checking in the in-line layer below rule 2.&lt;/P&gt;&lt;P&gt;I.e rule 3 and below will never be checked if rule2 parent was matched&lt;/P&gt;&lt;P class="tpbodytext"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="tpbodytext"&gt;The Inline Layer has a parent rule (Rule 2 in the example), and sub rules (Rules 2.1 and 2.2). The Action of the parent rule is the name of the Inline Layer.&lt;/P&gt;&lt;P class="tpbodytext"&gt;If the packet does not match the parent rule of the Inline Layer, the matching continues to the next rule of the Ordered Layer (Rule 3).&lt;/P&gt;&lt;P class="tpbodytext"&gt;If a packet matches the parent rule of the Inline Layer (Rule 2), the Firewall checks it against the sub rules:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If the packet matches a sub rule in the Inline Layer (Rule 2.1), no more rule matching is done.&lt;/LI&gt;&lt;LI&gt;If none of the higher rules in the Ordered Layer match the packet, the explicit&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Cleanup Rule&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is applied (Rule 2.2). If this rule is missing, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A title="Types of Rules in the Rule Base" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SecurityManagement_AdminGuide/136972.htm#o148075" target="_self"&gt;Implicit Cleanup Rule&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is applied. No more rule matching is done.&lt;/LI&gt;&lt;/UL&gt;&lt;P class="tpbodytext"&gt;&lt;STRONG&gt;Important&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Always add an explicit&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Cleanup Rule&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;at the end of each Inline Layer, and make sure that its&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is the same as the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt;of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Implicit Cleanup Rule&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="tpbodytext"&gt;Does that answer the question?&lt;/P&gt;&lt;P class="tpbodytext"&gt;thanks&lt;/P&gt;&lt;P class="tpbodytext"&gt;Peter&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 08:33:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56246#M85365</guid>
      <dc:creator>Peter_Lyndley</dc:creator>
      <dc:date>2019-06-20T08:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56277#M85366</link>
      <description>&lt;P&gt;Once a match occurs on the parent rule (rule 6 let's say) and evaluation descends into the sub-rules beneath that parent (6.1-6.X), a match with action will happen in those sub-rules one way or the other and evaluation will not continue past that matched parent's sub-rules.&amp;nbsp; Each layer or set of sub-rules has its own implicit cleanup rule if you don't create one yourself that will be matched.&lt;/P&gt;
&lt;P&gt;Once evaluation descends into a set of sub-rules there is no circumstance where evaluation comes back out of the sub-rules and continues past the matched parent rule (i.e. rule 7+).&amp;nbsp; However once evaluating in a set of sub-rules it is possible to branch into yet another layer with its own set of sub-rules (i.e. rules 6.2.X) but one way or the other a match with action will happen at some point somewhere under 6.X(.X) and evaluation is complete.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 13:15:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56277#M85366</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-06-20T13:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56299#M85367</link>
      <description>So as usual assumption is the mother of all mess ups. (to use the nice word)&lt;BR /&gt;Which means I will have to create a sublayer in each of the /29 layers.&lt;BR /&gt;**bleep**.</description>
      <pubDate>Thu, 20 Jun 2019 18:38:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56299#M85367</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-06-20T18:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56302#M85368</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; can be quite annoying if you have lots of layers.&lt;/P&gt;&lt;P&gt;Still, the managament API could save you lots of time in this case&lt;/P&gt;&lt;P&gt;Use the "add access-rule" statement with the "position bottom" argument. the rule is the same for all layers, so you would just need to parse in all the layers via a csv and the batch option.&lt;/P&gt;&lt;P&gt;"show access-layers" should give you the list that you need to specify within the csv &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hope it helps&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 18:47:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56302#M85368</guid>
      <dc:creator>Maik</dc:creator>
      <dc:date>2019-06-20T18:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56303#M85369</link>
      <description>Understand the trick however, I'm not that clever with the PAI and have run into a real snag there as well with R80.30, it just does not accept the -s id.txt flag when using mgmt_cli anymore.&lt;BR /&gt;But again that is another issue all together.</description>
      <pubDate>Thu, 20 Jun 2019 18:53:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56303#M85369</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-06-20T18:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56304#M85370</link>
      <description>&lt;P&gt;Did you redirect the output of the "mgmt_cli login" statement to the correct file name?&lt;/P&gt;&lt;P&gt;If yes and this is a real issue with R80.30, meaning bug related, you can still do it the way that I described.&lt;/P&gt;&lt;P&gt;Once you make an API call, like "add access-rule", and do not specify a session the "mgmt_cli" command will ask you to log in.&lt;/P&gt;&lt;P&gt;As the described way is just one execution of the api its fine like that and also works (you just call it once, with all the required information, meaning the layer names, within a csv).&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 19:00:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56304#M85370</guid>
      <dc:creator>Maik</dc:creator>
      <dc:date>2019-06-20T19:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56305#M85371</link>
      <description>Script that was running fine on R80.10 just does not want to work on R80.30&lt;BR /&gt;Only when using the -r true flag it works, however that contains these steps:&lt;BR /&gt;login, execute the script step, pulish, logout&lt;BR /&gt;For some quick steps no problem but the wait time per line of script is way to much to be useful.</description>
      <pubDate>Thu, 20 Jun 2019 19:22:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56305#M85371</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-06-20T19:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56486#M85372</link>
      <description>Did you start a separate thread on the mgmt_cli command not working as it did in R80.10?</description>
      <pubDate>Sun, 23 Jun 2019 21:24:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56486#M85372</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-23T21:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56516#M85373</link>
      <description>Nope, did not have the time to do so.</description>
      <pubDate>Mon, 24 Jun 2019 06:46:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56516#M85373</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-06-24T06:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56548#M85374</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17364"&gt;@Maarten_Sjouw&lt;/a&gt;&amp;nbsp; , my name is Amiad Stern and I'm the team leader of the Management APIs.&lt;/P&gt;
&lt;P&gt;I would like to understand what worked on R80.10 which doesn't work on R80.30.&lt;/P&gt;
&lt;P&gt;Can you please share your script, my mail is amiads@checkpoint.com.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Amiad.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 13:18:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56548#M85374</guid>
      <dc:creator>Amiad_Stern</dc:creator>
      <dc:date>2019-06-24T13:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56579#M85375</link>
      <description>&lt;P&gt;Amiad,&lt;BR /&gt;Tomorrow morning back in the office I will send it to you.&lt;BR /&gt;Simply put it comes down to the Authentication part where after you login with "&amp;gt; id.txt" and on the next line you end with the "-s id.txt" it just comes back with an error, sorry cannot give you the error, but when you check with your colleague A. Chuklov, he has a copy of my MDS running.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I knew I posted it here as well, have a look &lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/How-to-add-a-rule-with-multiple-actions/m-p/8975" target="_self"&gt;in this post&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 21:20:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56579#M85375</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-06-24T21:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: in line layer without cleanup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56590#M85376</link>
      <description>Last weekend we resolved a lot of problems that were still pending a SR that we had open for validation errors. It seems this also resolved the problems I had with the scripts as the same script is now running again.</description>
      <pubDate>Tue, 25 Jun 2019 05:57:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/in-line-layer-without-cleanup/m-p/56590#M85376</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-06-25T05:57:06Z</dc:date>
    </item>
  </channel>
</rss>

