<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inline layers and 'Any' access in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-layers-and-Any-access/m-p/48342#M87058</link>
    <description>The column-based matching only applies within a layer, ignoring any inline layers.&lt;BR /&gt;If the packet matches a rule with an action of an inline layer, then that inline layer is analyzed for a match.&lt;BR /&gt;If no rule in that inline layer matches, the implicit rule (either drop or accept, depending on configuration) applies.</description>
    <pubDate>Fri, 22 Mar 2019 21:52:18 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-03-22T21:52:18Z</dc:date>
    <item>
      <title>Inline layers and 'Any' access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-layers-and-Any-access/m-p/48241#M87056</link>
      <description>&lt;P&gt;Just to verify my understanding.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I have a inline layer like this&lt;/P&gt;&lt;P&gt;1.1 src:Any dst:MyNet1&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1.2 src:MyNet2 dst:MyNet1 Action:Accept&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1.3 src:Any dst:MyNet Action:Drop (inline clean up)&lt;/P&gt;&lt;P&gt;2.0 src:MyNet3 dst:Any Action:Accept&lt;/P&gt;&lt;P&gt;and the 2.0 rule won't allow mynet3 to reach mynet1? Just thinking how the "Accept internet except internal networks" would work here after all the internal networks have been handled like that. The reason I am using inline layer dst field is this article&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Management-Topics/Unified-Policy-Column-based-Rule-Matching/td-p/9888" target="_blank"&gt;https://community.checkpoint.com/t5/General-Management-Topics/Unified-Policy-Column-based-Rule-Matching/td-p/9888&lt;/A&gt;&amp;nbsp;where it says that rule matching begins from dst.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 09:11:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-layers-and-Any-access/m-p/48241#M87056</guid>
      <dc:creator>SamiH</dc:creator>
      <dc:date>2019-03-22T09:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Inline layers and 'Any' access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-layers-and-Any-access/m-p/48318#M87057</link>
      <description>Rule 2.0 will not allow access to MyNet1 as first of all rule 1.3 will drop it, otherwise the default Implicit drop will (a setting on the layer). &lt;BR /&gt;To allow Internal networks you need them to either skip rule 1.1 by negating the internal network, or be explicit in the layer as you are doing in rule 1.2.</description>
      <pubDate>Fri, 22 Mar 2019 18:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-layers-and-Any-access/m-p/48318#M87057</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-03-22T18:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: Inline layers and 'Any' access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-layers-and-Any-access/m-p/48342#M87058</link>
      <description>The column-based matching only applies within a layer, ignoring any inline layers.&lt;BR /&gt;If the packet matches a rule with an action of an inline layer, then that inline layer is analyzed for a match.&lt;BR /&gt;If no rule in that inline layer matches, the implicit rule (either drop or accept, depending on configuration) applies.</description>
      <pubDate>Fri, 22 Mar 2019 21:52:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Inline-layers-and-Any-access/m-p/48342#M87058</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-22T21:52:18Z</dc:date>
    </item>
  </channel>
</rss>

