<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Related Question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35110#M88117</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vijay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand your rule ordering. However your problem is that your traffic isn't matching your new rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To help you diagnose this we need to see log entries to see what is happening in the environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post further information so that we can help you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Feb 2019 20:56:51 GMT</pubDate>
    <dc:creator>Mark_Mitchell</dc:creator>
    <dc:date>2019-02-22T20:56:51Z</dc:date>
    <item>
      <title>Policy Related Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35106#M88113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Am working on rule base cleanup and after i cleaned up few rules i see some hits in my old rules for any service..below is the example . We have R77.30 Mgmt server.&lt;/P&gt;&lt;P&gt;we have created the new rules on top of old rule, now when I checked the usage of old rules only for service I still see the usage in the old rules for the same ports which is allowed on new rules. Please let me&amp;nbsp; know if this is fine to disable the old rules?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example : Rule 101 (Old) ANY Service&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Rule 102 (New) FTP, HTTP&lt;/P&gt;&lt;P&gt;But still seeing hits in old rules for same services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vijay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2019 16:26:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35106#M88113</guid>
      <dc:creator>Vijay_Nagaraj</dc:creator>
      <dc:date>2019-02-22T16:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Related Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35107#M88114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI the rule order is New rule with limited service on top and same source and destination with ANY service in bottom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vijay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2019 16:33:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35107#M88114</guid>
      <dc:creator>Vijay_Nagaraj</dc:creator>
      <dc:date>2019-02-22T16:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Related Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35108#M88115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vijay,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your more specific rule is placed above the less specific one, then the more specific rule should be being hit. Can you share more details around the rules please? And also the log entries if possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your "new" rule is not being hit right now then disabling the old rule will more than likely result in a loss of service.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2019 19:28:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35108#M88115</guid>
      <dc:creator>Mark_Mitchell</dc:creator>
      <dc:date>2019-02-22T19:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Related Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35109#M88116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;My new rule with limited services like HTTP, STP is in top&amp;nbsp;&lt;/P&gt;&lt;P&gt;My old rule with ANY services is bottom of this rule. Both has the same source and destination but the service differs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VIjay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2019 20:50:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35109#M88116</guid>
      <dc:creator>Vijay_Nagaraj</dc:creator>
      <dc:date>2019-02-22T20:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Related Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35110#M88117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vijay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand your rule ordering. However your problem is that your traffic isn't matching your new rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To help you diagnose this we need to see log entries to see what is happening in the environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post further information so that we can help you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2019 20:56:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35110#M88117</guid>
      <dc:creator>Mark_Mitchell</dc:creator>
      <dc:date>2019-02-22T20:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Related Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35111#M88118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you push the policy on affected firewall ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Feb 2019 08:10:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35111#M88118</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2019-02-23T08:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Related Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35112#M88119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes,,,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Feb 2019 13:30:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Related-Question/m-p/35112#M88119</guid>
      <dc:creator>Vijay_Nagaraj</dc:creator>
      <dc:date>2019-02-23T13:30:21Z</dc:date>
    </item>
  </channel>
</rss>

