<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80(.20) rule matching in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-rule-matching/m-p/14242#M91188</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please verify your topology configuration. If it is configured correctly please open a support ticket.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Nov 2018 14:33:43 GMT</pubDate>
    <dc:creator>Tal_Ben_Avraham</dc:creator>
    <dc:date>2018-11-08T14:33:43Z</dc:date>
    <item>
      <title>R80(.20) rule matching</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-rule-matching/m-p/14240#M91186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was a bit surprised by the rule matching logic in R80(.20).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a parent rule for Internal to DMZ traffic:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/73453_2018-11-01 14_35_51-SmartConsole (fwmgmt.networkschool.org).png" /&gt;&lt;/P&gt;&lt;P&gt;And a parent rule for Internal to Internal traffic:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="/legacyfs/online/checkpoint/73454_2018-11-01 14_37_14-SmartConsole (fwmgmt.networkschool.org).png" /&gt;&lt;/P&gt;&lt;P&gt;In the Internal to Internal policy&amp;nbsp;I have a&amp;nbsp;rule for my Active Directory traffic:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-4 jive-image j-img-original" src="/legacyfs/online/checkpoint/73457_2018-11-08 13_34_15-SmartConsole (fwmgmt.networkschool.org).png" /&gt;&lt;/P&gt;&lt;P&gt;But as I missed a protocol in this bunch the traffic was dropped. But not on the rule I expected it to be dropped on:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-3 jive-image j-img-original" src="/legacyfs/online/checkpoint/73455_2018-11-01 14_36_46-Log Details.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So why would it drop on the wrong rule here?&lt;/P&gt;&lt;P&gt;There seems to be an inconsistence in the logging as it goes from Internal to Internal on the left hand but on the right hand it declares it from Internal to DMZ.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-5 jive-image j-img-original" src="/legacyfs/online/checkpoint/73458_2018-11-08 13_40_00-Interface_ eth0.101.png" /&gt;&lt;IMG alt="" class="image-6 jive-image j-img-original" src="/legacyfs/online/checkpoint/73459_2018-11-08 13_40_45-Interface_ eth0.105.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone explain why this inconsistence behaviour occurs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2018 12:44:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-rule-matching/m-p/14240#M91186</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-11-08T12:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: R80(.20) rule matching</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-rule-matching/m-p/14241#M91187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hugo,&lt;/P&gt;&lt;P&gt;The only thing that comes to mind is if your DMZs IPv6 scope is including the destination, but there is likely a mechanism that should prevent it from happening.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2018 13:12:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-rule-matching/m-p/14241#M91187</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-11-08T13:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: R80(.20) rule matching</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-rule-matching/m-p/14242#M91188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please verify your topology configuration. If it is configured correctly please open a support ticket.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2018 14:33:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-rule-matching/m-p/14242#M91188</guid>
      <dc:creator>Tal_Ben_Avraham</dc:creator>
      <dc:date>2018-11-08T14:33:43Z</dc:date>
    </item>
  </channel>
</rss>

