<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How are the group objects being processed by the policy? in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/How-are-the-group-objects-being-processed-by-the-policy/m-p/9988#M99720</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a big change in enforcement logic between R77 and R80.10 The latter is briefly viewed here:&amp;nbsp;&lt;A class="link-titled" href="http://checkpoint-master-architect.blogspot.ch/2017/06/cpet-session-2-recording-is-out-there.html" title="http://checkpoint-master-architect.blogspot.ch/2017/06/cpet-session-2-recording-is-out-there.html"&gt;CCMA's blog: CPET session 2 recording is out there&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But for the purpose your question, the answer is simple. A group is used for either Source or Destination. FW will try to match those fields as they are. That means, it will check if IP address is part of the listed objects. In other words, no "virtual rules", just a simple&amp;nbsp;search to match an IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Nov 2017 17:05:00 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2017-11-09T17:05:00Z</dc:date>
    <item>
      <title>How are the group objects being processed by the policy?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/How-are-the-group-objects-being-processed-by-the-policy/m-p/9986#M99718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Somewhat trivial question, but I am interested in the impact the group objects have on policy.&lt;/P&gt;&lt;P&gt;If, for example, we have a single source and a destination comprised of 250 objects, will this result in firewall "creating" 250 virtual rules to process the parent rule?&lt;/P&gt;&lt;P&gt;If the group members are IP addresses, how are they sorted for processing?&lt;/P&gt;&lt;P&gt;If the "last" IP is the one with most hits, does this imply that the preceding objects in the group slowing overall rule processing?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Nov 2017 14:24:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/How-are-the-group-objects-being-processed-by-the-policy/m-p/9986#M99718</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-11-09T14:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: How are the group objects being processed by the policy?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/How-are-the-group-objects-being-processed-by-the-policy/m-p/9987#M99719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rules containing multiple objects will just contain those objects (without creating multiple virtual rules).&lt;/P&gt;&lt;P&gt;In the multiple addresses example you've mentioned the rule will contain all the 250 addresses. Those will be sorted and compact to ranges.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Nov 2017 17:02:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/How-are-the-group-objects-being-processed-by-the-policy/m-p/9987#M99719</guid>
      <dc:creator>Tal_Ben_Avraham</dc:creator>
      <dc:date>2017-11-09T17:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: How are the group objects being processed by the policy?</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/How-are-the-group-objects-being-processed-by-the-policy/m-p/9988#M99720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a big change in enforcement logic between R77 and R80.10 The latter is briefly viewed here:&amp;nbsp;&lt;A class="link-titled" href="http://checkpoint-master-architect.blogspot.ch/2017/06/cpet-session-2-recording-is-out-there.html" title="http://checkpoint-master-architect.blogspot.ch/2017/06/cpet-session-2-recording-is-out-there.html"&gt;CCMA's blog: CPET session 2 recording is out there&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But for the purpose your question, the answer is simple. A group is used for either Source or Destination. FW will try to match those fields as they are. That means, it will check if IP address is part of the listed objects. In other words, no "virtual rules", just a simple&amp;nbsp;search to match an IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Nov 2017 17:05:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/How-are-the-group-objects-being-processed-by-the-policy/m-p/9988#M99720</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2017-11-09T17:05:00Z</dc:date>
    </item>
  </channel>
</rss>

