<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint Firewall Blade in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Firewall-Blade/m-p/178150#M6839</link>
    <description>&lt;P&gt;Hi CheckMates!&lt;BR /&gt;&lt;BR /&gt;I've got a question regarding the default policy for the Harmony Endpoint Firewall Blade.&lt;BR /&gt;Within the "Inbound Traffic" ruleset, a default rule is one which allows *inbound* UDP on ports 67 and 68, seemingly for purposes of DHCP/BOOTP based IP acquisition.&lt;/P&gt;&lt;P&gt;Why exactly is this rule necessary? I've spent the morning testing and DHCP seems to work just fine as long as I permit outbound UDP 67 broadcasts.&lt;/P&gt;&lt;P&gt;If there's something I'm missing regarding DHCP/BOOTP and general FW blade operation please do tell, I just want to avoid keeping things open unless they have to be.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Sat, 15 Apr 2023 16:47:44 GMT</pubDate>
    <dc:creator>Swiftyyyy</dc:creator>
    <dc:date>2023-04-15T16:47:44Z</dc:date>
    <item>
      <title>Endpoint Firewall Blade</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Firewall-Blade/m-p/178150#M6839</link>
      <description>&lt;P&gt;Hi CheckMates!&lt;BR /&gt;&lt;BR /&gt;I've got a question regarding the default policy for the Harmony Endpoint Firewall Blade.&lt;BR /&gt;Within the "Inbound Traffic" ruleset, a default rule is one which allows *inbound* UDP on ports 67 and 68, seemingly for purposes of DHCP/BOOTP based IP acquisition.&lt;/P&gt;&lt;P&gt;Why exactly is this rule necessary? I've spent the morning testing and DHCP seems to work just fine as long as I permit outbound UDP 67 broadcasts.&lt;/P&gt;&lt;P&gt;If there's something I'm missing regarding DHCP/BOOTP and general FW blade operation please do tell, I just want to avoid keeping things open unless they have to be.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 15 Apr 2023 16:47:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Firewall-Blade/m-p/178150#M6839</guid>
      <dc:creator>Swiftyyyy</dc:creator>
      <dc:date>2023-04-15T16:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Firewall Blade</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Firewall-Blade/m-p/178156#M6840</link>
      <description>&lt;P&gt;Have you tested both interim renewal and lease expiry workflows in addition to the initial lease acquisition, presume none of the target machines are DHCP servers themselves?&lt;/P&gt;</description>
      <pubDate>Sun, 16 Apr 2023 00:03:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Firewall-Blade/m-p/178156#M6840</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-16T00:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Firewall Blade</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Firewall-Blade/m-p/178159#M6841</link>
      <description>&lt;P&gt;The test machine(s) are Windows 10 Pro patched to 22H2, the DHCP server is a Mikrotik hAP series.&lt;/P&gt;&lt;P&gt;The following workflows work&lt;/P&gt;&lt;P&gt;1) DHCP IP acquisition while connected to the network during boot/reboot&lt;BR /&gt;This one is rather clear as DHCP seems to occur prior to the Firewall service being up&lt;/P&gt;&lt;P&gt;2) DHCP IP acquisition after fully booting the system and connecting it to the network once on-desktop with CHKP agent services verified to be running&lt;/P&gt;&lt;P&gt;3) DHCP IP forced re-acquisition through ipconfig /release, ipconfig /renew&lt;/P&gt;&lt;P&gt;4) Permitting the client to sit idle on desktop, waiting for DHCP lease expiry&lt;BR /&gt;In this instance the lease length is periodically extended without issue.&lt;/P&gt;&lt;P&gt;5) Changing the STATIC DHCP lease IP address on the DHCP server&lt;BR /&gt;After a period the IP on the client is automatically retrieved.&lt;/P&gt;&lt;P&gt;Another thing that comes to mind would be RFC 3203 - DHCP reconfigure extension which would allow the DHCP server to force-expire a DHCP lease by sending a Unicast message to the client. But I'm not sure where this option is actually implemented/supported.&lt;/P&gt;&lt;P&gt;My Client &amp;amp; Server are also both on the same network; would the workflow differ if a DHCP relay is configured?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Apr 2023 04:50:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Firewall-Blade/m-p/178159#M6841</guid>
      <dc:creator>Swiftyyyy</dc:creator>
      <dc:date>2023-04-16T04:50:24Z</dc:date>
    </item>
  </channel>
</rss>

