<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Duplicate services - which will be used? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/53484#M10661</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;recently I came across behavior, where supposedly permitted traffic is dropped by protocol handler. In my case I do do have defined duplicated service objects for snmp, udp/161. First is default service object snmp, port udp/161 with no Protocol Type set. Second service object is also port udp/161 with Protocol Type: SNMP_V3 , both objects are set "Match for Any", And both objects are used in a rule, which permits SNMP for monitoring.&lt;/P&gt;&lt;P&gt;Some SNMPv2 packets are permitted when matching rule, but dropped by protocol handler:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;;[cpu_2];[fw4_3];fw_log_drop_ex: Packet proto=17 10.20.30.40:47940 -&amp;gt; 20.30.40.50:161 dropped by fwpslglue_chain Reason: PSL Drop: ASPII_MT;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Being aware, that such is not ideal situation, but still I am wonder, how INSPECT will decide, which service parameters will be used for traffic? How then is handling traffic in situation, where is duplicity in service objects exists and in a rule is used "any" for service?&lt;/P&gt;&lt;P&gt;Thank you for tips to documentation or SKs related.&lt;/P&gt;</description>
    <pubDate>Wed, 15 May 2019 07:50:56 GMT</pubDate>
    <dc:creator>Martin_Oles</dc:creator>
    <dc:date>2019-05-15T07:50:56Z</dc:date>
    <item>
      <title>Duplicate services - which will be used?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/53484#M10661</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;recently I came across behavior, where supposedly permitted traffic is dropped by protocol handler. In my case I do do have defined duplicated service objects for snmp, udp/161. First is default service object snmp, port udp/161 with no Protocol Type set. Second service object is also port udp/161 with Protocol Type: SNMP_V3 , both objects are set "Match for Any", And both objects are used in a rule, which permits SNMP for monitoring.&lt;/P&gt;&lt;P&gt;Some SNMPv2 packets are permitted when matching rule, but dropped by protocol handler:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;;[cpu_2];[fw4_3];fw_log_drop_ex: Packet proto=17 10.20.30.40:47940 -&amp;gt; 20.30.40.50:161 dropped by fwpslglue_chain Reason: PSL Drop: ASPII_MT;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Being aware, that such is not ideal situation, but still I am wonder, how INSPECT will decide, which service parameters will be used for traffic? How then is handling traffic in situation, where is duplicity in service objects exists and in a rule is used "any" for service?&lt;/P&gt;&lt;P&gt;Thank you for tips to documentation or SKs related.&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 07:50:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/53484#M10661</guid>
      <dc:creator>Martin_Oles</dc:creator>
      <dc:date>2019-05-15T07:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate services - which will be used?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/53492#M10665</link>
      <description>&lt;P&gt;Duplicate services are not supported and should not be used at all !&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 09:18:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/53492#M10665</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-05-15T09:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate services - which will be used?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/53731#M10731</link>
      <description>Depends on what service is in the rule that matches the connection.&lt;BR /&gt;If the rule has a service of "Any" then the service that has "Match for Any" checked will apply.&lt;BR /&gt;And yes, you can only have one service defined with a given port that is configured with "Match for Any" else you will get a a compilation error.</description>
      <pubDate>Fri, 17 May 2019 20:20:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/53731#M10731</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-17T20:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate services - which will be used?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/54027#M10794</link>
      <description>&lt;P&gt;Both services are having currently "match for any" set. I am aware, that such is not supported, but rather big environment and complex rule is profound for such. Surprisingly SNMPv2 traffic is dropped by protocol handler as not matching SNMPv3 even if I have created dedicated rule, where is only used SNMPv2 service object without any protocol handler.&lt;/P&gt;&lt;P&gt;Not being fan to elaborate on production system I will try to re-create it in lab environment.&lt;/P&gt;&lt;P&gt;Dropped traffic is matching rule, where as service are both service objects used with udp/161.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 13:07:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/54027#M10794</guid>
      <dc:creator>Martin_Oles</dc:creator>
      <dc:date>2019-05-21T13:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate services - which will be used?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/54040#M10798</link>
      <description>&lt;P&gt;If you are already aware that such a configuration is not supported and will not work, all is good !&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 14:40:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/54040#M10798</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-05-21T14:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate services - which will be used?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/54044#M10799</link>
      <description>That's bound to cause some issues and is definitely worth a TAC case.&lt;BR /&gt;In a default configuration in R80.x at least, specific services for SNMPv3 and SNMPv2 do not exist.</description>
      <pubDate>Tue, 21 May 2019 15:11:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Duplicate-services-which-will-be-used/m-p/54044#M10799</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-21T15:11:29Z</dc:date>
    </item>
  </channel>
</rss>

