<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobile Access Web Portal Access Matching Rule Issue in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105942#M20296</link>
    <description>&lt;P&gt;Off the top of my head:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Gaia Platform Portal (OS configuration)&lt;/LI&gt;
&lt;LI&gt;Mobile Access Blade&lt;/LI&gt;
&lt;LI&gt;Captive Portal (for Identity Awareness)&lt;/LI&gt;
&lt;LI&gt;UserCheck&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Visitor Mode for Remote Access&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;There may be a few others.&lt;BR /&gt;However, disabling/changing all those may not disable multiportal and the relevant implied rules.&lt;/P&gt;</description>
    <pubDate>Sun, 20 Dec 2020 03:12:03 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-12-20T03:12:03Z</dc:date>
    <item>
      <title>Mobile Access Web Portal Access Matching Rule Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105701#M20258</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been experiencing below issue related to Mobile Access Portal.&lt;/P&gt;&lt;P&gt;My requirement is to just block specific Public IPs from accessing Mobile Access Portal. What I've done is, I change Mobile Access-&amp;gt;Portal Settings-&amp;gt;According to the firewall policy to enabled and placed an explicit security rule to block required source IPs and then below that placed an explicit security rule to allow any source IP to Mobile Access Portal.&lt;/P&gt;&lt;P&gt;My Observation:&lt;/P&gt;&lt;P&gt;My Mobile Access Portal got blocked as expected to the required blocked IP addresses. But issue is when I checked smart log it showed me that blocked requests are also matched with an implied rule and the action is accept instead of my explicit block rule. But other public IPs matched with my explicit allow rule where as I expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my SIEM tool alerting us Blocked IPs are gaining access without getting blocked based on implied rule log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 03:19:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105701#M20258</guid>
      <dc:creator>zeromahesh</dc:creator>
      <dc:date>2020-12-17T03:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Web Portal Access Matching Rule Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105909#M20288</link>
      <description>&lt;P&gt;Are you actually seeing two logs (one for the implied rule accepting and one for the block rule)?&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 03:53:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105909#M20288</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-19T03:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Web Portal Access Matching Rule Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105910#M20289</link>
      <description>&lt;P&gt;What I see is when I access Mobile Access Portal using non blocked IP it matches to the explicit rule which allow access to mobile portal. When I access using blocked IP using explicit block rule matches to implicit rule and action shows as accept. But portal getting denied with SSL error. Some logs shows as denied by multiportal infrastructure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 03:58:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105910#M20289</guid>
      <dc:creator>zeromahesh</dc:creator>
      <dc:date>2020-12-19T03:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Web Portal Access Matching Rule Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105933#M20292</link>
      <description>&lt;P&gt;Multiportal allows multiple portals to share the same port (e.g. Gaia WebUI, MAB, UserCheck).&lt;BR /&gt;However, access (i.e. the initial TCP handshake) is generally permitted by implied rules, which is needed to determine which portal to activate.&lt;BR /&gt;If you don’t want multiportal to respond at all, then you have to disable multiportal functionality per:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165937" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165937&lt;/A&gt;&lt;BR /&gt;However, this means you will need to manually configure ALL the relevant portals to use a unique port.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 19:12:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105933#M20292</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-19T19:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Web Portal Access Matching Rule Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105936#M20293</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Currently I’ve already set Gia portal (Platform) Accessibility settings to “Internal Interface only”. Mobile Access Portal Accessibility option to “ According to firewall policy”. So what are the other portals published through all the interfaces by default and how to change port or interface.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 20:48:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105936#M20293</guid>
      <dc:creator>zeromahesh</dc:creator>
      <dc:date>2020-12-19T20:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Web Portal Access Matching Rule Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105942#M20296</link>
      <description>&lt;P&gt;Off the top of my head:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Gaia Platform Portal (OS configuration)&lt;/LI&gt;
&lt;LI&gt;Mobile Access Blade&lt;/LI&gt;
&lt;LI&gt;Captive Portal (for Identity Awareness)&lt;/LI&gt;
&lt;LI&gt;UserCheck&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Visitor Mode for Remote Access&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;There may be a few others.&lt;BR /&gt;However, disabling/changing all those may not disable multiportal and the relevant implied rules.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 03:12:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105942#M20296</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-20T03:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Web Portal Access Matching Rule Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105943#M20297</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Major issue that I'm facing is, when Implied rule matches for the connections from explicit rule blocked IPs even though portal is not loaded implied rule log says connection accepted. This incident is alerted by the SIEM tool. How to overcome this issue.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 06:18:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105943#M20297</guid>
      <dc:creator>zeromahesh</dc:creator>
      <dc:date>2020-12-20T06:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Web Portal Access Matching Rule Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105946#M20299</link>
      <description>&lt;P&gt;Seems like you should tune this in the SIEM.&lt;BR /&gt;However, if I’m understanding the macro in sk165937 correctly, where it shows you what section to comment out to entirely disable this behavior, you may be able to simply remove the following from the definition:&lt;/P&gt;
&lt;PRE&gt;IMPLIED_LOG,&amp;nbsp;&amp;nbsp;&lt;/PRE&gt;
&lt;P&gt;This will cause the gateway to still accept the connection as it’s doing now but not generate a log message.&lt;BR /&gt;Don’t necessarily recommend this approach, tuning the SIEM would be better.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 06:33:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105946#M20299</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-20T06:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Web Portal Access Matching Rule Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105947#M20300</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you for your suggestion. Please let me know what will happen if I enable separate portals in separate IPs in same interface. Will that solved the issue the way that I'm expecting...?&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 06:40:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105947#M20300</guid>
      <dc:creator>zeromahesh</dc:creator>
      <dc:date>2020-12-20T06:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Web Portal Access Matching Rule Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105988#M20304</link>
      <description>&lt;P&gt;The issue is coming from Multiportal itself, not the other portals in use.&lt;BR /&gt;Most of the portals can be moved to a different port on the same IP if you prefer, but that doesn’t disable multiportal.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 17:57:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Mobile-Access-Web-Portal-Access-Matching-Rule-Issue/m-p/105988#M20304</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-20T17:57:11Z</dc:date>
    </item>
  </channel>
</rss>

