<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Implied Rules vs manually created policy rules in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Implied-Rules-vs-manually-created-policy-rules/m-p/133236#M24005</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am confused with the below scenario.&lt;/P&gt;&lt;P&gt;I am able to ping mailserver.mycompany.com from the public internet and I need to drop this traffic.&amp;nbsp; Logs show this traffic is accepted via implied rule.&lt;/P&gt;&lt;P&gt;In global properties I have Accept ICMP requests checked and it is set to Before Last.&amp;nbsp; I think this is what allows the pings with a implied rule?&lt;/P&gt;&lt;P&gt;If I create a test rule near the top of my policy with the source being my public internet ip, destination ip address for mailserver.mycompany.com, action drop the pings are dropped by that rule as expected.&lt;/P&gt;&lt;P&gt;My policy has a cleanup rule at the bottom.&amp;nbsp; I don't understand why the icmp request / ping traffic is not dropped by the cleanup rule but is dropped by my test rule?&lt;/P&gt;&lt;P&gt;With the global property set at "Before last" does that literally mean that the implied rule is applied before the last rule (my cleanup rule) in the policy?&lt;/P&gt;&lt;P&gt;What is the best practice when it comes to dropping unwanted traffic like this?&lt;/P&gt;</description>
    <pubDate>Thu, 04 Nov 2021 13:37:19 GMT</pubDate>
    <dc:creator>Mike_Jensen</dc:creator>
    <dc:date>2021-11-04T13:37:19Z</dc:date>
    <item>
      <title>Implied Rules vs manually created policy rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-Rules-vs-manually-created-policy-rules/m-p/133236#M24005</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am confused with the below scenario.&lt;/P&gt;&lt;P&gt;I am able to ping mailserver.mycompany.com from the public internet and I need to drop this traffic.&amp;nbsp; Logs show this traffic is accepted via implied rule.&lt;/P&gt;&lt;P&gt;In global properties I have Accept ICMP requests checked and it is set to Before Last.&amp;nbsp; I think this is what allows the pings with a implied rule?&lt;/P&gt;&lt;P&gt;If I create a test rule near the top of my policy with the source being my public internet ip, destination ip address for mailserver.mycompany.com, action drop the pings are dropped by that rule as expected.&lt;/P&gt;&lt;P&gt;My policy has a cleanup rule at the bottom.&amp;nbsp; I don't understand why the icmp request / ping traffic is not dropped by the cleanup rule but is dropped by my test rule?&lt;/P&gt;&lt;P&gt;With the global property set at "Before last" does that literally mean that the implied rule is applied before the last rule (my cleanup rule) in the policy?&lt;/P&gt;&lt;P&gt;What is the best practice when it comes to dropping unwanted traffic like this?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 13:37:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-Rules-vs-manually-created-policy-rules/m-p/133236#M24005</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2021-11-04T13:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Implied Rules vs manually created policy rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-Rules-vs-manually-created-policy-rules/m-p/133237#M24006</link>
      <description>&lt;P&gt;I think you just answered all your questions yourself. Yes, implied rule "before last" literally means, before the last explicit rule, which is usually the cleanup policy rule. ICMP "Before Last" is disabled by default. In your case, you can just un-check it and install policy. If you need ICMP to run, I would recommend more targeted explicit rules for that.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 13:46:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-Rules-vs-manually-created-policy-rules/m-p/133237#M24006</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-04T13:46:47Z</dc:date>
    </item>
  </channel>
</rss>

