<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inline Layer with APPL-only does also handle Firewall-Layer rules in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135349#M24223</link>
    <description>&lt;P&gt;I believe FW layer should be enabled there.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Dec 2021 17:34:41 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2021-12-01T17:34:41Z</dc:date>
    <item>
      <title>Inline Layer with APPL-only does also handle Firewall-Layer rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135160#M24198</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;I recently saw a &lt;U&gt;working&lt;/U&gt; environment, where an Inline Layer was used which had only one blade active: Application Control &amp;amp; URL Filtering. The firewall blade was &lt;U&gt;not&lt;/U&gt; enabled on that layer.&lt;/P&gt;
&lt;P&gt;In this layer, there were multiple rules. Most of them used Application Objects in Services &amp;amp; Application Column, but not all.&lt;/P&gt;
&lt;P&gt;There were multiple rules in that layer, that are clearly a job for plain firewall blade:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Src: Host object (static)&lt;/LI&gt;
&lt;LI&gt;Dst: Network object (static)&lt;/LI&gt;
&lt;LI&gt;Service: custom tcp-object with some high port. No protocol selected in that service.&lt;/LI&gt;
&lt;LI&gt;Action: Accept&lt;/LI&gt;
&lt;LI&gt;Track: Log&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These rules are working normally. They have matches like they should.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Now the question(s):&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Is this a supported setup and working correctly by design?&lt;/P&gt;
&lt;P&gt;Or is the customer just lucky that it works this way at the moment and I should tell him to enable firewall blade in that layer?&lt;/P&gt;
&lt;P&gt;Any performance penalties?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Environment:&lt;/P&gt;
&lt;P&gt;Gateway: R80.40 JHF T120&lt;/P&gt;
&lt;P&gt;Management: R80.40 JHF T120&lt;/P&gt;
&lt;P&gt;SmartConsole R80.40 Build 994000424&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your ideas &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 16:00:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135160#M24198</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-11-29T16:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layer with APPL-only does also handle Firewall-Layer rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135349#M24223</link>
      <description>&lt;P&gt;I believe FW layer should be enabled there.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Dec 2021 17:34:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135349#M24223</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-12-01T17:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layer with APPL-only does also handle Firewall-Layer rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135364#M24224</link>
      <description>&lt;P&gt;It should be, yes, but I think even if you don't explicitly enable it, basic firewall rules will still work by design.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 03:04:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135364#M24224</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-12-02T03:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layer with APPL-only does also handle Firewall-Layer rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135365#M24225</link>
      <description>&lt;P&gt;I believe thats expected behavior if you have rule like that...I also saw that with couple customers before.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 04:12:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135365#M24225</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-02T04:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layer with APPL-only does also handle Firewall-Layer rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135543#M24245</link>
      <description>&lt;P&gt;The Firewall checkbox in the layer's properties seems to be purely superficial and is only there to add the icon in the layer's content. I suggest CP would remove the checkbox and pre-populate each layer with the firewall icon in situations where this statement is true.&lt;/P&gt;
&lt;P&gt;Cloning the policy containing Firewall+APCL/URLF+Content Awareness and unchecking the Firewall does not affect functionality.&lt;/P&gt;
&lt;P&gt;As per my offline discussion on this subject with &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt; , he has suggested calling the firewall functionality in APCL/URLF layers as "inferred" whereas I may suggest "inherent".&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 19:37:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135543#M24245</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-12-05T19:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Inline Layer with APPL-only does also handle Firewall-Layer rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135559#M24247</link>
      <description>&lt;P&gt;If you actually think about this, it kinda makes sense that firewall rules still work in layers where it isn't specifically enabled.&lt;BR /&gt;You may need to exclude certain network segments from the advanced inspection done in these other blades.&lt;BR /&gt;The only way to do this...with firewall rules.&lt;BR /&gt;That said, I agree it could be represented better in the UI.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 02:56:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Inline-Layer-with-APPL-only-does-also-handle-Firewall-Layer/m-p/135559#M24247</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-12-06T02:56:12Z</dc:date>
    </item>
  </channel>
</rss>

