<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Required Rules for Gateway and SMS? Implied Rules Question. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162976#M27176</link>
    <description>&lt;P&gt;In a Unified Policy, you'd have a single layer with the relevant blades enabled (Firewall and App Control in this case).&lt;/P&gt;</description>
    <pubDate>Wed, 23 Nov 2022 19:09:36 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-11-23T19:09:36Z</dc:date>
    <item>
      <title>Required Rules for Gateway and SMS? Implied Rules Question.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162678#M27099</link>
      <description>&lt;P&gt;Hey all, we have a Smart-1 appliance/2 SG 6000 appliances clustered.&lt;BR /&gt;Our system has been updated at least twice from older hardware with existing rules.&lt;/P&gt;&lt;P&gt;Looking over a few rules, I'd like to clean our rules up to what is necessary to unify sec/app layer.&lt;BR /&gt;Are there any articles for what is needed to for the management and security gateways on R81.10?&lt;/P&gt;&lt;P&gt;For example, I'm looking at deleting a rule 2 for our SMS/SGs (Source) -&amp;gt; Internal DNS Servers (Destination) / udp&amp;amp;tcp 53 -&amp;gt;Accept.&lt;BR /&gt;Logs for that rule look like this. Rule 0 under a different layer is saying its Implied.&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="q.png" style="width: 494px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18496i15C563D50F5D07BA/image-size/large?v=v2&amp;amp;px=999" role="button" title="q.png" alt="q.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've disabled Rule 2, but wondering now I'm wondering if I move to a unified layer and delete the Application layer will DNS stop working? If a log exists lists an rule 0 - Implied Rule, would that be safe to determine we do not need a rule (after verifying logs are not hitting any other rules of course).&lt;BR /&gt;&lt;BR /&gt;Another log example. Would this be safe to determine to delete if it is implied?&amp;nbsp; I'm not seeing a difference between my Security/App layer Implied Rules. (I'm not sure if they're the same or not?)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="z.png" style="width: 585px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18498iBCB272871D93FF76/image-dimensions/585x76?v=v2" width="585" height="76" role="button" title="z.png" alt="z.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="p.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18497i254CB7A7616C5D49/image-size/medium?v=v2&amp;amp;px=400" role="button" title="p.png" alt="p.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If you have any Policy cleanup tips that would be great too. I have rules that are too permissive that I'd like to clean up to have our network more secure.&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 18:24:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162678#M27099</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2022-11-21T18:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Required Rules for Gateway and SMS? Implied Rules Question.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162686#M27102</link>
      <description>&lt;P&gt;Below post should be helpful:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security/Port-Requirement-Management-Server-and-Gateways/td-p/87059" target="_blank"&gt;https://community.checkpoint.com/t5/Cloud-Network-Security/Port-Requirement-Management-Server-and-Gateways/td-p/87059&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Now, you cant disable any implied rules from GUI (as you should NOT anyway), but you can modify based on below (if need be)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43401" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43401&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92281&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92281&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;As far as rules cleanup, I would look for disabled/0 hits rules and take care of those.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2022 19:21:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162686#M27102</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-21T19:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: Required Rules for Gateway and SMS? Implied Rules Question.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162705#M27104</link>
      <description>&lt;P&gt;Thanks Andy. That thread was helpful.&lt;BR /&gt;&lt;BR /&gt;DO you know if there is Gateway &amp;amp; SMS -to-&amp;gt; External requirements like NTP/DNS/CheckPoint Updates KB?&lt;BR /&gt;Can't seem to find the article.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 00:05:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162705#M27104</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2022-11-22T00:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Required Rules for Gateway and SMS? Implied Rules Question.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162706#M27105</link>
      <description>&lt;P&gt;Not sure if below is what you need, but this is the only one I know of. Now, this is ONLY needed if you disable option in global properties as indicated. I personally never in 15 years dealing with CP met or talked to anyone who did this, but, in all fairness, with much better handling of updatable objects, I guess it might not be so unusual to see customers do it now days.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106251&amp;amp;srcFavorites=favorites" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106251&amp;amp;srcFavorites=favorites&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 00:18:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162706#M27105</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-22T00:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Required Rules for Gateway and SMS? Implied Rules Question.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162722#M27107</link>
      <description>&lt;P&gt;Unless there is a serious security based argument, I would advise you to keep the default implied rules.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 07:44:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162722#M27107</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-22T07:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Required Rules for Gateway and SMS? Implied Rules Question.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162864#M27140</link>
      <description>&lt;P&gt;Hi Val,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not interested in modifying the implied rules. I'm trying to understand them since we have rules created that seem like they are already covered under the Implied Rules. Duplicate rules?&lt;BR /&gt;&lt;BR /&gt;Like if we have a rule for CheckPoint updates to 'x' destination. Is that necessary if I see logs below that rule that it is implied?&lt;BR /&gt;&lt;BR /&gt;Hope I am explaining that right.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 23:53:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162864#M27140</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2022-11-22T23:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Required Rules for Gateway and SMS? Implied Rules Question.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162865#M27141</link>
      <description>&lt;P&gt;Thanks for this. I wonder if at one point we that did have unchecked, and whoever administrated the FW at the time created explicit rules for updates.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 23:55:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162865#M27141</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2022-11-22T23:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Required Rules for Gateway and SMS? Implied Rules Question.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162867#M27142</link>
      <description>&lt;P&gt;Most likely, you must have, because Im 99.99% sure the only time anyone would have explicit rules for updates in the policy would have been if that option in global properties was off.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 00:16:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162867#M27142</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-23T00:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: Required Rules for Gateway and SMS? Implied Rules Question.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162868#M27143</link>
      <description>&lt;P&gt;All of the Implied Rules should be shown here.&lt;BR /&gt;See also:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110218&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110218&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18514i89D26DB8CF337989/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;DNS has implied rules.&lt;BR /&gt;NTP is not covered under Implied Rules (at least the ones shown here).&lt;/P&gt;
&lt;P&gt;However, if traffic were purely being accepted based on these implied rules, it would be accepted that way for both layers.&lt;BR /&gt;Which means...this "Implied Rule" is probably something different.&lt;BR /&gt;I'm assuming your Application layer only has App Control/URL Filtering active and not Firewall?&lt;BR /&gt;That might be the reason for the implied rule as DNS and NTP are handled in the Firewall, not App Control.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 00:19:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162868#M27143</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-23T00:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Required Rules for Gateway and SMS? Implied Rules Question.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162966#M27174</link>
      <description>&lt;P&gt;Thanks PhoneBoy. I'll go over that article as well.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="implied.PNG" style="width: 469px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18518i6E94822F75944A55/image-size/large?v=v2&amp;amp;px=999" role="button" title="implied.PNG" alt="implied.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy.PNG" style="width: 698px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18519i15C8ED7E024186CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="policy.PNG" alt="policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You are correct! That makes sense to me, I THINK.&amp;nbsp;&lt;BR /&gt;--&lt;BR /&gt;I'm assuming it is required to have the Security layer enabled with Application &amp;amp; URL Filtering in order to achieve a unified policy?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 17:25:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162966#M27174</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2022-11-23T17:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Required Rules for Gateway and SMS? Implied Rules Question.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162976#M27176</link>
      <description>&lt;P&gt;In a Unified Policy, you'd have a single layer with the relevant blades enabled (Firewall and App Control in this case).&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 19:09:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Required-Rules-for-Gateway-and-SMS-Implied-Rules-Question/m-p/162976#M27176</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-23T19:09:36Z</dc:date>
    </item>
  </channel>
</rss>

