<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: In-Line rules, can they 'do nothing' as the last rule in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168811#M28085</link>
    <description>&lt;P&gt;R100 would be more appropriate mate ; - )&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jan 2023 21:03:44 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-01-23T21:03:44Z</dc:date>
    <item>
      <title>In-Line rules, can they 'do nothing' as the last rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168770#M28072</link>
      <description>&lt;P&gt;I am confident that the answer is no for in-line rules.&amp;nbsp; You can drop or allow, but not 'do nothing, pass to the next rule'.&amp;nbsp; Of course, the standard answer is it will be in the next version...&lt;BR /&gt;&lt;BR /&gt;The reason I ask is that we have a global rule that wants to use a complex service, ALL_DCE_RPC.&amp;nbsp; SecureXL stops at that rule.&lt;BR /&gt;With In-Line rules, you could 'hide' ALL_DCE_RPC away from the normal acceleration line.&amp;nbsp; But rules cover a large group of IPs, so will match some parameter.&amp;nbsp; But as the inline runs its course, I would want to use it as a filter and continue with the rest of the rules.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Like I said, this I do something that is not covered in the process,&amp;nbsp; But if you know a way, please share.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 16:31:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168770#M28072</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2023-01-23T16:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: In-Line rules, can they 'do nothing' as the last rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168800#M28081</link>
      <description>&lt;P&gt;I think what you are asking is that if a top/parent rule is matched (say rule 3), and we descend into the sub-rules (3.x) and then if no explicit sub-rules match is there a way to "do nothing" and continue rulebase evaluation at top/parent rule 4?&lt;/P&gt;
&lt;P&gt;If I understand you correctly the answer is no.&amp;nbsp; There is an implied cleanup rule at the end of the sub-layer that will either drop or accept according to the layer property and it is over at that point as a decision has been rendered, there is no way to continue with next parent/top rule right under the sub-layer.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 19:08:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168800#M28081</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-01-23T19:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: In-Line rules, can they 'do nothing' as the last rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168802#M28082</link>
      <description>&lt;P&gt;Im pretty confident answer is no and Im more than confident that it will NOT be in the next version either : - ). As you said, the best you can do is set it to allow or drop. Sadly, you cant change it in below field either...&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19252iE8E31C929429C9EC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 19:38:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168802#M28082</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-23T19:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: In-Line rules, can they 'do nothing' as the last rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168810#M28084</link>
      <description>&lt;P&gt;That is the way I know it would work.&amp;nbsp; I was just having a hope on hope that there was a trick to bend it to my will.&amp;nbsp; Fixed in R90 probably... &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 20:52:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168810#M28084</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2023-01-23T20:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: In-Line rules, can they 'do nothing' as the last rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168811#M28085</link>
      <description>&lt;P&gt;R100 would be more appropriate mate ; - )&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 21:03:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168811#M28085</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-23T21:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: In-Line rules, can they 'do nothing' as the last rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168839#M28091</link>
      <description>&lt;P&gt;There is a DCE-RCE-Protocol "Application" in Application Control that should be SecureXL friendly.&lt;BR /&gt;Of course, that assumes you're using Application Control on the relevant gateways...&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 04:25:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168839#M28091</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-24T04:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: In-Line rules, can they 'do nothing' as the last rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168921#M28108</link>
      <description>&lt;P&gt;Maybe it is time to reevaluate AC &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 12:40:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168921#M28108</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2023-01-24T12:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: In-Line rules, can they 'do nothing' as the last rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168934#M28110</link>
      <description>&lt;P&gt;Yes and no.&amp;nbsp; While the use of that DCE/RPC application-based object will prevent SecureXL templating from being stopped (reported by &lt;STRONG&gt;fwaccel stat&lt;/STRONG&gt;) as opposed to using a simple DCE/RPC service, doing so requires APCL/URLF to be enabled in that first layer along with the Firewall blade.&amp;nbsp; Once you do that&amp;nbsp;&lt;STRONG&gt;fwaccel stat&lt;/STRONG&gt; will report templating "enabled" with no rule stopping it, but the actual live templating rate will always be zero as shown by &lt;STRONG&gt;fwaccel stats -s&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a consequence of using application objects in your first layer along with the Firewall blade and why it is recommended to not invoke APCL/URLF/Content Awareness in the first layer of an ordered implementation, Firewall should be all by itself in that first layer.&amp;nbsp; For inline layers the top/parent layer should only use simple services, while APCL/URLF/Content Awareness objects are only invoked in sub-layers.&lt;/P&gt;
&lt;P&gt;Admittedly I haven't checked this behavior since R80.40 and it may have changed in the latest releases (but I doubt it), will check today.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 13:04:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/In-Line-rules-can-they-do-nothing-as-the-last-rule/m-p/168934#M28110</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-01-24T13:04:22Z</dc:date>
    </item>
  </channel>
</rss>

