<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CPEarlyDrop Mechanism in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/170000#M28262</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I understand that this mechanism "appears" when you have many "similar" rules, right?&lt;/P&gt;&lt;P&gt;Something like if you have 4 rules, that all work with "Source" and "Destination" as "any", "any", and you just "customize" the services, changing the actions, between "Allow" and "deny".&lt;/P&gt;&lt;P&gt;If you decide to put a 5th rule in the list that has almost the same criteria as the first 4, I understand that the "mechanism" of CPEarlyDrop appears, is this correct?&lt;/P&gt;&lt;P&gt;My question is, when this type of mechanism appears, at the moment of creating an explicit rule, what is the best solution method, to make the traffic match with the rule that I just created, and not with the CPEarlyDrop?&lt;/P&gt;&lt;P&gt;Thanks for your comments.&lt;/P&gt;&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2023 23:34:53 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-02-01T23:34:53Z</dc:date>
    <item>
      <title>CPEarlyDrop Mechanism</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/169977#M28258</link>
      <description>&lt;P&gt;Hello, team.&lt;/P&gt;&lt;P&gt;Could someone enlighten me with the following question.&lt;/P&gt;&lt;P&gt;How does the "mechanism" of "CPEarlyDrop" work?&lt;/P&gt;&lt;P&gt;Sometimes it is really annoying, as I understand a little bit the SK, although not 100%.&lt;/P&gt;&lt;P&gt;I would like to know, what is the best way to avoid "running into" this mechanism, when creating a security rule, to allow or deny an access to certain origin(s) of your network.&lt;/P&gt;&lt;P&gt;I share with you an image of a log of my client's environment, where having created an explicit rule to allow the connection from an origin to a destination, the traffic does not MATCH with this rule, but it does MATCH with the CPEarlyDrop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CPEarly.jpg" style="width: 932px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19387iEAAA7CD4B593E9E5/image-size/large?v=v2&amp;amp;px=999" role="button" title="CPEarly.jpg" alt="CPEarly.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I will be attentive to your kind comments.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 18:48:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/169977#M28258</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-02-01T18:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: CPEarlyDrop Mechanism</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/169996#M28261</link>
      <description>&lt;P&gt;The mechanism is described here:&lt;BR /&gt;&lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111643&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk111643: Early drop of a connection before the final rule match&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;It is well explained in the SK video.&lt;BR /&gt;&lt;BR /&gt;If that is not enough, please describe your question in more detail.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 22:37:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/169996#M28261</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2023-02-01T22:37:38Z</dc:date>
    </item>
    <item>
      <title>Re: CPEarlyDrop Mechanism</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/170000#M28262</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I understand that this mechanism "appears" when you have many "similar" rules, right?&lt;/P&gt;&lt;P&gt;Something like if you have 4 rules, that all work with "Source" and "Destination" as "any", "any", and you just "customize" the services, changing the actions, between "Allow" and "deny".&lt;/P&gt;&lt;P&gt;If you decide to put a 5th rule in the list that has almost the same criteria as the first 4, I understand that the "mechanism" of CPEarlyDrop appears, is this correct?&lt;/P&gt;&lt;P&gt;My question is, when this type of mechanism appears, at the moment of creating an explicit rule, what is the best solution method, to make the traffic match with the rule that I just created, and not with the CPEarlyDrop?&lt;/P&gt;&lt;P&gt;Thanks for your comments.&lt;/P&gt;&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 23:34:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/170000#M28262</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-02-01T23:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: CPEarlyDrop Mechanism</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/170005#M28264</link>
      <description>&lt;P&gt;CPEarlyDrop kicks primarily when multiple rules kick in with similar source/destination, Services that aren't just simple TCP/UDP services, and the action is Drop.&lt;BR /&gt;The "services that aren't simple TCP/UDP services" are key because they require packets beyond the first SYN to make a rulebase match and is when CPEarlyDrop kicks in.&lt;BR /&gt;Rules that involve only simple TCP/UDP services with the action Accept won't be subject to CPEarlyDrop since they can be resolved on the first packet.&lt;/P&gt;
&lt;P&gt;To clean up the problem, you should probably disable (temporarily) the mechanism as described in the SK and see what rules the traffic matches.&lt;BR /&gt;The offending rule(s) should be logged and you can adjust them accordingly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 00:13:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/170005#M28264</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-02T00:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: CPEarlyDrop Mechanism</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/170006#M28265</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One doubt, when you talk about "Simple TCP/UDP services", you are referring to "known ports", for example the 179 which is, as far as I remember the port for BGP, or for example the port for RDP 3389.&lt;/P&gt;&lt;P&gt;Is it these services you are referring to, in your comment?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it a viable option to take the rule I created, and put it at the beginning of the rule base, just to "test" the traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This way I avoid disabling perhaps the CPEarlyDrop mechanism.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 00:29:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/170006#M28265</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-02-02T00:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: CPEarlyDrop Mechanism</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/170013#M28270</link>
      <description>&lt;P&gt;You are correct on both accounts.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 01:46:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CPEarlyDrop-Mechanism/m-p/170013#M28270</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-02T01:46:48Z</dc:date>
    </item>
  </channel>
</rss>

