<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Separate layers of Security Rules vs. APPC + URLF in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Separate-layers-of-Security-Rules-vs-APPC-URLF/m-p/184593#M30751</link>
    <description>&lt;P&gt;When using ordered layers, an Accept rule has to be matched in every layer.&lt;BR /&gt;That means, yes, you will have to create a rule in both layers in your case.&lt;/P&gt;
&lt;P&gt;Unless you're managing pre-R8x gateways, there's no real benefit to having a separate Firewall and App Control/URLF layer.&lt;BR /&gt;In pre-R8x gateways, the cleanup rule on the App Control ruleset was Accept.&lt;BR /&gt;It should only be Drop if you're certain you have rules in both layers to allow all relevant traffic.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Jun 2023 22:43:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-06-22T22:43:49Z</dc:date>
    <item>
      <title>Separate layers of Security Rules vs. APPC + URLF</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Separate-layers-of-Security-Rules-vs-APPC-URLF/m-p/184592#M30750</link>
      <description>&lt;P&gt;Hello, world.&lt;/P&gt;
&lt;P&gt;One question, when you activate the APPC + URLF modules in your Firewall Cluster, and you work these 2 blades, in a separate layer from the Firewall layer, what is the logic regarding the rules?&lt;/P&gt;
&lt;P&gt;The security layer and the APPC+URLF layer have implicit rules that block traffic.&lt;BR /&gt;Is this "order" to be preserved? Or should the implicit rule of one of the layers be "varied"? ????&lt;/P&gt;
&lt;P&gt;If I want to give permissions to an IP 192.168.1.5 to consume only certain "applications" such as "LinkedIN, Youtube, Netflix"?&lt;BR /&gt;This IP must have created, both a rule in the Firewall layer, and 1 rule in the APPC+URLF layer, is it correct????&lt;/P&gt;
&lt;P&gt;The implicit rule, of the APPC+URLF layer, for good practice, as it should be after its activation, as ALLOW or DROP?&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 22:14:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Separate-layers-of-Security-Rules-vs-APPC-URLF/m-p/184592#M30750</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-22T22:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Separate layers of Security Rules vs. APPC + URLF</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Separate-layers-of-Security-Rules-vs-APPC-URLF/m-p/184593#M30751</link>
      <description>&lt;P&gt;When using ordered layers, an Accept rule has to be matched in every layer.&lt;BR /&gt;That means, yes, you will have to create a rule in both layers in your case.&lt;/P&gt;
&lt;P&gt;Unless you're managing pre-R8x gateways, there's no real benefit to having a separate Firewall and App Control/URLF layer.&lt;BR /&gt;In pre-R8x gateways, the cleanup rule on the App Control ruleset was Accept.&lt;BR /&gt;It should only be Drop if you're certain you have rules in both layers to allow all relevant traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 22:43:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Separate-layers-of-Security-Rules-vs-APPC-URLF/m-p/184593#M30751</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-22T22:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Separate layers of Security Rules vs. APPC + URLF</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Separate-layers-of-Security-Rules-vs-APPC-URLF/m-p/184595#M30753</link>
      <description>&lt;P&gt;Sorry, but this comment "It should only be Drop if you're certain you have rules in both layers to allow all relevant traffic", I can't interpret it well.&lt;/P&gt;
&lt;P&gt;My environment is Clusters in R81.10 version.&lt;BR /&gt;The previous administrator inherited me the solution, with "separate layers".&lt;/P&gt;
&lt;P&gt;Maybe with an example it could be clearer.&lt;BR /&gt;If I have an IP 192.168.100.5 and I want to give it to consume, only "LinkedIN and Youtube", I will use "LinkedIN and Youtube".&lt;/P&gt;
&lt;P&gt;I must have a rule, in the security layer, in this sense&lt;BR /&gt;SRC: 192.168.100.5&lt;BR /&gt;DST: ANY&lt;BR /&gt;SERVICE: ANY&lt;/P&gt;
&lt;P&gt;And apart a rule in APPC/URLF, almost in the same sense, except that here I will be able to specify the applications that I want.&lt;BR /&gt;Is this the correct way?&lt;/P&gt;
&lt;P&gt;In this case, the implicit rule of the APPC/URLF layer, how should it go, as ALLOW or DROP?&lt;/P&gt;
&lt;P&gt;Thank you. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 23:28:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Separate-layers-of-Security-Rules-vs-APPC-URLF/m-p/184595#M30753</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-22T23:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Separate layers of Security Rules vs. APPC + URLF</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Separate-layers-of-Security-Rules-vs-APPC-URLF/m-p/184640#M30758</link>
      <description>&lt;P&gt;Most likely the previous administrator upgraded from an earlier release where you HAD to have a separate Firewall and App Control/URLF policy layer (i.e. R77.x gateways were being managed at some point).&lt;BR /&gt;While you can maintain this: policy structure if you prefer, it would be better (and simpler) to combine these policies in the long run.&lt;/P&gt;
&lt;P&gt;In any case, you are correct: you need a rule similar to what you describe in both policies.&lt;BR /&gt;What you use for the default cleanup rule in the App Control policy will depend on whether you are still managing R77.x gateways or not.&lt;BR /&gt;The default cleanup rule MUST be Allow for App Control/URLF layers if you are managing R77.x gateways.&lt;BR /&gt;Otherwise, it can be Drop, but you should be fairly certain you have explicit rules defined for all traffic you wish to permit in the App Control layer.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 14:53:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Separate-layers-of-Security-Rules-vs-APPC-URLF/m-p/184640#M30758</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-23T14:53:51Z</dc:date>
    </item>
  </channel>
</rss>

