<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic does not match with explicit rule in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186913#M31242</link>
    <description>&lt;P&gt;Maybe try disable,re-enable rule,push policy and test. Otherwise, try below example&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jul 2023 17:58:03 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-07-19T17:58:03Z</dc:date>
    <item>
      <title>Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186893#M31230</link>
      <description>&lt;P&gt;Hello, Team&lt;BR /&gt;&lt;BR /&gt;I have the following scenario, which I would like to clarify my doubt.&lt;/P&gt;
&lt;P&gt;I have a Cluster R81.10&lt;/P&gt;
&lt;P&gt;We have a publication of a service, so that from the Internet (From certain public IPs, can access our service pointing to a TCP port 1122)&lt;/P&gt;
&lt;P&gt;The problem I see is that the traffic is not doing MATCH with the first explicit rule that I have, which has the #585, but is doing MATCH with a rule that is below with #594, and I do not understand the "why", because the first rule has a "custom" group where we are explicitly declaring the IP that we want to connect to our server, but for some reason, the traffic "ignores" the first rule, and goes to the rule that is below.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="R3.png" style="width: 647px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21794i2ECB4211BE5691E5/image-size/large?v=v2&amp;amp;px=999" role="button" title="R3.png" alt="R3.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="R2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21793iB9291E572F044B63/image-size/large?v=v2&amp;amp;px=999" role="button" title="R2.png" alt="R2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="R1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21792iBDF1BD86A08A4060/image-size/large?v=v2&amp;amp;px=999" role="button" title="R1.png" alt="R1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Is this a normal behavior? Is it something that can be corrected?&lt;/P&gt;
&lt;P&gt;The purpose is that the traffic makes MATCH with the 585.&lt;/P&gt;
&lt;P&gt;I hope you can support me with your point of view.&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 16:59:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186893#M31230</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-19T16:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186903#M31236</link>
      <description>&lt;P&gt;The reason I see is that one has source any.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:24:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186903#M31236</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-19T17:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186907#M31238</link>
      <description>&lt;P&gt;Buddy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But rule #585, is much more explicit than rule #594, other than that, it is more "up" in the rulebase.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't see the logic in it. &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:34:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186907#M31238</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-19T17:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186909#M31240</link>
      <description>&lt;P&gt;K, so whats the source IP you are coming from and is it included in that group in rule 585?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:48:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186909#M31240</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-19T17:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186912#M31241</link>
      <description>&lt;P&gt;Rule #585, has as its origin a general group.&lt;BR /&gt;The group is called GRP_SFTP_200.48.202.52.&lt;/P&gt;
&lt;P&gt;Within this group, there are several additional "subgroups", 1 of them is the group GRP_RE, in which there are several public IPs to which we are allowing access to our public one.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="R3.png" style="width: 647px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21796i094F16E14EE0D6FF/image-size/large?v=v2&amp;amp;px=999" role="button" title="R3.png" alt="R3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="R1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21797i3B4DA712D3A12A2D/image-size/large?v=v2&amp;amp;px=999" role="button" title="R1.png" alt="R1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So, I do not understand why the traffic "ignores" this rule, and goes to the rule that has as origin an ANY.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:55:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186912#M31241</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-19T17:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186913#M31242</link>
      <description>&lt;P&gt;Maybe try disable,re-enable rule,push policy and test. Otherwise, try below example&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:58:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186913#M31242</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-19T17:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186914#M31243</link>
      <description>&lt;P&gt;That's like a Cisco Packet-Tracert, isn't it?&lt;/P&gt;
&lt;P&gt;To validate the rule for certain traffic?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 18:00:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186914#M31243</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-19T18:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186915#M31244</link>
      <description>&lt;P&gt;Sort of...&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 18:05:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186915#M31244</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-19T18:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186917#M31245</link>
      <description>&lt;P&gt;I got almost the same result as what can be seen by the SmartConsole.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="R4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21798iEA698AD1F984D15E/image-size/large?v=v2&amp;amp;px=999" role="button" title="R4.png" alt="R4.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As I interpret it, it first "matches" rule #585.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 18:11:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186917#M31245</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-19T18:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186922#M31246</link>
      <description>&lt;P&gt;Thats what it shows, right...BUT, as I said, if it fails, I would try what I found to be easy fix in the past. Disable rule 585, push policy, re-enable, push policy. If that fails, disable rule 594, push policy and test. Does traffic get dropped?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 18:45:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186922#M31246</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-19T18:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186947#M31250</link>
      <description>&lt;P&gt;We have not observed "traffic down", but for auditing purposes, the traffic should match the rule that has been defined for it (Rule #585).&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 00:12:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186947#M31250</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-20T00:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186948#M31251</link>
      <description>&lt;P&gt;I agree bro, you are 100% right. I cant see why its not catching that rule, UNLESS there is some sort of nat or something causing it. If not, then I would get in touch with TAC to solve it via remote session. Before that, try my suggestion and see what happens.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 00:24:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/186948#M31251</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-20T00:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic does not match with explicit rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/187035#M31264</link>
      <description>&lt;P&gt;This is probably going to require the TAC to investigate.&lt;BR /&gt;&lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 12:30:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-does-not-match-with-explicit-rule/m-p/187035#M31264</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-20T12:30:32Z</dc:date>
    </item>
  </channel>
</rss>

