<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: edit policies in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196595#M32952</link>
    <description>&lt;P&gt;When rule 5 was enabled, did you ever do zdebug to see why its dropped?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 30 Oct 2023 17:25:05 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-10-30T17:25:05Z</dc:date>
    <item>
      <title>edit policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196594#M32951</link>
      <description>&lt;P&gt;Hello everyone;&lt;BR /&gt;&lt;BR /&gt;I need your help to solve a problem.&lt;BR /&gt;&lt;BR /&gt;After an error message from smartconsol R81.10, I could no longer display the policies&lt;BR /&gt;and I had to reset the FW. i reset it and installed R81.20&lt;/P&gt;&lt;P&gt;this is a diagram of the Network.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="schema réseau.png" style="width: 615px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22988iD49E6BBB9ECF23F2/image-size/large?v=v2&amp;amp;px=999" role="button" title="schema réseau.png" alt="schema réseau.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Interface design.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22990i7718D967DFCDC39E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Interface design.png" alt="Interface design.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;The dhcp server is activated on eth3 on which a cloudkey with access points is connected&lt;BR /&gt;(192.168.2.0).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DHCP serveur.png" style="width: 672px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22989i8A0DA08544DB1B0C/image-size/large?v=v2&amp;amp;px=999" role="button" title="DHCP serveur.png" alt="DHCP serveur.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;The problem is that rule 5 doesn't allow access points to distribute |p addresses to devices.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture d'écran 2023-10-30 090134.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22991i8FA29D483252BA87/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture d'écran 2023-10-30 090134.png" alt="Capture d'écran 2023-10-30 090134.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;When the cleanup rule is "accept" enabled, access points distribute IP addresses, but not when it's "drop"&amp;nbsp;&lt;BR /&gt;when in normal "drop" mode.&lt;BR /&gt;&lt;BR /&gt;I'd like to know how to write the rules so that Pa can distribute addresses to the lan (192.168.2.0) eth3.&lt;/P&gt;&lt;P&gt;thank you&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.deepl.com/translator?utm_source=windows&amp;amp;utm_medium=app&amp;amp;utm_campaign=windows-share" target="_blank" rel="noopener"&gt;Translated with DeepL&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 17:16:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196594#M32951</guid>
      <dc:creator>junior_kakou</dc:creator>
      <dc:date>2023-10-30T17:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: edit policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196595#M32952</link>
      <description>&lt;P&gt;When rule 5 was enabled, did you ever do zdebug to see why its dropped?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 17:25:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196595#M32952</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-30T17:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: edit policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196596#M32953</link>
      <description>&lt;P&gt;this is the resulte after zdebug command&lt;BR /&gt;[Expert@GW-xxxx:0]# zdebug&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;bash: zdebug: command not found&lt;/FONT&gt;&lt;BR /&gt;[Expert@GW-xxxx:0]#&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 17:58:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196596#M32953</guid>
      <dc:creator>junior_kakou</dc:creator>
      <dc:date>2023-10-30T17:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: edit policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196597#M32954</link>
      <description>&lt;P&gt;Thats not how you do it. Say if IP you checking for is 1.2.3.4, you run&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;fw ctl zdebug + drop | grep 1.2.3.4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 18:01:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196597#M32954</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-30T18:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: edit policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196600#M32956</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sortie commande.png" style="width: 805px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22992iBE1A44F758312902/image-size/large?v=v2&amp;amp;px=999" role="button" title="sortie commande.png" alt="sortie commande.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 19:13:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196600#M32956</guid>
      <dc:creator>junior_kakou</dc:creator>
      <dc:date>2023-10-30T19:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: edit policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196604#M32957</link>
      <description>&lt;P&gt;I would do firewall captures to make sure why connection is not completing...ie tcpdump and fw monitor.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 19:58:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196604#M32957</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-30T19:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: edit policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196608#M32959</link>
      <description>&lt;P&gt;Check your routing tables... It appears traffic from source 192.168.2.141 is not going through the firewall, only return traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 20:18:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196608#M32959</guid>
      <dc:creator>Zolocofxp</dc:creator>
      <dc:date>2023-10-30T20:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: edit policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196629#M32966</link>
      <description>&lt;P&gt;Very good point actually.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 01:46:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/edit-policies/m-p/196629#M32966</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-31T01:46:49Z</dc:date>
    </item>
  </channel>
</rss>

