<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Difference between interface based and zone based firewall? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-interface-based-and-zone-based-firewall/m-p/4191#M330</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;like to know the difference between interface based and zone based firewall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 15 Jul 2017 06:33:57 GMT</pubDate>
    <dc:creator>yoganand_i</dc:creator>
    <dc:date>2017-07-15T06:33:57Z</dc:date>
    <item>
      <title>Difference between interface based and zone based firewall?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-interface-based-and-zone-based-firewall/m-p/4191#M330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;like to know the difference between interface based and zone based firewall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Jul 2017 06:33:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Difference-between-interface-based-and-zone-based-firewall/m-p/4191#M330</guid>
      <dc:creator>yoganand_i</dc:creator>
      <dc:date>2017-07-15T06:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between interface based and zone based firewall?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Difference-between-interface-based-and-zone-based-firewall/m-p/4192#M331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It comes down to how the policy is defined.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In a zone-based firewall I can say "everything that comes from this interface should be treated this way" without worrying about the IP addresses at all.&lt;/P&gt;&lt;P&gt;You can achieve the same thing in an interface-based firewall, but you have to know (and define) every IP address reachable from that firewall.&lt;/P&gt;&lt;P&gt;Which, in complex environments with dynamic routing, can be a challenge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check Point did not support using zones in the firewall policy until R80.10 (except on SMB appliances, where this has been supported for a while).&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, even in R80.10, interface Anti-spoofing and NAT rules still have to be defined in terms of IP addresses--something that should be addressed in future releases.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Jul 2017 15:54:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Difference-between-interface-based-and-zone-based-firewall/m-p/4192#M331</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-07-15T15:54:35Z</dc:date>
    </item>
  </channel>
</rss>

