<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBR Behavior for Gaia WebUI in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/PBR-Behavior-for-Gaia-WebUI/m-p/197527#M33091</link>
    <description>&lt;P&gt;"Locally-generated traffic" is a PBR limitation per&amp;nbsp;&lt;SPAN&gt;sk167135.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;VSX or MDPS may help achieve the separation that you desire.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Nov 2023 23:06:09 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-11-08T23:06:09Z</dc:date>
    <item>
      <title>PBR Behavior for Gaia WebUI</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PBR-Behavior-for-Gaia-WebUI/m-p/197522#M33090</link>
      <description>&lt;P&gt;Without having a separate VRF for Management traffic I have added PBR rules to facilitate this for the Management interface which is connected to a downstream router that does the L3 routing for Internal networks.&amp;nbsp; &amp;nbsp;It is a simple PBR matching the source IP of the Management interface 10.254.254.61 and the 10.253.253.0/24 destination network where a client would be sourcing Management traffic ( HTTPS,SSH)&amp;nbsp; The action table is also simple where the route back to the 10.253.253.0/24 destination network has next hop gateway IP 10.254.254.1 of the downstream router that the Checkpoint Management interface is connected to ( out-of-band from normal data traffic ).&amp;nbsp; Of course there is a more generic route configured on the firewall for the internal private IP subnets pointing to the downstream router on a separate transit interface.&amp;nbsp; The interesting part is that SSH management traffic gets routed appropriately via the PBR, so traffic ingresses the&amp;nbsp; Management interface and egresses the Management interface.&amp;nbsp; However management Gaia Webui 443 traffic does NOT seem to follow the PBR, instead the traffic ingresses the Management interface and egresses the transit interface with the more generic route.&amp;nbsp; I have verified the traffic flows via fw monitor and disabled/enabled SecureXL just to make sure.&amp;nbsp; The PBR does not define service ports.&amp;nbsp; Any ideas?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R81.10 T110 on 6400 Cluster&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 23:04:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PBR-Behavior-for-Gaia-WebUI/m-p/197522#M33090</guid>
      <dc:creator>Yeti</dc:creator>
      <dc:date>2023-11-08T23:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: PBR Behavior for Gaia WebUI</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PBR-Behavior-for-Gaia-WebUI/m-p/197527#M33091</link>
      <description>&lt;P&gt;"Locally-generated traffic" is a PBR limitation per&amp;nbsp;&lt;SPAN&gt;sk167135.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;VSX or MDPS may help achieve the separation that you desire.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 23:06:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PBR-Behavior-for-Gaia-WebUI/m-p/197527#M33091</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-08T23:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: PBR Behavior for Gaia WebUI</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PBR-Behavior-for-Gaia-WebUI/m-p/197528#M33092</link>
      <description>&lt;P&gt;I did review this SK but wasn't sure if this particular scenario is considered as locally generated as the session is sourced outside of the firewall.&amp;nbsp; Any reasons for only SSH working ?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 23:11:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PBR-Behavior-for-Gaia-WebUI/m-p/197528#M33092</guid>
      <dc:creator>Yeti</dc:creator>
      <dc:date>2023-11-08T23:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: PBR Behavior for Gaia WebUI</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PBR-Behavior-for-Gaia-WebUI/m-p/200716#M33478</link>
      <description>&lt;P&gt;Is there any plan to resolve the Local-generated traffic&amp;nbsp; limitation?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 11:28:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PBR-Behavior-for-Gaia-WebUI/m-p/200716#M33478</guid>
      <dc:creator>Luis_Miguel_Mig</dc:creator>
      <dc:date>2023-12-15T11:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: PBR Behavior for Gaia WebUI</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PBR-Behavior-for-Gaia-WebUI/m-p/200768#M33479</link>
      <description>&lt;P&gt;I recommend approaching your local Check Point office with an RFE if this is needed.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 18:55:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PBR-Behavior-for-Gaia-WebUI/m-p/200768#M33479</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-15T18:55:57Z</dc:date>
    </item>
  </channel>
</rss>

