<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Implied rules and dynamic objects in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/209767#M34744</link>
    <description>&lt;P&gt;I believe they simply refer to mgmt and fw object(s), but I could be mistaken.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 27 Mar 2024 00:49:29 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-03-27T00:49:29Z</dc:date>
    <item>
      <title>Implied rules and dynamic objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/209752#M34738</link>
      <description>&lt;P&gt;I've been playing with Implied Rules in my lab. Currently have things set like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Implied rules config.jpg" style="width: 502px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25034i3DF14FDE058E0747/image-dimensions/502x336?v=v2" width="502" height="336" role="button" title="Implied rules config.jpg" alt="Implied rules config.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;With this set, these rules appear (among others):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Implied Rules list.jpg" style="width: 740px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25035i8E54975087896B9D/image-dimensions/740x215?v=v2" width="740" height="215" role="button" title="Implied Rules list.jpg" alt="Implied Rules list.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;(we have generally stayed away from implied rules - those rules with source "Any" make me uncomfortable).&lt;/P&gt;
&lt;P&gt;My specific question - is there a published list of what all these dynamic objects (e.g. FW1 Management, FW1 Module) are? Is there a way to resolve them on the gateway? (dynamic_objects command doesn't seem to help).&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 19:33:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/209752#M34738</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2024-03-26T19:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and dynamic objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/209767#M34744</link>
      <description>&lt;P&gt;I believe they simply refer to mgmt and fw object(s), but I could be mistaken.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 00:49:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/209767#M34744</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-27T00:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and dynamic objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/209831#M34749</link>
      <description>&lt;P&gt;Most of these are somewhat self-explanatory, at least to someone who has been working with Check Point for some time. However, if we enable implied rules in production, we will need to provide a&amp;nbsp;&lt;STRONG&gt;vendor provided&lt;/STRONG&gt; explanation of what these objects represent, since they will be part of our access policy. Here's a list of the objects in the implied rules based on my config above:&lt;/P&gt;
&lt;P&gt;According to Gateway MTA Settings&lt;BR /&gt;MTA enabled Gateways&lt;BR /&gt;According to Gateway ICAP Settings&lt;BR /&gt;ICAP enabled Gateways&lt;BR /&gt;Analyzer Server&lt;BR /&gt;FW1 Management&lt;BR /&gt;FW1 Module&lt;BR /&gt;Log Servers&lt;BR /&gt;RT-Physical-Servers&lt;BR /&gt;Ldap-Servers&lt;BR /&gt;Tacacs-Servers&lt;BR /&gt;Radius-Servers&lt;BR /&gt;UFP-Servers&lt;BR /&gt;CVP-Servers&lt;BR /&gt;LocalMachine&lt;BR /&gt;NG Policy Server&lt;BR /&gt;Reporting Server&lt;BR /&gt;SmartPortal&lt;BR /&gt;Gui-clients&lt;/P&gt;
&lt;P&gt;CPMI-clients&lt;/P&gt;
&lt;P&gt;In general, I know enabling implied rules is considered best/recommended practice (by Check Point support), but again, rules with a source of "any" does not strike me as best security practice.&amp;nbsp; Feedback welcome.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 13:35:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/209831#M34749</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2024-03-27T13:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and dynamic objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/209833#M34750</link>
      <description>&lt;P&gt;I get your point. Honestly, if I were you, I would try get an official TAC answer for this.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just my 2 cents...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 14:00:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/209833#M34750</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-27T14:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and dynamic objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/209999#M34773</link>
      <description>&lt;P&gt;Andy,&lt;/P&gt;
&lt;P&gt;Good suggestion, and I've opened a case. Surprised there isn't documentation around this, but not the first time I've been surprised by similar lack of documentation.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2024 13:39:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/209999#M34773</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2024-03-29T13:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and dynamic objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/210025#M34775</link>
      <description>&lt;P&gt;Ticket has been opened and support directed me to sk17745, which provides some information. It's not complete (and honestly doesn't really answer the question I asked) but it's a start. I also found these interesting implied rules that are created when you enable "Accept Control connections"&lt;/P&gt;
&lt;DIV id="tinyMceEditor_63fd4f61652f6cDavid_C1_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="implied rule.jpg" style="width: 764px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25083i8B3FFEB9F00413C6/image-dimensions/764x107?v=v2" width="764" height="107" role="button" title="implied rule.jpg" alt="implied rule.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Why interesting?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="services.jpg" style="width: 774px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25084iC9E0FD77D2EF6D10/image-dimensions/774x89?v=v2" width="774" height="89" role="button" title="services.jpg" alt="services.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Either sk52421 is inaccurate or Check Point is enabling rules for services that have not been supported since the stone age.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2024 17:38:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/210025#M34775</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2024-03-29T17:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and dynamic objects</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/210029#M34776</link>
      <description>&lt;P&gt;You really got me curious about it now too. I clicked help section when viewing implied rules and link that comes up is this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/SmartConsole_OLH/EN/Topics-OLH/E-_rdHN2etpvAKaSBr1fSA2.htm?cshid=E-_rdHN2etpvAKaSBr1fSA2" target="_blank"&gt;Implied Policy - Rules (checkpoint.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;On that link, you get directed to below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk119497" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk119497&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2024 18:40:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-dynamic-objects/m-p/210029#M34776</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-29T18:40:40Z</dc:date>
    </item>
  </channel>
</rss>

