<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Rule does not work in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216391#M35974</link>
    <description>&lt;P&gt;In your screenshot&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/68655"&gt;@Roadrunner88&lt;/a&gt;&amp;nbsp;, it shows name as tcp 15672, NOT 15000, unless you are trying to trick us with the name &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Can you verify what is the actual post number?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jun 2024 14:34:11 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-06-04T14:34:11Z</dc:date>
    <item>
      <title>Policy Rule does not work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216357#M35957</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have a Policy with a Rule allowing traffic to single TCP port: 15672&lt;BR /&gt;&lt;BR /&gt;This rule does not work, I suppose because we have er Service object, TCP-High-Ports (Includes Port range 1024 - 65535), this is shown in the log. So the Policy does not use the Selected TCP Port 15672 but uses this object, which isnt defined in this dedicated rule anbd the traffic is dropped.&lt;BR /&gt;&lt;BR /&gt;How can we fix this?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 05:24:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216357#M35957</guid>
      <dc:creator>Roadrunner88</dc:creator>
      <dc:date>2024-06-05T05:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rule does not work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216358#M35958</link>
      <description>&lt;P&gt;I can neither see the rule nor your rule base - so better open an SR# with CP TAC to get this resolved !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 12:44:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216358#M35958</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-06-04T12:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rule does not work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216364#M35960</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26073i8018CEC7B905C7C8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cp1.png" alt="cp1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; TCP Port is defined in rule number 32&lt;BR /&gt;&lt;BR /&gt;But Traffic passes on temp any any rule number 38 as service object "tcp-high-ports"&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26074iE736F02CA841E085/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cp2.png" alt="cp2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp3.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26076iAE68544C6EC7CBD5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cp3.png" alt="cp3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;BR /&gt;&lt;BR /&gt;it should pass by rule 32 not 38 already&lt;BR /&gt;&lt;BR /&gt;the blacked parts of the rules are correct, the traffic should go over rule 32.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 12:57:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216364#M35960</guid>
      <dc:creator>Roadrunner88</dc:creator>
      <dc:date>2024-06-04T12:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rule does not work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216386#M35972</link>
      <description>&lt;P&gt;The service shown in the log doesn't correspond to anything. The actual log entry only has the port number. SmartConsole then takes that port number and tries to resolve it to an object name to be helpful. You can totally ignore the object name shown there.&lt;/P&gt;
&lt;P&gt;In your original post, you mention the port at issue is 15600. The service in the rule you have shared is named 15672, implying it matches that port rather than 15600. Which port are you actually trying to match? Are you sure the service object in the rule matches that port? Ignore the name of the service object and only look at the contents.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 14:24:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216386#M35972</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-06-04T14:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rule does not work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216391#M35974</link>
      <description>&lt;P&gt;In your screenshot&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/68655"&gt;@Roadrunner88&lt;/a&gt;&amp;nbsp;, it shows name as tcp 15672, NOT 15000, unless you are trying to trick us with the name &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Can you verify what is the actual post number?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 14:34:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216391#M35974</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-04T14:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rule does not work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216454#M35994</link>
      <description>&lt;P&gt;yes I wanted to anonymise a little bit but doesnt matter, the point is the same...&lt;BR /&gt;&lt;BR /&gt;what do you mean by the post number?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;the port is written in rule 32 but the firewall does not use this rule , but uses the any any rule with this high port range.&lt;BR /&gt;&lt;BR /&gt;source and destination in rule 32 is correct.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 05:28:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216454#M35994</guid>
      <dc:creator>Roadrunner88</dc:creator>
      <dc:date>2024-06-05T05:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rule does not work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216533#M36010</link>
      <description>&lt;P&gt;If the traffic is not matching an access rule, then one of four things is happening. Either:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The source of the traffic is not in the source of the rule&lt;/LI&gt;
&lt;LI&gt;The destination of the traffic is not in the destination of the rule&lt;/LI&gt;
&lt;LI&gt;The service of the traffic is not in the service of the rule&lt;/LI&gt;
&lt;LI&gt;The rule is not on the firewall in question&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;One of those four items is the cause 99.999% of the time traffic doesn't match an access rule someone expects. Check the values of the objects in the rule, not the names. Make sure the firewall is in the "Install On" column, or that column is set to Policy Targets and the policy's installation targets includes the firewall. Make sure the policy has been pushed.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:01:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216533#M36010</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-06-05T14:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rule does not work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216535#M36012</link>
      <description>&lt;P&gt;I meant port number, what is the post number in that service?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216535#M36012</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-05T14:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Rule does not work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216537#M36013</link>
      <description>&lt;P&gt;Valid points, but sometimes even with those conditions, rule might not get matched.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:03:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Policy-Rule-does-not-work/m-p/216537#M36013</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-05T14:03:31Z</dc:date>
    </item>
  </channel>
</rss>

