<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practice for Expired rule in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Best-Practice-for-Expired-rule/m-p/219818#M36624</link>
    <description>&lt;P&gt;Depends on the audit. Both ways are good in my opinion.&lt;/P&gt;
&lt;P&gt;Clean them up makes the rulebase more clean and better overview.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also it is in general recommended to remove 0 hit or disabled rules and clean them up.&lt;/P&gt;
&lt;P&gt;But on the other side if traffic has been allowed in the past and you have to show the rule that allowed the traffic you need to still have it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can put the expired time rules within a special section title. Then at least you have them in one spot and with one click you can hide them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some audits require you to keep data for years so it all depends in the audit.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Btw audits go hand in hand with the compliance blade. With this blade you can select certain ISO etc's you want to reflect and it will check the firewall setup. Most of them show that you have to clean disabled and 0 hit rules.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2024 21:05:58 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-07-05T21:05:58Z</dc:date>
    <item>
      <title>Best Practice for Expired rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-Practice-for-Expired-rule/m-p/219695#M36604</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I'm interested in learning best practices for handling time-based firewall rules. In a scenario where a rule is set to automatically expire after a specific timeframe (e.g., 3 days), what's the recommended approach: deleting the rule or keeping it for audit purposes?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 11:23:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-Practice-for-Expired-rule/m-p/219695#M36604</guid>
      <dc:creator>Ihenock1011</dc:creator>
      <dc:date>2024-07-04T11:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice for Expired rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-Practice-for-Expired-rule/m-p/219698#M36605</link>
      <description>&lt;P&gt;I always advise people to disable it for the time being and push policy, so that way if audit happens, at least its there, but not active. Then, you can delete it afterwards.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 11:57:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-Practice-for-Expired-rule/m-p/219698#M36605</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-04T11:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice for Expired rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-Practice-for-Expired-rule/m-p/219818#M36624</link>
      <description>&lt;P&gt;Depends on the audit. Both ways are good in my opinion.&lt;/P&gt;
&lt;P&gt;Clean them up makes the rulebase more clean and better overview.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also it is in general recommended to remove 0 hit or disabled rules and clean them up.&lt;/P&gt;
&lt;P&gt;But on the other side if traffic has been allowed in the past and you have to show the rule that allowed the traffic you need to still have it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can put the expired time rules within a special section title. Then at least you have them in one spot and with one click you can hide them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some audits require you to keep data for years so it all depends in the audit.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Btw audits go hand in hand with the compliance blade. With this blade you can select certain ISO etc's you want to reflect and it will check the firewall setup. Most of them show that you have to clean disabled and 0 hit rules.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 21:05:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-Practice-for-Expired-rule/m-p/219818#M36624</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-05T21:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice for Expired rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-Practice-for-Expired-rule/m-p/219839#M36625</link>
      <description>&lt;P&gt;All valid points.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jul 2024 12:28:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-Practice-for-Expired-rule/m-p/219839#M36625</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-06T12:28:17Z</dc:date>
    </item>
  </channel>
</rss>

