<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How layered policies are matched | FW, APP, URL in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242542#M40523</link>
    <description>&lt;P&gt;Hey brother,&lt;/P&gt;
&lt;P&gt;Remember what I said on the remote sesison about this? Traffic HAS TO match on ALL ordered layers. So say you have 2 layers and its accepted on first layer, but dropped on 2nd layer, it will not work. If you need more help, we can do another remote as well. In your case, if it is indeed 2 layers, I would do any any allow at the bottom of 2nd layer&amp;nbsp; and then block whatever needed above.&lt;/P&gt;
&lt;P&gt;1) They are match top to bottom, left to right&lt;/P&gt;
&lt;P&gt;2) Thats how it works for layered rules, traffic has to traverse all layered rules to be accepted&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Partner-Community/Layered-rules-approach/m-p/242051" target="_blank"&gt;https://community.checkpoint.com/t5/Partner-Community/Layered-rules-approach/m-p/242051&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Feb 2025 13:14:04 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-02-27T13:14:04Z</dc:date>
    <item>
      <title>How layered policies are matched | FW, APP, URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242528#M40521</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;I was testing the layered policy approach and got confused a bit. I have created separate layers for FW and APP blade. In my admin access I have allowed SSH access to the FW but I was unable to do so.&lt;/P&gt;&lt;P&gt;When I checked it was hitting the cleanup in the APP layer policy, can somebody help me out with this.&lt;/P&gt;&lt;P&gt;1&amp;gt; How are the policies matched?&lt;/P&gt;&lt;P&gt;2&amp;gt; If the FW layer rule 1 allows the access then why is it coming to the APP layer.&lt;/P&gt;&lt;P&gt;Please help me on this!!!&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;WR,&lt;/P&gt;&lt;P&gt;FH&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 10:40:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242528#M40521</guid>
      <dc:creator>Firewall_Head</dc:creator>
      <dc:date>2025-02-27T10:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: How layered policies are matched | FW, APP, URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242542#M40523</link>
      <description>&lt;P&gt;Hey brother,&lt;/P&gt;
&lt;P&gt;Remember what I said on the remote sesison about this? Traffic HAS TO match on ALL ordered layers. So say you have 2 layers and its accepted on first layer, but dropped on 2nd layer, it will not work. If you need more help, we can do another remote as well. In your case, if it is indeed 2 layers, I would do any any allow at the bottom of 2nd layer&amp;nbsp; and then block whatever needed above.&lt;/P&gt;
&lt;P&gt;1) They are match top to bottom, left to right&lt;/P&gt;
&lt;P&gt;2) Thats how it works for layered rules, traffic has to traverse all layered rules to be accepted&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Partner-Community/Layered-rules-approach/m-p/242051" target="_blank"&gt;https://community.checkpoint.com/t5/Partner-Community/Layered-rules-approach/m-p/242051&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 13:14:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242542#M40523</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-27T13:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: How layered policies are matched | FW, APP, URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242545#M40524</link>
      <description>&lt;P&gt;If you wish to do another quick zoom remote, Im good till 7.30 pm your time, or between 10.30-11.30&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 13:21:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242545#M40524</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-27T13:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: How layered policies are matched | FW, APP, URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242556#M40528</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you sm for the reply, let's do a remote at 10.40 PM IST.&lt;BR /&gt;&lt;BR /&gt;====&lt;/P&gt;&lt;P&gt;WR,&lt;/P&gt;&lt;P&gt;FH&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 14:22:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242556#M40528</guid>
      <dc:creator>Firewall_Head</dc:creator>
      <dc:date>2025-02-27T14:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: How layered policies are matched | FW, APP, URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242558#M40530</link>
      <description>&lt;P&gt;Sounds good, will send you zoom for that time 10 mins before.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 14:25:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242558#M40530</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-27T14:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: How layered policies are matched | FW, APP, URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242571#M40535</link>
      <description>&lt;P&gt;Sent you link directly.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 16:59:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242571#M40535</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-27T16:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: How layered policies are matched | FW, APP, URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242573#M40537</link>
      <description>&lt;P&gt;Just to update, had quick remote with the guys and I explained that traffic has to be accepted on EVERY ordered layer and whatever is dropped on the network (1st layer), wont need to go through any other layer.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 17:22:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242573#M40537</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-27T17:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: How layered policies are matched | FW, APP, URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242579#M40539</link>
      <description>&lt;P&gt;Thank you so much Andy&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; !&lt;/P&gt;&lt;P&gt;========&lt;BR /&gt;WR,&lt;/P&gt;&lt;P&gt;FH&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 17:34:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242579#M40539</guid>
      <dc:creator>Firewall_Head</dc:creator>
      <dc:date>2025-02-27T17:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: How layered policies are matched | FW, APP, URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242580#M40540</link>
      <description>&lt;P&gt;No problem! Now that I had some garlic naan bread, I feel better, haha.&lt;/P&gt;
&lt;P&gt;Cheers mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 17:35:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242580#M40540</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-27T17:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: How layered policies are matched | FW, APP, URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242583#M40541</link>
      <description>&lt;P&gt;Suggest you read the following community posts (they're older, but still relevant)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Unified-Policy-Column-based-Rule-Matching/m-p/9888#M1693" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Unified-Policy-Column-based-Rule-Matching/m-p/9888#M1693&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Policy-Layers-in-R80-x/td-p/1717" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Policy-Layers-in-R80-x/td-p/1717&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;TL;DR: If you have multiple ordered layers, traffic must match an accept rule in each layer, otherwise the traffic will not pass.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 17:47:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242583#M40541</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-27T17:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: How layered policies are matched | FW, APP, URL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242584#M40542</link>
      <description>&lt;P&gt;Thats pretty much what I showed the guys in my lab, so Im 100% sure they are clear now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 18:03:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-layered-policies-are-matched-FW-APP-URL/m-p/242584#M40542</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-27T18:03:16Z</dc:date>
    </item>
  </channel>
</rss>

