<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which Layer Takes Precedence? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Which-Layer-Takes-Precedence/m-p/249499#M41719</link>
    <description>&lt;P&gt;Look at this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Order of Rule Enforcement in Ordered&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_laypols variable"&gt;Layers&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;When a packet arrives at the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;checks it against the rules in the first Ordered&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_laypol variable"&gt;Layer&lt;/SPAN&gt;, sequentially from top to bottom, and enforces the first rule that matches a packet.&lt;/P&gt;
&lt;P&gt;If the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Action&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of the matching rule is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Drop&lt;/SPAN&gt;, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;stops matching against later rules in the Policy&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_rule variable"&gt;Rule Base&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and drops the packet. If the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Action&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Accept&lt;/SPAN&gt;, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;continues to check rules in the next Ordered&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_laypol variable"&gt;Layer&lt;/SPAN&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 21 May 2025 13:18:23 GMT</pubDate>
    <dc:creator>Tal_Paz-Fridman</dc:creator>
    <dc:date>2025-05-21T13:18:23Z</dc:date>
    <item>
      <title>Which Layer Takes Precedence?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Which-Layer-Takes-Precedence/m-p/249498#M41718</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;I need clarification on rule evaluation when using Ordered Layers (Access Control + Application Control).&lt;/P&gt;
&lt;P&gt;Here’s the scenario:&lt;/P&gt;
&lt;P&gt;In the Access Control layer (e.g. rule #25), I allow traffic from 192.168.10.2 to the "Internet" object.&lt;/P&gt;
&lt;P&gt;In the Application Control layer (e.g. rule #5), I drop traffic from the same IP to the category "Gambling or malicious site".&lt;/P&gt;
&lt;P&gt;If 192.168.10.2 tries to access a malicious site:&lt;BR /&gt;My question is simple:&lt;BR /&gt;Which rule takes precedence?&lt;BR /&gt;Does the final action follow the Drop in the Application Control layer, even though Access Control allowed it?&lt;/P&gt;
&lt;P&gt;I want to confirm if traffic must be accepted by all layers to be ultimately allowed, meaning any Drop overrides previous Accepts, correct?&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 13:06:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Which-Layer-Takes-Precedence/m-p/249498#M41718</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-05-21T13:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Which Layer Takes Precedence?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Which-Layer-Takes-Precedence/m-p/249499#M41719</link>
      <description>&lt;P&gt;Look at this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Order of Rule Enforcement in Ordered&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_laypols variable"&gt;Layers&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;When a packet arrives at the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;checks it against the rules in the first Ordered&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_laypol variable"&gt;Layer&lt;/SPAN&gt;, sequentially from top to bottom, and enforces the first rule that matches a packet.&lt;/P&gt;
&lt;P&gt;If the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Action&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of the matching rule is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Drop&lt;/SPAN&gt;, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;stops matching against later rules in the Policy&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_rule variable"&gt;Rule Base&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and drops the packet. If the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Action&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Accept&lt;/SPAN&gt;, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;continues to check rules in the next Ordered&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_laypol variable"&gt;Layer&lt;/SPAN&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 13:18:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Which-Layer-Takes-Precedence/m-p/249499#M41719</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2025-05-21T13:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Which Layer Takes Precedence?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Which-Layer-Takes-Precedence/m-p/249500#M41720</link>
      <description>&lt;P&gt;Thank you buddy&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 13:24:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Which-Layer-Takes-Precedence/m-p/249500#M41720</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-05-21T13:24:38Z</dc:date>
    </item>
  </channel>
</rss>

