<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about optimizing policies in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Question-about-optimizing-policies/m-p/269476#M45258</link>
    <description>&lt;P&gt;Personally bro, but this is just me, I always create inline layers where needed and use ordered layers as well. Make sure to disable any unused rules (or delete them if 100% sure no hits). Hope my post below helps.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Lab-setup-video/m-p/268062" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Lab-setup-video/m-p/268062&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Happy to show you all this in smart console as well, though video explains it pretty well (I would say). I also attached simple word doc about it as well.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Feb 2026 19:29:52 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2026-02-02T19:29:52Z</dc:date>
    <item>
      <title>Question about optimizing policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-optimizing-policies/m-p/269450#M45248</link>
      <description>&lt;P&gt;Hi Mates,&lt;BR /&gt;What is the best way to optimize security policies, especially in a datacenter environment? (Large policy-package)&lt;BR data-start="194" data-end="197" /&gt;Are there any best practices that should be followed?&lt;BR /&gt;If I have a rule with “Any” as the protocol, what is the best way to analyze and optimize it?&lt;BR /&gt;Are there any tools integrated with Check Point that can help?&lt;BR /&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 16:11:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-optimizing-policies/m-p/269450#M45248</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-02-02T16:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Question about optimizing policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-optimizing-policies/m-p/269459#M45253</link>
      <description>&lt;P&gt;Some thoughts knowing that in huge policy packages it could be extremely hard work:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;General / Structure&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Move most-used rules (high hit count) to the top&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Place specific rules before general ones&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Broad rules (Any / large networks) towards the bottom&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Use clear sections / inline layers for readability&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Analysis &amp;amp; Maintenance&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Zero-hit rules:&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;verify (shadowed vs. obsolete)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;remove or disable&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Merge duplicate or overlapping rules&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Maintain comments (rule purpose / business context)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Performance &amp;amp; Logging&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;High-hit allow rules: consider Track = None if logging not absolutely necessary&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Log selectively, not everywhere&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Tips to get rid of “Any” rules&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Temporarily enable logging on the Any rule&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Analyze in SmartLog / SmartEvent:&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;which ports&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;which applications&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Split the rule:&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;explicit services (e.g. TCP 443, 22)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;or Application Control instead of ports&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Use Policy Optimizer for automatic suggestions (Tufin, AlgoSec or similar)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Monitor after changes, then remove the Any rule&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 16:53:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-optimizing-policies/m-p/269459#M45253</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-02-02T16:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: Question about optimizing policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-optimizing-policies/m-p/269470#M45257</link>
      <description>&lt;P&gt;We have something called &lt;A href="https://community.checkpoint.com/t5/General-Topics/Policy-Insights-Your-AI-Powered-Firewall-Assistant/m-p/264968" target="_self"&gt;Policy Insights&lt;/A&gt; that can help with this.&lt;BR /&gt;It is a paid feature available in our AI Management bundles (appropriate SKUs are here&amp;nbsp;&lt;A href="https://www.checkpoint.com/resources/items/solution-brief-ai-powered-security-management-for-the-hyperconnected-world" target="_blank"&gt;https://www.checkpoint.com/resources/items/solution-brief-ai-powered-security-management-for-the-hyperconnected-world&lt;/A&gt;&amp;nbsp;).&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 18:25:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-optimizing-policies/m-p/269470#M45257</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-02-02T18:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: Question about optimizing policies</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-optimizing-policies/m-p/269476#M45258</link>
      <description>&lt;P&gt;Personally bro, but this is just me, I always create inline layers where needed and use ordered layers as well. Make sure to disable any unused rules (or delete them if 100% sure no hits). Hope my post below helps.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Lab-setup-video/m-p/268062" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Lab-setup-video/m-p/268062&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Happy to show you all this in smart console as well, though video explains it pretty well (I would say). I also attached simple word doc about it as well.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 19:29:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-optimizing-policies/m-p/269476#M45258</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-02T19:29:52Z</dc:date>
    </item>
  </channel>
</rss>

