<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UP kernel chain and policy enforcement in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1643#M46</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no new chain module for Unified Policy.&lt;/P&gt;&lt;P&gt;Unified Policy is enforced for first packet in the VM chain module (where security rule base was enforced before).&lt;/P&gt;&lt;P&gt;Since Unified Policy rulebase might not be finally matched on SYN packets, followed rulebase execution will be done on various parser contexts (blade dependent - e.g: HTTP_1ST_RESPONSE for Application Control blade).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 17 Jan 2016 15:39:47 GMT</pubDate>
    <dc:creator>Oded_Bergman</dc:creator>
    <dc:date>2016-01-17T15:39:47Z</dc:date>
    <item>
      <title>UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1642#M45</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please advise which chain module is enforcing security policy on the GW for unified policy case? Is it only up chain? What are the roles of fw vm chains in R80 GW?&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Dec 2015 13:08:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1642#M45</guid>
      <dc:creator />
      <dc:date>2015-12-23T13:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1643#M46</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no new chain module for Unified Policy.&lt;/P&gt;&lt;P&gt;Unified Policy is enforced for first packet in the VM chain module (where security rule base was enforced before).&lt;/P&gt;&lt;P&gt;Since Unified Policy rulebase might not be finally matched on SYN packets, followed rulebase execution will be done on various parser contexts (blade dependent - e.g: HTTP_1ST_RESPONSE for Application Control blade).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Jan 2016 15:39:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1643#M46</guid>
      <dc:creator>Oded_Bergman</dc:creator>
      <dc:date>2016-01-17T15:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1644#M47</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, &lt;A href="https://community.checkpoint.com/migrated-users/2046"&gt;Oded Bergman&lt;/A&gt;, indeed there is no chain module named UP. My original question was badly worded. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please allow me to rephrase. There is a new kernel debug module UP. If my understanding is correct, it can print out kernel decisions related to enforcement of Unified Policies. Could you please advise if it is related to fw VM or also other chain modules? &lt;SPAN style="text-decoration: underline;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jan 2016 08:36:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1644#M47</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2016-01-18T08:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1645#M48</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apparently this question was not answered, so I'm unmarking it from being correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Apr 2016 14:13:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1645#M48</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2016-04-08T14:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1646#M49</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the question is not answered. Thanks, Tomer. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Apr 2016 16:06:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1646#M49</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2016-04-08T16:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1647#M50</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Correct, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;UP is a new module including its own kernel debug flags.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;UP debug in kernel include Unified Rulebase executions and enforcement. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Regarding chain modules, the only chain module UP is being executed from is the VM chain module.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2016 15:18:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1647#M50</guid>
      <dc:creator>Tal_Ben_Avraham</dc:creator>
      <dc:date>2016-04-11T15:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1648#M51</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot. One last question. Does it compliment the regular stateful inspection / rule base enforcement or replace it completely? I can see rule base match effort in the debug output, and it is quite different from the usual one for fm VM. Just trying to make sense out of it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2016 18:20:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1648#M51</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2016-04-11T18:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1649#M52</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;UP (Unified Policy) module replaces the inspect rulebase (with the same and extra capabilities).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2016 16:59:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1649#M52</guid>
      <dc:creator>Tal_Ben_Avraham</dc:creator>
      <dc:date>2016-04-14T16:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1650#M53</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Tal, that is VERY interesting. Why then I can still see module fw in the fw ctl debug output? Up should replace it, according to your answer.&lt;/P&gt;&lt;P&gt;Why is it still there?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Apr 2016 11:06:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1650#M53</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2016-04-15T11:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1651#M54</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;fw module debug flags include a lot of debugging none-related to the rulebase execution and enforcement (NAT debugs for example).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Apr 2016 17:13:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1651#M54</guid>
      <dc:creator>Tal_Ben_Avraham</dc:creator>
      <dc:date>2016-04-20T17:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1652#M55</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/6880"&gt;Tal  Ben Avraham&lt;/A&gt;‌,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I remember you were saying that new connection module &lt;STRONG&gt;UnifiedPolicy&lt;/STRONG&gt; was added which is executed from the fw VM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@luka-eye]# fw ctl conn -a&lt;/P&gt;&lt;P&gt;Installed connections modules:&lt;BR /&gt;No. Name Used Newconn Packet End Reload Dup Type Dup Handler&lt;BR /&gt;Connectivity level 0:&lt;BR /&gt;0: Accounting yes 0: Accounting 00000000 00000000 f549e5d0 00000000 Special f549f500&lt;BR /&gt;1: Authentication yes 1: Authentication f568b4b0 00000000 00000000 00000000 Special f568ba00&lt;BR /&gt;2: AutoTopology no 2: AutoTopology 00000000 00000000 00000000 00000000 None&lt;BR /&gt;3: CPAS yes 3: CPAS 00000000 00000000 f5911af0 00000000 None&lt;BR /&gt;4: FG-1 no 4: FG-1 00000000 00000000 00000000 00000000 None&lt;BR /&gt;5: FWconn_stats no 5: FWconn_stats 00000000 00000000 00000000 00000000 None&lt;BR /&gt;6: ISP-Redundancy no 6: ISP-Redundancy 00000000 00000000 00000000 00000000 None&lt;BR /&gt;7: IcmpTunnel no 7: IcmpTunnel 00000000 00000000 00000000 00000000 None&lt;BR /&gt;8: NAC yes 8: NAC f5af4720 00000000 00000000 00000000 Save&lt;BR /&gt;9: NAT yes 9: NAT 00000000 00000000 f5638360 00000000 Special f5638a90&lt;BR /&gt;10: PSL yes 10: PSL 00000000 00000000 f5702ef0 f56fe690 None&lt;BR /&gt;11: RTM no 11: RTM 00000000 00000000 00000000 00000000 None&lt;BR /&gt;12: RTM2 no 12: RTM2 00000000 00000000 00000000 00000000 None&lt;BR /&gt;13: SPII yes 13: SPII f56aea40 00000000 f56b2ed0 f56b33c0 None&lt;BR /&gt;14: SeqVerifier yes 14: SeqVerifier f54edea0 00000000 00000000 f54e8de0 Special f54edf50&lt;BR /&gt;15: SynDoSDefender no 15: SynDoSDefender 00000000 00000000 00000000 00000000 None&lt;BR /&gt;&lt;STRONG&gt;16: UnifiedPolicy yes 16: UnifiedPolicy f5efda00 00000000 f5efd620 00000000 Special f5efcfd0&lt;/STRONG&gt;&lt;BR /&gt;17: VPN yes 17: VPN f5c94040 00000000 f5c7d330 00000000 Special f5c72ae0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it will help to understand the flow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jun 2017 05:11:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1652#M55</guid>
      <dc:creator>Alex_Sazonov</dc:creator>
      <dc:date>2017-06-28T05:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1653#M56</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Security policy is enforced by the VM chain module (as in pervious versions_.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In cases where rulebase requires data inspection (e.g: Applicative rulebsae) there will be first execution of the rulebase in the VM chain module followed by additional rulebase executions triggered by parsers upon connection data (i.e: TCP/UDP payload) being inspected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jun 2017 07:33:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1653#M56</guid>
      <dc:creator>Tal_Ben_Avraham</dc:creator>
      <dc:date>2017-06-28T07:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1654#M57</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tal, what is a connection module? Any documentation reference?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jun 2017 07:09:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1654#M57</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2017-06-29T07:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: UP kernel chain and policy enforcement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1655#M58</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Above statement is not accurate.&lt;/P&gt;&lt;P&gt;UnifiedPolicy (UP) is indeed a connection module. Generally means it saves information on the connection table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has nothing to do with the position (chain module) the rulebase is being executed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Jun 2017 11:35:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/UP-kernel-chain-and-policy-enforcement/m-p/1655#M58</guid>
      <dc:creator>Tal_Ben_Avraham</dc:creator>
      <dc:date>2017-06-29T11:35:29Z</dc:date>
    </item>
  </channel>
</rss>

