<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: questions regarding Security Zones in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282734#M47108</link>
    <description>&lt;P&gt;Zones are basically interface tags or groups. You add interfaces into a specific zone and then create rules based on those zones, for example you can have internal, external and DMZ zones.&amp;nbsp;&lt;BR /&gt;While you can allow traffic based on zones only, it's fairly broad unless you have very specific services behind each interface. Best practice with zones is to use inline layers.&amp;nbsp;&lt;BR /&gt;Parent rule is from zone 1 to zone 2. Then build more granular sub-policy where you can use identities, IPs, applications etc. to match traffic.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Sep 2026 04:33:18 GMT</pubDate>
    <dc:creator>Lari_Luoma</dc:creator>
    <dc:date>2026-09-24T04:33:18Z</dc:date>
    <item>
      <title>questions regarding Security Zones</title>
      <link>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282694#M47102</link>
      <description>&lt;P&gt;We have configured Security Zones on an interfaces and some rules with Security Zones as source or destination.&lt;/P&gt;
&lt;P&gt;Traffic with destination IP-address of the interface in the defined Security Zone does not match via the rule with zones. I believe the interface IP-address should be included in the defined Security Zone of the interface, but maybe not ?&lt;/P&gt;
&lt;P&gt;Another question regarding logging... Is it possible to use the Security Zones as a filter in the logs ?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 11:47:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282694#M47102</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2026-09-23T11:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: questions regarding Security Zones</title>
      <link>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282718#M47105</link>
      <description>&lt;P&gt;Is the traffic from the zone to itself? If so, I would expect that to match traffic to the firewall.&lt;/P&gt;
&lt;P&gt;If instead you're allowing traffic from one zone to another zone, I would expect that to &lt;EM&gt;not&lt;/EM&gt; match traffic to the interface leading to the destination zone. The zone matches traffic which would come in or go out the interface. Traffic to an IP owned by the firewall stops at the routing table and wouldn't go out the interface.&lt;/P&gt;
&lt;P&gt;The inherent difficulty of predicting what will match a zone object is a big part of why I dislike them.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 14:32:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282718#M47105</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2026-09-23T14:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: questions regarding Security Zones</title>
      <link>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282719#M47106</link>
      <description>&lt;P&gt;I believe you can do that, yes.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2026 14:49:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282719#M47106</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-09-23T14:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: questions regarding Security Zones</title>
      <link>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282734#M47108</link>
      <description>&lt;P&gt;Zones are basically interface tags or groups. You add interfaces into a specific zone and then create rules based on those zones, for example you can have internal, external and DMZ zones.&amp;nbsp;&lt;BR /&gt;While you can allow traffic based on zones only, it's fairly broad unless you have very specific services behind each interface. Best practice with zones is to use inline layers.&amp;nbsp;&lt;BR /&gt;Parent rule is from zone 1 to zone 2. Then build more granular sub-policy where you can use identities, IPs, applications etc. to match traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 04:33:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282734#M47108</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2026-09-24T04:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: questions regarding Security Zones</title>
      <link>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282740#M47109</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;&amp;nbsp;parent rules with zones and then inline layer with more granular rules is what we configure.&lt;/P&gt;
&lt;P&gt;But return to my questions......&lt;/P&gt;
&lt;P&gt;1. Is the interface IP included in the zone of the interface ?&lt;/P&gt;
&lt;P&gt;2. Is it possible to define a log filter with zones ?&lt;/P&gt;
&lt;P&gt;3. Are Security Zones working with automatic topology calculation ?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2026-09-24 093354.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35368i9FF676278E7E1A30/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2026-09-24 093354.png" alt="Screenshot 2026-09-24 093354.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 07:36:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282740#M47109</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2026-09-24T07:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: questions regarding Security Zones</title>
      <link>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282806#M47125</link>
      <description>&lt;P&gt;1. A Security Zone incude whatever traffic comes through that interface. It's not based on IP-addresses.&amp;nbsp;&lt;BR /&gt;2. You cannot directly filter based on zones in the logs. However, you can filter according to the rules or rule names that use zones.&lt;BR /&gt;&lt;SPAN&gt;3. Zone is an interface tag/definition and does not interfere with the topology in any way.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 04:40:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282806#M47125</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2026-09-25T04:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: questions regarding Security Zones</title>
      <link>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282883#M47143</link>
      <description>&lt;P&gt;For item 1, is the decision based on the routing topology, or is it based on actually passing through the interface?&lt;/P&gt;
&lt;P&gt;Let's say you have a firewall with bond1.123 (address 10.0.123.1/24, zone A) and bond1.234 (address 10.0.234.1/24, zone B) a rule which allows traffic from zone A to zone A, and another rule which allows traffic from zone A to zone B.&lt;/P&gt;
&lt;P&gt;If 10.0.123.5 tries to connect to 10.0.234.5, that should match the A-to-B rule.&lt;/P&gt;
&lt;P&gt;If 10.0.123.5 tries to connect to 10.0.123.1, I would expect that to match the A-to-A rule. Is that what actually happens?&lt;/P&gt;
&lt;P&gt;If 10.0.123.5 tries to connect to 10.0.234.1, that traffic won't ever hit bond1.234, so I expect it to &lt;EM&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;/EM&gt; match the A-to-B rule. Is that what actually happens?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 21:05:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282883#M47143</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2026-09-25T21:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: questions regarding Security Zones</title>
      <link>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282889#M47144</link>
      <description>&lt;P&gt;yes, those networks are behind the interfaces in zone A or zone B, so traffic between them should match the zone based rule. If you are only connecting to the interface IP address, I don't think that would match a zone though.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2026 01:43:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/questions-regarding-Security-Zones/m-p/282889#M47144</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2026-09-26T01:43:27Z</dc:date>
    </item>
  </channel>
</rss>

