<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Implied rules and hardening against attacks in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282910#M47153</link>
    <description>&lt;P&gt;Need the option of doing it the other way around, not disabling on a country by country basis. And this needs to be possible within the SmartConsole policy view - we shouldn't have to be doing this within Gaia.&lt;BR /&gt;&lt;BR /&gt;Use case: Block inbound Remote Access VPNs from *everywhere*, with the following exceptions: allow all addresses in a specific Gulf country and allow 4 specific addresses in the UK.&lt;/P&gt;</description>
    <pubDate>Sat, 26 Sep 2026 14:43:17 GMT</pubDate>
    <dc:creator>ccsjnw</dc:creator>
    <dc:date>2026-09-26T14:43:17Z</dc:date>
    <item>
      <title>Implied rules and hardening against attacks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282756#M47111</link>
      <description>&lt;P&gt;Where do we stand as a community in regard to implied rules?&lt;/P&gt;
&lt;P&gt;While I understand it is very convinient to have them enabled. The major issue we have is that there is not much one can control in this regard and several of the latest CVE issues I have seen can't be mitigated in full if you rely on implied rules.&lt;/P&gt;
&lt;P&gt;Also audits in the past always forced us to disable them as too much information was exposed during pentesting. So it is very easy to fingerprint a Check Point firewall.&lt;/P&gt;
&lt;P&gt;It seems Check Point is very, very reluctant to disable them or give a better control on them.&lt;/P&gt;
&lt;P&gt;For me this is at the moment the biggest issue we see in terms of exposure management. I am almost forced to put some sort of ACL or firewall before my firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my experience some of the implied rules can be tough to setup with manual rules. As you may need 3 rules and some tweeks for some very specific traffic.&lt;/P&gt;
&lt;P&gt;So in my view the middle ground could be to make the implied rules a sort of layer where you can choose to disable or enable the rules and not actually change them.&lt;/P&gt;
&lt;P&gt;I can live with a guideline where I need to sort out my manual rules on my own if I disable any of the implied rules. But it will allow me to do so selectively as was sort of implied in at least one of the recent SKs in regard to a high risk CVE issue. (that information is propably gone by now from the SK.&lt;/P&gt;
&lt;P&gt;But this is where as a community we can send a message of how we want our firewalls to work for us. So by all means .... comment on this.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 11:37:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282756#M47111</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2026-09-24T11:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and hardening against attacks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282758#M47112</link>
      <description>&lt;P&gt;Given these rules can be visualised, having them in a special layer on top and bottom of production rules instead of checkboxes in the Global Properties would indeed be a welcome improvement.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 12:04:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282758#M47112</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2026-09-24T12:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and hardening against attacks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282759#M47113</link>
      <description>&lt;P&gt;Yeah I agree,&lt;BR /&gt;I think implied rules should only exist on the management port nothing else. that way we can avoid the risks you stated here.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 12:12:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282759#M47113</guid>
      <dc:creator>Shyyyy</dc:creator>
      <dc:date>2026-09-24T12:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and hardening against attacks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282766#M47115</link>
      <description>&lt;P&gt;Second this.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 14:10:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282766#M47115</guid>
      <dc:creator>toblun</dc:creator>
      <dc:date>2026-09-24T14:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and hardening against attacks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282780#M47119</link>
      <description>&lt;P&gt;I suspect we will or already are reviewing how Implied Rules are handled in light of the recent CVEs.&lt;BR /&gt;Given how deep some of these are in the code, it will probably have to be addressed as part of a major release.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 15:26:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282780#M47119</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-24T15:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and hardening against attacks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282784#M47120</link>
      <description>&lt;P&gt;I echo everything that has been said above. It would be extremely useful to see (and have full control) over the implied rules in the standard policy view.&lt;/P&gt;
&lt;P&gt;Having a feature where an administrator can simply disable specific implied rules would be very welcome - when an implied rule is disabled by the administrator, just pop up a warning message stating that the administrator will need to create their own appropriate rule. Job done - this doesn’t need to be complicated.&lt;/P&gt;
&lt;P&gt;Please can CheckPoint ensure that Geo Blocking rules are applied *first*. We need this for all inbound connections including Remote Access VPN clients trying to establish a connection with a Security Gateway.&lt;/P&gt;
&lt;P&gt;Country specific Geo blocking is now *mandated* by some government authorities in the Arabian Gulf region, and it is very painful to do this manually. This has been asked for many times, and there’s always been arguments against this, but customers need this functionality to comply with local in-country restrictions.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 17:02:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282784#M47120</guid>
      <dc:creator>ccsjnw</dc:creator>
      <dc:date>2026-09-24T17:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and hardening against attacks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282802#M47122</link>
      <description>&lt;P&gt;You can handle geo blocking by using the DoS mitigation tools similar to:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Firewall-Security-Management/Block-VPN-Traffic-by-Country/m-p/172695#M31396" target="_blank"&gt;https://community.checkpoint.com/t5/Firewall-Security-Management/Block-VPN-Traffic-by-Country/m-p/172695#M31396&lt;/A&gt;&lt;BR /&gt;These are applied before implied rules.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 23:03:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282802#M47122</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-24T23:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and hardening against attacks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282910#M47153</link>
      <description>&lt;P&gt;Need the option of doing it the other way around, not disabling on a country by country basis. And this needs to be possible within the SmartConsole policy view - we shouldn't have to be doing this within Gaia.&lt;BR /&gt;&lt;BR /&gt;Use case: Block inbound Remote Access VPNs from *everywhere*, with the following exceptions: allow all addresses in a specific Gulf country and allow 4 specific addresses in the UK.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2026 14:43:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282910#M47153</guid>
      <dc:creator>ccsjnw</dc:creator>
      <dc:date>2026-09-26T14:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: Implied rules and hardening against attacks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282938#M47165</link>
      <description>&lt;P&gt;I tried a little test today on one cluster in my attempts to get all implied rules turned off.&amp;nbsp; It was close, but had to revert.&amp;nbsp; &amp;nbsp;Very simple design,&amp;nbsp; On prem (publicly addressed) management/logging running r82.10 and (9) clusters all running r82 or r81.20.&amp;nbsp; I disabled all implied rules, and created these very clear and simple 4 rules at the top of the policy for the test cluster.&amp;nbsp; Note that the "any" services was going to be set granularly after a few days of logging:&lt;/P&gt;
&lt;P&gt;Rule 1:&amp;nbsp; Management -&amp;gt; test cluster VIP/ both public real IPs: any services&lt;/P&gt;
&lt;P&gt;Rule 2: test cluster VIP/both public real IPs -&amp;gt; Management: any services&lt;/P&gt;
&lt;P&gt;Rule 3: all gateways/VIPs &amp;lt;-&amp;gt; all gateways/VIPs: any services.&amp;nbsp; This is for all VPNs&lt;/P&gt;
&lt;P&gt;Rule 4:&amp;nbsp;test cluster VIP/both public real IPs -&amp;gt; Internet : any services.&amp;nbsp; This for DNS/ntp/threat updates....&lt;/P&gt;
&lt;P&gt;Pushed policy to the test cluster and all was good for about 30 minutes.&amp;nbsp; Saw traffic matching the rules as planned, all looked good, and then all tunnels to/from this cluster went down.&amp;nbsp; vpn tu showed no phase 1.&amp;nbsp; couldn't find anything salient in logs.&lt;/P&gt;
&lt;P&gt;Enabled only "accept control connections - first" and tunnels immediately came back.&amp;nbsp; I would think this would have all be covered by the rule 3 i created.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Sep 2026 21:41:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Implied-rules-and-hardening-against-attacks/m-p/282938#M47165</guid>
      <dc:creator>D_TK</dc:creator>
      <dc:date>2026-09-27T21:41:22Z</dc:date>
    </item>
  </channel>
</rss>

