<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rule matching on sources it shouldn't in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26561#M5430</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can upload the log message of accepted traffic? Did you get something like sk113479:&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113479" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113479"&gt;"Connection terminated before detection" in log reason for Unified Rulebase&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;Also, which version of CP components and fix level are you using (GW, Mgmt, SmartConsole)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Sep 2018 19:03:06 GMT</pubDate>
    <dc:creator>KennyManrique</dc:creator>
    <dc:date>2018-09-13T19:03:06Z</dc:date>
    <item>
      <title>Rule matching on sources it shouldn't</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26555#M5424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, we've successfully installed policy numerous times and are very concerned that a rule is matching any and all source IPs:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-4 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70235_rule.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The allowed source objects:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70232_10.6.0.0.jpg" /&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;IMG alt="" class="image-3 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70234_192.168.51.0.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way I can validate the rule base on a running security gateway?&lt;/P&gt;&lt;P&gt;Surely there is no way this could be expected behavior?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 21:55:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26555#M5424</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-12T21:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Rule matching on sources it shouldn't</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26556#M5425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please disable the rule and create two new rules:&lt;/P&gt;&lt;P&gt;one rule for&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;External -&amp;gt; External IP2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;and another rule for&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;LAN -&amp;gt; External IP2,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;then check what your log says.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Btw, why is a private 10. network called External?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 22:25:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26556#M5425</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-09-12T22:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Rule matching on sources it shouldn't</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26557#M5426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can poke around $FWDIR/state to see what is installed, but it probably won't be all that readable.&lt;/P&gt;&lt;P&gt;I strongly recommend opening a TAC case to get assistance with troubleshooting this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 22:26:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26557#M5426</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-12T22:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Rule matching on sources it shouldn't</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26558#M5427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="direction: ltr;"&gt;For better understanding the issue here we will need full screen shot of your rule base.&lt;/P&gt;&lt;P style="direction: ltr;"&gt;you may contact me offline &lt;A href="mailto:iliay@checkpoint.com"&gt;iliay@checkpoint.com&lt;/A&gt;&amp;nbsp;and i will assist you to understand the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 06:00:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26558#M5427</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2018-09-13T06:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Rule matching on sources it shouldn't</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26559#M5428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Web site provides access for a financial services company. 10.6.0.0/16 is another company's internal network range&amp;nbsp; which reaches this server through the Check Point security gateway and is therefor external to this environment. Legacy VPN subnet is handled by the router in front of the Check Point security gateway, being replaced with Mobile Access VPN, which is also technically outside of the protected environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 07:29:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26559#M5428</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-13T07:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: Rule matching on sources it shouldn't</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26560#M5429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What does rule 8 itself look like?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 10:16:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26560#M5429</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-09-13T10:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Rule matching on sources it shouldn't</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26561#M5430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can upload the log message of accepted traffic? Did you get something like sk113479:&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113479" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113479"&gt;"Connection terminated before detection" in log reason for Unified Rulebase&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;Also, which version of CP components and fix level are you using (GW, Mgmt, SmartConsole)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 19:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26561#M5430</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-09-13T19:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Rule matching on sources it shouldn't</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26562#M5431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Customer of us had exactly same issue with this log message. Issue with connection hold on source column because of identity awareness although access role not used on this rule.&lt;/P&gt;&lt;P class=""&gt;Is fixed in jumbo (don’t remember take) and you might need to &amp;nbsp;clear all tables by things like taking offline standby and either deleting table entries or also parallel stop of active member.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 19:28:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26562#M5431</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2018-09-13T19:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Rule matching on sources it shouldn't</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26563#M5432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ilya Yusupov from Check Point was immensely helpful in tracking this down, installing the hotfix for&amp;nbsp;sk134054 (&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk134054&amp;amp;src=securityAlerts" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk134054&amp;amp;src=securityAlerts"&gt;Rare failure in the Identity Sharing network registration may potentially result in incorrect policy actions&lt;/A&gt;) resolved the problem:&lt;/P&gt;&lt;P style="margin-left: 36.0pt;"&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70264_sk134054.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway was running R80.10 with JHF 121 and&amp;nbsp;sk134253 (Check Point response to SegmentSmack &amp;amp; FragmentSmack) with Identity Awareness&amp;nbsp;blade inactive:&lt;/P&gt;&lt;P style="margin-left: 36.0pt;"&gt;&lt;SPAN style="font-size: 8.0pt; color: #7f7f7f;"&gt;[Expert@fwcp1:0]#&lt;/SPAN&gt; &lt;SPAN style="font-size: 8.0pt;"&gt;enabled_blades&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 36.0pt;"&gt;&lt;SPAN style="font-size: 8.0pt;"&gt;fw vpn urlf av appi ips anti_bot mon vpn&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The network security policy exclusively had the firewall blade active:&lt;/P&gt;&lt;P style="margin-left: 36.0pt;"&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70278_cp_network.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem appears to occur when a policy rule references identity awareness data and there is either a failure obtaining identities (eg the original SK where identity sharing was unavailable) or when the policy includes a rule which had been structured for imminent activation of the Identity Awareness blade:&lt;/P&gt;&lt;P style="margin-left: 36.0pt;"&gt;&lt;SPAN style="font-size: 8.0pt; color: #7f7f7f;"&gt;&lt;IMG alt="" class="image-3 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70279_policy_outgoing.jpg" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 21:59:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Rule-matching-on-sources-it-shouldn-t/m-p/26563#M5432</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-13T21:59:18Z</dc:date>
    </item>
  </channel>
</rss>

