<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time based rule - rematch connection in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32882#M6871</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However I'm not trying to have policy applied after a Policy Installation but after a Rule with a Time ressource defined on it. When this rule expire I would like to rematch the existing connection (no policy installation)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Jun 2018 11:28:56 GMT</pubDate>
    <dc:creator>CP-NDA</dc:creator>
    <dc:date>2018-06-20T11:28:56Z</dc:date>
    <item>
      <title>Time based rule - rematch connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32878#M6867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We would like to implement a Time Based restricted rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The time limitation is correclty applied for all new connections but for existing traffic there is no rematch of the active connections once rule expires&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to force this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We would like to apply Bandwidth limitation starting at a defined day and hour and release this limitation after a certain time...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now if the connection start before the time restriction the limitation is not applied&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 09:49:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32878#M6867</guid>
      <dc:creator>CP-NDA</dc:creator>
      <dc:date>2018-06-20T09:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Time based rule - rematch connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32879#M6868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nicolas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you check that "Rematch connections" is chosen under SmartDashboard -&amp;gt; gateway object -&amp;gt; Other -&amp;gt; Connection Persistence ? sxl may help without rematch conn config;&amp;nbsp; for the configuration to apply for connections from existing templates, you should run "fwaccel off; fwaccel on".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 10:37:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32879#M6868</guid>
      <dc:creator>Huseyin_Rencber</dc:creator>
      <dc:date>2018-06-20T10:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Time based rule - rematch connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32880#M6869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for this update we are in Keep Connection to avoid drops when pushing policies in VPN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this settings responsible for the non-rematch of the rules?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you ask to set fwaccl off then on do we need to run this manually once the rule has expired?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 10:54:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32880#M6869</guid>
      <dc:creator>CP-NDA</dc:creator>
      <dc:date>2018-06-20T10:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: Time based rule - rematch connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32881#M6870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You setting (keep connection) will keep connections open until the connections ended. The newly installed policy will be enforced only for the new connection. The second option sxl may help. not sure about that, you can try it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 11:25:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32881#M6870</guid>
      <dc:creator>Huseyin_Rencber</dc:creator>
      <dc:date>2018-06-20T11:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Time based rule - rematch connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32882#M6871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However I'm not trying to have policy applied after a Policy Installation but after a Rule with a Time ressource defined on it. When this rule expire I would like to rematch the existing connection (no policy installation)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 11:28:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32882#M6871</guid>
      <dc:creator>CP-NDA</dc:creator>
      <dc:date>2018-06-20T11:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Time based rule - rematch connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32883#M6872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As Check Point's rulebase is matched only against new connections the only way I see to force this via a simple Bash script that is resetting the existing connection at your specific times.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 11:31:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32883#M6872</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-06-20T11:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Time based rule - rematch connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32884#M6873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I though there would be a native and better way to handle this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my debug the way of limiting the bandwidth is quite strange (dropping packets)...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 11:36:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Time-based-rule-rematch-connection/m-p/32884#M6873</guid>
      <dc:creator>CP-NDA</dc:creator>
      <dc:date>2018-06-20T11:36:25Z</dc:date>
    </item>
  </channel>
</rss>

