<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic objects from ACI not working in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Dynamic-objects-from-ACI-not-working/m-p/258473#M3654</link>
    <description>&lt;P dir="ltr"&gt;Are the drops seen in debugs definitely for active machines?&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;SPAN&gt;Anything of interest in: cloud_proxy.elg&lt;/SPAN&gt;&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;SPAN&gt;What do you see with "pep show user query cid a.b.c.d"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Sep 2025 14:56:05 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2025-09-29T14:56:05Z</dc:date>
    <item>
      <title>Dynamic objects from ACI not working</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Dynamic-objects-from-ACI-not-working/m-p/258445#M3648</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello Community,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;we have an issue with dynamic objects imported from ACI and used in Access Control policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When we use static network objects, the traffic works fine. But when we replace it with dyn obj (imported form ACI) for the same subnet, the traffic does not match the rule and gets dropped by cleanup.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Environment:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Check Point is synced with Identity Awareness on the gateway&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Check Point does not show any error in logs regarding the dynamic object&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;In SmartConsole, the dynamic object shows the correct hosts inside&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;with fw ctl zdebug + drop, we see traffic dropped by cleanup rule when the dynamic object is used as destination.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Tech Specs:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL class="lia-list-style-type-square"&gt;&lt;LI&gt;&lt;SPAN&gt;Hyperscale Maestro Solution 9700 running VS&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Product version Check Point Gaia R81.20&lt;/LI&gt;&lt;LI&gt;HOTFIX_R81_20_JUMBO_HF_MAIN Take: 113&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Is this known limitation or bug when using ACI dyn objects?&lt;/P&gt;&lt;P&gt;Are there any recommendations for debugging this further, or a known fix/workaround other then replacing with a static subnet?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;K.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 11:21:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Dynamic-objects-from-ACI-not-working/m-p/258445#M3648</guid>
      <dc:creator>katarina_</dc:creator>
      <dc:date>2025-09-29T11:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic objects from ACI not working</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Dynamic-objects-from-ACI-not-working/m-p/258473#M3654</link>
      <description>&lt;P dir="ltr"&gt;Are the drops seen in debugs definitely for active machines?&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;SPAN&gt;Anything of interest in: cloud_proxy.elg&lt;/SPAN&gt;&lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;SPAN&gt;What do you see with "pep show user query cid a.b.c.d"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P dir="ltr"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 14:56:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Dynamic-objects-from-ACI-not-working/m-p/258473#M3654</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-09-29T14:56:05Z</dc:date>
    </item>
  </channel>
</rss>

