<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using inline layers together with zone pairs in SmartMove</title>
    <link>https://community.checkpoint.com/t5/SmartMove/Using-inline-layers-together-with-zone-pairs/m-p/274284#M695</link>
    <description>&lt;P&gt;That's a great conclusion. I'm doing a quick review of all the threads on Ordered vs. Inlayer. I'm going to switch from Ordered to Inlayer based on what you said, especially if your networking team doesn't provide all the network information.&lt;BR /&gt;&lt;BR /&gt;For newcomers who come across this, keep this in mind: &lt;A href="https://support.checkpoint.com/results/sk/sk184176" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk184176&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Mar 2026 21:38:06 GMT</pubDate>
    <dc:creator>alexgnunez2</dc:creator>
    <dc:date>2026-03-26T21:38:06Z</dc:date>
    <item>
      <title>Using inline layers together with zone pairs</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Using-inline-layers-together-with-zone-pairs/m-p/25939#M235</link>
      <description>&lt;P&gt;One of the things which were very different from other vendor's firewall when we changed to Checkpoint was the absence of interface(s) in the firewall policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now as Checkpoint introduced network zones and also inline-layers in the policy, isn't it possible to use some kind of template to have similar behavior? Here an example how it could look like for three zone pairs (internal-&amp;gt;internet, internal-&amp;gt;dmz-public, internal-&amp;gt;dmz-private), without actual rules, but I think you get the point:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66107_pastedImage_1.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then you would add the specific rules in the inline-layers. I see many advantages using this kind of template:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If you make an error in a rule, only the inline-sublayer (so traffic between those specific zones) will be affected, not the complete firewall&lt;/LI&gt;
&lt;LI&gt;The firewall engine don't has to check unnecessary rules if zone doesn't match&lt;/LI&gt;
&lt;LI&gt;Delegate policy administration for a specific zone pair&lt;/LI&gt;
&lt;LI&gt;etc.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any reason against doing like this from Checkpoint architecture point of view?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 04:55:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Using-inline-layers-together-with-zone-pairs/m-p/25939#M235</guid>
      <dc:creator>Markus_Marquard</dc:creator>
      <dc:date>2021-06-23T04:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Using inline layers together with zone pairs</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Using-inline-layers-together-with-zone-pairs/m-p/25940#M236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, this is a valid use-case for Inline Layers. It is supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to point out 2 things:&lt;/P&gt;&lt;P&gt;1. In case you have 2 interfaces from 2 different gateways that are linked to the same Security Zone, you still need to create a rule from and to the same zone to allow that traffic.&lt;/P&gt;&lt;P&gt;2. With Check Point you don't have to use Gateway&amp;nbsp;Interface objects (aka Security Zones) to create Network Segmentation with Inline Layers. You can use any network object that you like. So while security zone parent rules for inline layers works completely, you don't have to create another gateway interface&amp;nbsp;every time you want to place traffic to a separate inline layer. You can just use the object that represents the network.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 May 2018 06:16:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Using-inline-layers-together-with-zone-pairs/m-p/25940#M236</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-05-27T06:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Using inline layers together with zone pairs</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Using-inline-layers-together-with-zone-pairs/m-p/25941#M237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is exactly the approach&amp;nbsp;implemented by our &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115416"&gt;SmartMove&lt;/A&gt; tool, when migrating Juniper SRX and Cisco ASA policies into Check Point R80.10 Management.&lt;/P&gt;&lt;P&gt;Robert.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2018 11:07:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Using-inline-layers-together-with-zone-pairs/m-p/25941#M237</guid>
      <dc:creator>Robert_Decker</dc:creator>
      <dc:date>2018-05-29T11:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Using inline layers together with zone pairs</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Using-inline-layers-together-with-zone-pairs/m-p/274284#M695</link>
      <description>&lt;P&gt;That's a great conclusion. I'm doing a quick review of all the threads on Ordered vs. Inlayer. I'm going to switch from Ordered to Inlayer based on what you said, especially if your networking team doesn't provide all the network information.&lt;BR /&gt;&lt;BR /&gt;For newcomers who come across this, keep this in mind: &lt;A href="https://support.checkpoint.com/results/sk/sk184176" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk184176&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2026 21:38:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Using-inline-layers-together-with-zone-pairs/m-p/274284#M695</guid>
      <dc:creator>alexgnunez2</dc:creator>
      <dc:date>2026-03-26T21:38:06Z</dc:date>
    </item>
  </channel>
</rss>

