<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: rules in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56817#M2202</link>
    <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;to display a web page containing information from the database, the web server must connect to the sql server through the firewall. it uses port 1433 in tcp.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint.png" style="width: 939px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1694i605F0B14D73A310F/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint.png" alt="checkpoint.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jun 2019 09:30:09 GMT</pubDate>
    <dc:creator>Junior</dc:creator>
    <dc:date>2019-06-27T09:30:09Z</dc:date>
    <item>
      <title>rules management</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56271#M2167</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello everyone ;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have the SMB 1490, I publish here my rules of management to know if they are well written. also I would like to know if there is documentation for the 1490 for better grip.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thank.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="capture1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1609i7D5EFB6D127C040B/image-size/large?v=v2&amp;amp;px=999" role="button" title="capture1.PNG" alt="capture1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1610i670D5DB535089425/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture2.PNG" alt="Capture2.PNG" /&gt;&lt;/span&gt;grip. Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 12:02:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56271#M2167</guid>
      <dc:creator>Junior</dc:creator>
      <dc:date>2019-06-20T12:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: rules management</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56359#M2168</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R77.20.85/1400_Local_AdminGuide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R77.20.85/1400_Local_AdminGuide/html_frameset.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 11:18:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56359#M2168</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-06-21T11:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: rules management</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56480#M2181</link>
      <description>Without knowing exactly what's connected to the different networks, I can't say for sure that's the best rulebase for you.&lt;BR /&gt;I usually end up dropping a few things on the local networks mostly to keep the logs reasonable (things like SMB).</description>
      <pubDate>Sun, 23 Jun 2019 20:38:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56480#M2181</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-23T20:38:38Z</dc:date>
    </item>
    <item>
      <title>rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56745#M2191</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Good evening;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i have a web server in my dmz that needs to interact with a sql server database server in the LAN network. simple pages are accessible, but pages displaying data are not, because they are blocked by the firewall. how to write the rule for the web server then query the database located in the LAN.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint.png" style="width: 939px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1687i0907534C2119E93E/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint.png" alt="checkpoint.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;thank&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 17:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56745#M2191</guid>
      <dc:creator>Junior</dc:creator>
      <dc:date>2019-06-26T17:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56755#M2192</link>
      <description>Hi, you created a new thread about the same environment.&lt;BR /&gt;I've merged it to this thread.&lt;BR /&gt;Also, hope that's not your actual public IP address in the diagram--you might want to consider updating the diagram.&lt;BR /&gt;&lt;BR /&gt;Without knowing precisely how your web server is communicating with the database server, I can't tell you exactly what rules to create.&lt;BR /&gt;That said, the screenshot you provided of the rules suggests it should work.&lt;BR /&gt;However, allowing everything from DMZ to LAN is not recommended.&lt;BR /&gt;You should configure the specific IPs and protocols you wish to allow.&lt;BR /&gt;&lt;BR /&gt;Actual screenshots of the relevant log messages you're seeing might be helpful.</description>
      <pubDate>Wed, 26 Jun 2019 21:11:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56755#M2192</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-26T21:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56817#M2202</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;to display a web page containing information from the database, the web server must connect to the sql server through the firewall. it uses port 1433 in tcp.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint.png" style="width: 939px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1694i605F0B14D73A310F/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint.png" alt="checkpoint.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 09:30:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/56817#M2202</guid>
      <dc:creator>Junior</dc:creator>
      <dc:date>2019-06-27T09:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/57092#M2217</link>
      <description>&lt;P&gt;hello PhoneBoy,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I managed to configure a rule to allow the web server to connect to the sql server by following your advice.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="&amp;amp;&amp;amp;.PNG" style="width: 896px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1743i63987A616B02CDE9/image-size/large?v=v2&amp;amp;px=999" role="button" title="&amp;amp;&amp;amp;.PNG" alt="&amp;amp;&amp;amp;.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now give me your opinion; it is secure?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 10:21:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/57092#M2217</guid>
      <dc:creator>Junior</dc:creator>
      <dc:date>2019-07-01T10:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: rules management</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/57154#M2219</link>
      <description>&lt;P&gt;Hello Junior,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rules 3, 4 and 5 are bypassing the blocks at default rule 6.&lt;/P&gt;&lt;P&gt;You need to block other dangerous/ilegal categories above rule 3 - Directeur, or else he will be at risk.&lt;/P&gt;&lt;P&gt;I recommend adding a group blocking stuff like Child Abuse, Phishing, Malware, Spam, etc. at the top.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 17:21:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/57154#M2219</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2019-07-01T17:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: rules management</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/57469#M2240</link>
      <description>&lt;P&gt;thank pedro for your answer,&lt;/P&gt;&lt;P&gt;can you qive me an exemples please.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 14:45:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/rules-management/m-p/57469#M2240</guid>
      <dc:creator>Junior</dc:creator>
      <dc:date>2019-07-04T14:45:13Z</dc:date>
    </item>
  </channel>
</rss>

