<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cprid implied rule in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78152#M3239</link>
    <description>When you're talking about implied rules for SIC and friends, you're in .def modifying territory.</description>
    <pubDate>Thu, 12 Mar 2020 19:54:40 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-03-12T19:54:40Z</dc:date>
    <item>
      <title>cprid implied rule</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78020#M3224</link>
      <description>&lt;P&gt;Does anyone know if there is an easy way to exclude cprid from implied rules? The use case I have is to hit cprid through a vpn tunnel on a daip gateway. Basically hit the internal interface through a vpn tunnel. Currently it seems implied which prevents encryption.&lt;/P&gt;&lt;P&gt;All the daip gateways are on a MDS (CMA) running R80.20 if that matters. Daip gateways are mostly R77.20.x&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 20:53:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78020#M3224</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-03-11T20:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: cprid implied rule</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78022#M3225</link>
      <description>&lt;P&gt;I should also point a large portion of the daip gateways are behind nat devices so i wouldn't have direct access to the external interface.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 20:55:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78022#M3225</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-03-11T20:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: cprid implied rule</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78036#M3228</link>
      <description>In general you should consult with TAC if you want to do anything SIC over VPN.&lt;BR /&gt;That said, poking around in implied_rules.def in the relevant Backward Compatibility directory, it seems like this should work already.&lt;BR /&gt;Perhaps you can twiddle some bits there and see.&lt;BR /&gt;Or open a TAC case.</description>
      <pubDate>Thu, 12 Mar 2020 01:07:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78036#M3228</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-12T01:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: cprid implied rule</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78057#M3230</link>
      <description>&lt;P&gt;I'm assuming your talking about&amp;nbsp;&lt;/P&gt;&lt;P&gt;#define accept_cprid&amp;nbsp; in the CPR77CMP dir?&lt;/P&gt;&lt;P&gt;My hope was not to touch .def files FYI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't chatted with the last 2 diamond reps so maybe its time to reach out.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 05:02:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78057#M3230</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-03-12T05:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: cprid implied rule</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78152#M3239</link>
      <description>When you're talking about implied rules for SIC and friends, you're in .def modifying territory.</description>
      <pubDate>Thu, 12 Mar 2020 19:54:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78152#M3239</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-12T19:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: cprid implied rule</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78158#M3240</link>
      <description>&lt;P&gt;yeah labbing up now. For some reason I was thinking i saw something where you could exclude services somewhere but i think i might be thinking about excluding services from vpn topo which wouldn't help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/shrug&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 21:06:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/cprid-implied-rule/m-p/78158#M3240</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-03-12T21:06:41Z</dc:date>
    </item>
  </channel>
</rss>

