<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB Access Policy Control and internet access in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180047#M8869</link>
    <description>&lt;P&gt;Using "Strict" is not really recommended out of my experience - i would suggest "Standard" with TP is secure enough &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; You have to allow every detail in many seperate rules in strict mode, and that needs much knowledge...&lt;/P&gt;</description>
    <pubDate>Fri, 05 May 2023 09:58:24 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-05-05T09:58:24Z</dc:date>
    <item>
      <title>SMB Access Policy Control and internet access</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180003#M8862</link>
      <description>&lt;P&gt;I'm stuck why this doesn't work, but basically I'm trying to allow devices connected to the LAN network of my SMB device access to the internet over certain ports.&lt;/P&gt;
&lt;P&gt;Background: Locally managed 1430 appliance running R77.20.87&lt;/P&gt;
&lt;P&gt;Access Policy (Firewall) is set to strict.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1430a.jpg" style="width: 497px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20783iA1214695BFD200C4/image-dimensions/497x153?v=v2" width="497" height="153" role="button" title="1430a.jpg" alt="1430a.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I've created a manual rule in the policy to allow internet access (top rule under Outgoing access to the Internet):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1430b.jpg" style="width: 781px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20784i87741C17504F3985/image-dimensions/781x316?v=v2" width="781" height="316" role="button" title="1430b.jpg" alt="1430b.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The service group "CFU_Internet" contains http, https, and ICMP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I'm seeing is traffic from the LAN network (172.x.x.x) to the internet is getting dropped on the last rule in the policy (rule 5 under Incoming, Internal, and VPN traffic):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-05-04_13-55-421430c.jpg" style="width: 591px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20785i845829E26BB39E4B/image-dimensions/591x378?v=v2" width="591" height="378" role="button" title="2023-05-04_13-55-421430c.jpg" alt="2023-05-04_13-55-421430c.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;What am I missing? Why isn't this traffic allowed by the first manual rule I created?&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 19:19:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180003#M8862</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-05-04T19:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Access Policy Control and internet access</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180019#M8863</link>
      <description>&lt;P&gt;Is your internet connection connected to a "WAN" port and what build of R77.20.87 firmware is used?&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 23:50:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180019#M8863</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-05-04T23:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Access Policy Control and internet access</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180022#M8864</link>
      <description>&lt;P&gt;Does 1st rule even have any hits? I noticed in the dropped log, shows inzone Internal and outzone as DMZ.&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 00:21:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180022#M8864</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-05T00:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Access Policy Control and internet access</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180047#M8869</link>
      <description>&lt;P&gt;Using "Strict" is not really recommended out of my experience - i would suggest "Standard" with TP is secure enough &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; You have to allow every detail in many seperate rules in strict mode, and that needs much knowledge...&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 09:58:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180047#M8869</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-05-05T09:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Access Policy Control and internet access</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180052#M8871</link>
      <description>&lt;P&gt;Inspiration struck in the middle of the night. The reason this is not working is that I do not have an internet connection defined/configured. Traffic from the LAN networks bound for the internet goes out the DMZ interface which is connected to an MPLS network, which eventually comes back to our datacenter and out our internet egress point there. I had to get a bit creative with the routing (solution found in another CheckMates post) but everything is working now as I need it.&lt;/P&gt;
&lt;P&gt;Thanks for everyone's suggestions,&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 13:03:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180052#M8871</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-05-05T13:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Access Policy Control and internet access</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180054#M8872</link>
      <description>&lt;P&gt;Excellent work&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10229"&gt;@David_C1&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 12:27:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Access-Policy-Control-and-internet-access/m-p/180054#M8872</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-05T12:27:01Z</dc:date>
    </item>
  </channel>
</rss>

