Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ben_Dunkley
Collaborator

"Interface leads to DMZ" setting

A slightly random curious question!

 

The "Interface leads to DMZ" checkbox under interface topology settings... what does it actually do?

 

i.e. does it alter the way NAT, anti-spoofing or something else behaves in relation to that interface?

 

The only visible change I notice is it alters the 'according to tolopogy' zone to DMZZone which doesn't really do anything if you're not using that object in the rulebase.

 

Documentation is hilariously un-useful : "Interface leads to DMZ - The DMZ that directly connects to this internal interface"

0 Kudos
3 Replies
Ben_Dunkley
Collaborator

Another checkmates thread (https://community.checkpoint.com/t5/General-Topics/Gateway-Topolgy-Internal-External-or-DMZ/td-p/178... links to sk108057, but it appears to be unreachable or non-existent.

0 Kudos
Ben_Dunkley
Collaborator

Further reading of the links from that thread seems to suggest:

  • In Application Control (and presumably URL filtering as well) rules, the 'Internet' destination object includes both external and DMZ
  • Some Threat Prevention settings reference the DMZ

And maybe that's all of it?

0 Kudos
Timothy_Hall
MVP Gold
MVP Gold

There was an SK that explained this nicely (sk108057: What does the box "Interface leads to DMZ" control in interface topology?), but it seems to be gone now.  The short answer is that the checkbox causes the interface to be treated as "External", even though it is designated "Internal".  Here is an excerpt from my upcoming Max Power 2026 book:

But if it is selected, what does the "Interface leads to DMZ" checkbox actually do? When enabled, this checkbox means that the interface will be treated as "External" in Access Control & Threat Prevention policies. It has a significant impact on how the special object “Internet” is calculated when used in Access Control policies, including APCL/URLF, Content Awareness,  and HTTPS Inspection.  For example, if "Interface leads to DMZ" is set on a DMZ network interface, and your APCL/URLF policy layer rules utilize the object "Internet" as the matching destination, web and application traffic from the inside network to the DMZ will be inspected by APCL/URLF in the Medium Path!  Normally, we would only want to perform this level of inspection on traffic heading to the Internet via an External interface; performance both to and from the DMZ will definitely be impacted!

This setting can also directly affect which traffic the Threat Prevention blades Anti-Virus & Threat Emulation will inspect, which once again can imapct performance:

te_dmz.pngav_dmz.png

Additionally, the DMZ designation is considered a possible restriction for where the Captive Portal can be displayed:

ia_dmz.png  

Finally, various VoIP Domain object definitions include configuration options such as "Call Manager in the DMZ" & "SIP Proxy in DMZ" & "H.323 Gatekeeper/Gateway in DMZ"; these *may* also be influenced by the "Interface Leads to DMZ" setting, but this relationship is not entirely clear.

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events