Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RobertTaylor
Participant

Outbound Firewall Cleanup Rule

I'm trying to implement a "Outbound - Cleanup" rule as shown that logs blocked traffic.

The purpose of this is two part:

  1. Block Any Undefined Traffic
  2. Log Blocked Traffic in case additional exceptions are required (logging wouldn't always need to be enabled, just sometimes when troubleshooting a policy)

TP9H2oVIwb.png

The issue that I'm having is that after applying this policy HTTP traffic is being blocked by the Cleanup rule even though it is added as a service on Rule #3.

Is this how its supposed to work?

Am I missing something, or is this a bug?

0 Kudos
12 Replies
PhoneBoy
Admin
Admin

Are you managing via Infinity Portal or on-prem (and if so, what version/JHF level)?
What client version(s) is/are involved?

0 Kudos
RobertTaylor
Participant

This is an Infinity Portal service (EPMaaS).

The installed version is the current recommended version 88.32.

0 Kudos
PhoneBoy
Admin
Admin

Recommend engaging the TAC here: https://help.checkpoint.com 

0 Kudos
the_rock
Legend
Legend

You mean rule 2?

Andy

0 Kudos
RobertTaylor
Participant

Sorry your correct, yes I meant rule #

0 Kudos
the_rock
Legend
Legend

I dont know if fw up execute command works on smb, but you can try. Just google fw up execute check point and it will give right syntax.

Andy

0 Kudos
RobertTaylor
Participant

Is that for endpoint or gw?

0 Kudos
the_rock
Legend
Legend

gateway

0 Kudos
RobertTaylor
Participant

ok
I'm having this issue on the endpoint, thanks for the help though

0 Kudos
the_rock
Legend
Legend

I know you are, but fw is dropping it on wrong rule, so to me, seems like fw problem, NOT endpoint

0 Kudos
PhoneBoy
Admin
Admin

Endpoint has its own firewall that operates a bit differently from our Quantum (Spark) appliances 🙂

the_rock
Legend
Legend

K, fair enough, tells u how much I know about endpoint side lol

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events