cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted

PBR limitations

Hi Mates,

reading the sk100500 I was very surprised when it described

The following features/blades are not supported with PBR:

  • IPv6
  • Locally-generated traffic
  • Security Servers
  • Data Loss Prevention (DLP) blade
  • Anti-Spam blade
  • Mail Transfer Agent (MTA) (relevant for Threat Emulation/Threat Extraction/Data Loss Prevention/Anti-Spam blades)
  • ISP Redundancy
  • The following applications (which use Check Point Active Streaming [CPAS]):
    • VoIP (H323, SIP, Skinny, etc.)
    • HTTPS Inspection
    • HTTP Header Spoofing
    • HTTP Proxy
    • IMAP in IPS

Despite my idea where, routing feature on the gateway musn't influence the security features, at the moment I need to have a PBR on a gateway where MTA is active for the TEX blade.

In the enviroment where I'd like to implement PBR and I have MTA enabled on a R80.10 gateway, the PBR doesn't work.

Does someone face the same scenario ?

Does someone know a workaround/solution?

13 Replies
Admin
Admin

Re: PBR limitations

Locally generated traffic accounts for most of the limitations, including MTA.

It would be useful to hear about your specific use case in a little more detail.

0 Kudos

Re: PBR limitations

the idea shoud be implement a PBR to move internet browsing from a proxy server inside the network throught out a new provider.

I implemented the PBR as I made in the past for other costumers, but it the first time the PBR doesn't work.

I mean running "IP RULE" command in expert mode on the gateway, I see the matches at my PBR.

Dumping the traffic, instead, the packets are forwarded by the route in the main route tables

0 Kudos
Admin
Admin

Re: PBR limitations

Routing configuration changes needs to be done via clish and not using the ip command via expert mode.

Are you using the security gateway as the explicit proxy in this case?

0 Kudos

Re: PBR limitations

the "ip rule" command is described in the SK for debugging PBR on Secure Gateway.

obviously I implemented PBR from clish.

In reply at your question "Are you using the security gateway as the explicit proxy in this case?", the response is NO, I have an external proxy gateway.

0 Kudos
Admin
Admin

Re: PBR limitations

So how is the traffic flowing from your clients to the Internet?

Since proxies are involved, need to understand where the TCP connections are terminating.

And are you using the Transparent proxy option?

0 Kudos

Re: PBR limitations

the browser on client is configured to use explicit proxy and the communication starts from client and terminate at the proxy end.

The proxy, then, initiates the connection to the web site

in other words, running tcpdump on gateway I see as source IP, the IP of proxy server

0 Kudos
Admin
Admin

Re: PBR limitations

So do the packets from your internal proxy server terminate on another proxy server or just go to the Internet sites directly?

Also, my question about proxy mode, which you didn't answer.

The setting is here:

0 Kudos

Re: PBR limitations

Hi Dameon

The internal proxy goes out to the internet directly. No more proxy are in the middle between internal proxy and internet.

In reply CKP proxy configuration, the gateways are not configured as a proxy and the box on the property is not tricked.

0 Kudos
Admin
Admin

Re: PBR limitations

I recommend opening a TAC case to troubleshoot this as, to the best of my knowledge, this should work. 

0 Kudos
D_W
Nickel

Re: PBR limitations

Hi,

I also have a questions to the Limitations stated in SK100500.

We use URLFilter and IPS so the limitation is that those two features are not working for traffic that is handled by the PBR OR are  those features without function for every traffic?

KR

David

0 Kudos

Re: PBR limitations

According to sk100500, IPS  and URLF are not working with PBR.

0 Kudos
D_W
Nickel

Re: PBR limitations

Yes this SK100500 is telling us that but my question is if the whole IPS and URLF is not working/supported or only not supported/working for the PBR traffic?!

0 Kudos

Re: PBR limitations

I think that the limitations are pointing that you cannot make routing decisions based on those blades.

If not I would be really confused, I have many customers with PBRs and IPS and both blades are working like a charm.

Would be nice that someone from Check Point clarifies it, it's true that the sk is not clear enough.

____________
https://www.linkedin.com/in/federicomeiners/