- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
I noticed that the option to negate a specific object is no long available in R80.xx, only available option is "negate cell"
I wonder why CheckPoint removed such a important feature.
I am simply trying to allow "any" but deny/negate "https" in the services cell, does anyone have a workaround?
I've been using Check Point since version 2 and I'm pretty sure it was never allowed to negate a specific object in a cell with two or more items in it.
Here's a snapshot from R77.30 where I'm selecting a specific object and I'm being offered "Negate Cell"
And it shows like this when negated.
Visually, it looks a little different in R80.x:
In either case, the effect is the same.
This even makes things more complicated; I would like to allow everything but https, how should my rule look like?
Any represents a lot of services which I cannot list.
I think your only option is two rules
top rule - service https - action - drop
second rule allow any
It seems so far the only option but why cp decided to get rid of such a good feature?
Now we end up with 2 rules instead of 1; I think checkpoint should reconsider putting this feature back.
No idea..
Its possible with network groups - create group with exclusion
seems there is no option to create service group with exclusion - you could have created a group containing tcp and udp 1-65535 and icmp and then exclude https.
If you wanted a really ugly solution you could create a group like above but with tcp range 1-442 and range 444-65535 group that together with udp range all ports and icmp.
It would look just like this, it allows my home lan to anything but the RFC1918 networks on any port but HTTP/HTTPS:
I've been using Check Point since version 2 and I'm pretty sure it was never allowed to negate a specific object in a cell with two or more items in it.
Here's a snapshot from R77.30 where I'm selecting a specific object and I'm being offered "Negate Cell"
And it shows like this when negated.
Visually, it looks a little different in R80.x:
In either case, the effect is the same.
Oh...then I misunderstood @Maarten_Sjouw explaination and thought that everything in the cell is allowed and the rest dropped. This makes sense now, thanks @PhoneBoy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 33 | |
| 21 | |
| 9 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Wed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY