- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hallo Dear Seniors & Juniors
I would like to ask about some Best Practices for Firewall Rules:
1. Best way to create a rule for a list of URLs.
2. Best way to create Rules for Applications.
Suppose I have a list of 10 URLs or IPs or Applications, I would like create a Rule in Smartconsole, How can this be achieved efficiently considering some Best Practice Approach?
Thank you and Kind regards,
Ahmed.
Most of the problems occur because some desirable applications may be "high risk" (or some other undesirable category of apps) and those tend to be blocked per the configured policy.
The policy should be built by a process that goes something like the following, assuming you are looking to build a typical "block malicious websites/applications and uncategorized ones."
You will have to watch logs for the Drop rule to handle false positives by adding them to the Explicit Accept rule, which should be set with Detailed or possibly Extended logging (Extended includes URLs if HTTPS Inspection is enabled).
On top of this, when you are creating custom application/site objects don't put all your URLs into one object, create one with the necessary URLs for each site, then you can put all the custom sites into a group. This way your logging and reporting will make sense.
Funny enough, I'm about to do one of my Web Filtering Best Practices sessions and someone asked me about this very thing.
Updated the session to include something about this.
I've seen custom sites named 'allowed_hosts' with upwards of 100 random URLs in it and people never know why any of them are in there, or what they're supposed to be allowing. It's always painful to unravel.
Hi @PhoneBoy
Thank you for the input. Let me be somehow specific.
I want to allow a list of websites of i want to allow some applications:
src: Client-Alpha or Server-Beta
Dst: list of websites (fcm, xxx.yyy.zzz, etc.) / some applications
Svc: http, https
Question:
Is it better if i create an inline-rule (nested-rule) and put all the those?
or
Is it better if I create a rule in access layer and then goto application layer and do another?
Because sometimes, although access-rule is allowed but communication is not successful, in case of Internet.
Thank
A.
Depends on a number of factors, most of which are covered in my Web Filtering Best Practices session.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 7 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY