Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor
Jump to solution

Deny Multiple Services in a Single Rule

Hi Mates,

I’d like to ask if it’s possible to deny more than one service within a single rule. (Negated cell)
For example, let’s say I want to allow all traffic except ICMP and HTTPS — can this be configured in one rule, or do I need to create separate rules for each service I want to block?

Thanks in advance!

0 Kudos
2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

In Access Control rules, yes.
Don't believe the NAT policy permits this, however.

View solution in original post

the_rock
MVP Platinum
MVP Platinum

Hey brother,

I verified what Phoneboy said and it is 100% true. You can easily do this with regular access control policy, but nat does NOT allow you, it always defaults to last service added.

Best,
Andy

View solution in original post

6 Replies
PhoneBoy
Admin
Admin

In Access Control rules, yes.
Don't believe the NAT policy permits this, however.

the_rock
MVP Platinum
MVP Platinum

Hey brother,

I verified what Phoneboy said and it is 100% true. You can easily do this with regular access control policy, but nat does NOT allow you, it always defaults to last service added.

Best,
Andy
RemoteUser
Advisor

Thanks a lot to both!!! As Always!!!

(1)
the_rock
MVP Platinum
MVP Platinum

FYFOC...aka for you, free of charge 😉

Best,
Andy
Tal_Paz-Fridman
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

If you have a large rulebase, I recommend using a Services Group with clearly defined properties. This helps keep the rulebase cleaner and also allows you to make a single-click change that applies to all rules using the same Services Group.

the_rock
MVP Platinum
MVP Platinum

I also recommend deleting anything unused in object explorer...based on my testing, I found it to be 100% accurate.

Best,
Andy

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events