Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor
Jump to solution

Deny Multiple Services in a Single Rule

Hi Mates,

I’d like to ask if it’s possible to deny more than one service within a single rule. (Negated cell)
For example, let’s say I want to allow all traffic except ICMP and HTTPS — can this be configured in one rule, or do I need to create separate rules for each service I want to block?

Thanks in advance!

0 Kudos
2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

In Access Control rules, yes.
Don't believe the NAT policy permits this, however.

View solution in original post

the_rock
MVP Diamond
MVP Diamond

Hey brother,

I verified what Phoneboy said and it is 100% true. You can easily do this with regular access control policy, but nat does NOT allow you, it always defaults to last service added.

Best,
Andy
"Have a great day and if its not, change it"

View solution in original post

6 Replies
PhoneBoy
Admin
Admin

In Access Control rules, yes.
Don't believe the NAT policy permits this, however.

the_rock
MVP Diamond
MVP Diamond

Hey brother,

I verified what Phoneboy said and it is 100% true. You can easily do this with regular access control policy, but nat does NOT allow you, it always defaults to last service added.

Best,
Andy
"Have a great day and if its not, change it"
RemoteUser
Advisor

Thanks a lot to both!!! As Always!!!

(1)
the_rock
MVP Diamond
MVP Diamond

FYFOC...aka for you, free of charge 😉

Best,
Andy
"Have a great day and if its not, change it"
Tal_Paz-Fridman
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

If you have a large rulebase, I recommend using a Services Group with clearly defined properties. This helps keep the rulebase cleaner and also allows you to make a single-click change that applies to all rules using the same Services Group.

the_rock
MVP Diamond
MVP Diamond

I also recommend deleting anything unused in object explorer...based on my testing, I found it to be 100% accurate.

Best,
Andy
"Have a great day and if its not, change it"

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events