Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor

HTTPS Traffic Accepted via Implied Rules

Dear mates,

The customer pointed out that a large amount of HTTPS traffic from external public IPs is being accepted by implied rules on the firewall. What could be the reason for this?

Is there any implied rule that allows HTTPS by default?
And in which scenarios should this behavior be considered a concern?

Thanks in advance, as always!

0 Kudos
3 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

0 Kudos
Vincent_Bacher
Advisor
Advisor

In addition, if someone wants to understand what is happening, I would suggest temporarily enabling logging for implied rules. When I first started working with Check Point, this was very useful for me.
https://support.checkpoint.com/results/sk/sk110218

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
the_rock
MVP Platinum
MVP Platinum

Hey brother,

Apart what the guys said, which is all correct, here is what I would recommend. Create a geo block rule on top of the rule base to limit access from countries you wish to block, then below that, rule that allows access to the fw on whatever services needed. Thats how I do it with literally every customer. Then, down the rulebase, you can set up stealth rule, which is src any, dst fw, service any, action drop.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events