- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi Mates,
I was testing the layered policy approach and got confused a bit. I have created separate layers for FW and APP blade. In my admin access I have allowed SSH access to the FW but I was unable to do so.
When I checked it was hitting the cleanup in the APP layer policy, can somebody help me out with this.
1> How are the policies matched?
2> If the FW layer rule 1 allows the access then why is it coming to the APP layer.
Please help me on this!!!
====
WR,
FH
Hey brother,
Remember what I said on the remote sesison about this? Traffic HAS TO match on ALL ordered layers. So say you have 2 layers and its accepted on first layer, but dropped on 2nd layer, it will not work. If you need more help, we can do another remote as well. In your case, if it is indeed 2 layers, I would do any any allow at the bottom of 2nd layer and then block whatever needed above.
1) They are match top to bottom, left to right
2) Thats how it works for layered rules, traffic has to traverse all layered rules to be accepted
https://community.checkpoint.com/t5/Partner-Community/Layered-rules-approach/m-p/242051
Andy
Suggest you read the following community posts (they're older, but still relevant)
TL;DR: If you have multiple ordered layers, traffic must match an accept rule in each layer, otherwise the traffic will not pass.
Hey brother,
Remember what I said on the remote sesison about this? Traffic HAS TO match on ALL ordered layers. So say you have 2 layers and its accepted on first layer, but dropped on 2nd layer, it will not work. If you need more help, we can do another remote as well. In your case, if it is indeed 2 layers, I would do any any allow at the bottom of 2nd layer and then block whatever needed above.
1) They are match top to bottom, left to right
2) Thats how it works for layered rules, traffic has to traverse all layered rules to be accepted
https://community.checkpoint.com/t5/Partner-Community/Layered-rules-approach/m-p/242051
Andy
If you wish to do another quick zoom remote, Im good till 7.30 pm your time, or between 10.30-11.30
Andy
Sounds good, will send you zoom for that time 10 mins before.
Andy
Sent you link directly.
Just to update, had quick remote with the guys and I explained that traffic has to be accepted on EVERY ordered layer and whatever is dropped on the network (1st layer), wont need to go through any other layer.
Andy
No problem! Now that I had some garlic naan bread, I feel better, haha.
Cheers mate.
Andy
Suggest you read the following community posts (they're older, but still relevant)
TL;DR: If you have multiple ordered layers, traffic must match an accept rule in each layer, otherwise the traffic will not pass.
Thats pretty much what I showed the guys in my lab, so Im 100% sure they are clear now 🙂
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
10 | |
7 | |
6 | |
5 | |
5 | |
5 | |
5 | |
4 | |
4 | |
4 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY