Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SecdetKrypton
Contributor
Jump to solution

How to add 'Internet' object to a policy.

I want to create a policy and use as destination the cloud 'Internet', but not the object 'all_Internet' — I want the cloud Internet.

0 Kudos
2 Solutions

Accepted Solutions
TurgutKaplanogl

More details are needed regarding your question but my assumption is that you want to use the Internet object coming from the App & URL blade. For that you need to enable the Application & URL feature in the policy.

In addition you also need to enable Application Control and if you have the license URL Filtering on the Cluster/Gateway object. Depending on the usage scenario, either both of them or only one of them may be sufficient.

Alternatively if there is a licensing limitation instead of using the Internet object you can assign a Zone to the external interface and use that Zone as the Internet object.

View solution in original post

0 Kudos
(1)
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Which object(s) you can use depends on the enabled blades.

The Internet object as described would usually require AppC / URLF blades.

CCSM R77/R80/ELITE

View solution in original post

9 Replies
Vincent_Bacher
MVP Silver
MVP Silver

I'm a bit lost. Could you please explain exactly what you mean by “cloud internet”?

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
Danny
MVP Platinum
MVP Platinum
TurgutKaplanogl

More details are needed regarding your question but my assumption is that you want to use the Internet object coming from the App & URL blade. For that you need to enable the Application & URL feature in the policy.

In addition you also need to enable Application Control and if you have the license URL Filtering on the Cluster/Gateway object. Depending on the usage scenario, either both of them or only one of them may be sufficient.

Alternatively if there is a licensing limitation instead of using the Internet object you can assign a Zone to the external interface and use that Zone as the Internet object.

0 Kudos
(1)
SecdetKrypton
Contributor

Thanks to everyone, indeed the cloud symbol used to represent the internet—I managed to obtain it by enabling URL filtering and app control directly in the rule base policy configurations I had. Thanks.

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Which object(s) you can use depends on the enabled blades.

The Internet object as described would usually require AppC / URLF blades.

CCSM R77/R80/ELITE
the_rock
MVP Diamond
MVP Diamond

Chris is 100% correct...you need urlf/appc blades enabled for that.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Vincent_Bacher
MVP Silver
MVP Silver

One thing that still puzzles me is that SK specifically refers to the ‘cloud internet’ rather than simply the ‘internet’.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
the_rock
MVP Diamond
MVP Diamond

I find that interesting as well.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

Presumably talking about the object which has a cloud as its icon. This is the object which requires App Control/URL Filtering to be enabled.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events