Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
David_C1
Advisor

Implied rules and dynamic objects

I've been playing with Implied Rules in my lab. Currently have things set like this:

Implied rules config.jpg

With this set, these rules appear (among others):

Implied Rules list.jpg

(we have generally stayed away from implied rules - those rules with source "Any" make me uncomfortable).

My specific question - is there a published list of what all these dynamic objects (e.g. FW1 Management, FW1 Module) are? Is there a way to resolve them on the gateway? (dynamic_objects command doesn't seem to help).

Dave

0 Kudos
6 Replies
the_rock
Legend
Legend

I believe they simply refer to mgmt and fw object(s), but I could be mistaken.

Andy

0 Kudos
David_C1
Advisor

Most of these are somewhat self-explanatory, at least to someone who has been working with Check Point for some time. However, if we enable implied rules in production, we will need to provide a vendor provided explanation of what these objects represent, since they will be part of our access policy. Here's a list of the objects in the implied rules based on my config above:

According to Gateway MTA Settings
MTA enabled Gateways
According to Gateway ICAP Settings
ICAP enabled Gateways
Analyzer Server
FW1 Management
FW1 Module
Log Servers
RT-Physical-Servers
Ldap-Servers
Tacacs-Servers
Radius-Servers
UFP-Servers
CVP-Servers
LocalMachine
NG Policy Server
Reporting Server
SmartPortal
Gui-clients

CPMI-clients

In general, I know enabling implied rules is considered best/recommended practice (by Check Point support), but again, rules with a source of "any" does not strike me as best security practice.  Feedback welcome.

Dave

 

0 Kudos
the_rock
Legend
Legend

I get your point. Honestly, if I were you, I would try get an official TAC answer for this. 

Just my 2 cents...

Andy

0 Kudos
David_C1
Advisor

Andy,

Good suggestion, and I've opened a case. Surprised there isn't documentation around this, but not the first time I've been surprised by similar lack of documentation.

Dave

(1)
David_C1
Advisor

Ticket has been opened and support directed me to sk17745, which provides some information. It's not complete (and honestly doesn't really answer the question I asked) but it's a start. I also found these interesting implied rules that are created when you enable "Accept Control connections"

 

implied rule.jpg

Why interesting?

services.jpg

Either sk52421 is inaccurate or Check Point is enabling rules for services that have not been supported since the stone age.

Dave

 

 

the_rock
Legend
Legend

You really got me curious about it now too. I clicked help section when viewing implied rules and link that comes up is this:

Implied Policy - Rules (checkpoint.com)

On that link, you get directed to below:

https://support.checkpoint.com/results/sk/sk119497

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events