Where do we stand as a community in regard to implied rules?
While I understand it is very convinient to have them enabled. The major issue we have is that there is not much one can control in this regard and several of the latest CVE issues I have seen can't be mitigated in full if you rely on implied rules.
Also audits in the past always forced us to disable them as too much information was exposed during pentesting. So it is very easy to fingerprint a Check Point firewall.
It seems Check Point is very, very reluctant to disable them or give a better control on them.
For me this is at the moment the biggest issue we see in terms of exposure management. I am almost forced to put some sort of ACL or firewall before my firewall.
In my experience some of the implied rules can be tough to setup with manual rules. As you may need 3 rules and some tweeks for some very specific traffic.
So in my view the middle ground could be to make the implied rules a sort of layer where you can choose to disable or enable the rules and not actually change them.
I can live with a guideline where I need to sort out my manual rules on my own if I disable any of the implied rules. But it will allow me to do so selectively as was sort of implied in at least one of the recent SKs in regard to a high risk CVE issue. (that information is propably gone by now from the SK.
But this is where as a community we can send a message of how we want our firewalls to work for us. So by all means .... comment on this.
<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>