Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor
Jump to solution

Inline layer Question

Hi everyone,
Is there a limit to the number of inline layers you can use?

0 Kudos
1 Solution
3 Replies
RemoteUser
Advisor

thanks Emma, 

I have a task to set up, specifically to minimize the number of inline layers we’re using, given that this policy package contains more than 6,000 rules. How can we do this, considering that most of these rules are either S2S or specific access role rules for different companies? Are there any best practices for inline layers that I could use with access roles or S2S? Or is it always recommended to use point-based rules?

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Short answer: It Depends.

If you have access to/from different companies involved in your policy then an inline layer per company is definitely a good idea. You can use VPN communities or access roles in parent rules for inline layers if that makes sense for what you're doing. There's not one best practice that can fit them all so really it comes down to what makes sense for your traffic and for your administrators. My feeling is always that a policy that makes sense for the people maintaining it is usually better than trying to force people to adhere to some imagined gold standard that doesn't really fit the purpose.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events