Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Lukasz_Pienkows
Explorer

Internet related rules

Hi,

I've been asked to provide rules for Internet traffic. Customer wants to know what is allowed towards Internet.

Is there any way to do it?

I have MDS setup with per-Customer CMAs.

 

Thanks

Lukas

0 Kudos
2 Replies
Chris_Atkinson
Employee Employee
Employee

There are a few ways to achieve this.

One option is possibly using "packet mode" and  searching for a destination that is not an RFC1918 address.

Refer:

https://community.checkpoint.com/t5/Management/Search-through-your-policy-using-R80-10-new-Packet-Mo...

CCSM R77/R80/ELITE
0 Kudos
PhoneBoy
Admin
Admin

Rules that potentially involve the Internet have a few possible characteristics:

  • Destination of Any (or All_Internet)
  • Destination of Internet
  • Destination involving an external Security Zone
  • Destination involving an IP that is not RFC-1918 

I presume you can write a script to parse the output of show-rulebase and pull out the rules in a specific policy layer that meet these requirements.
If you use show-as-ranges true in the call, you'll get the IP addresses covered by the rule, which should help in identifying such rules.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events