- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello everyone,
I'm having trouble installing policies on a firewall that is operating in Monitor Mode. According to the guide, I followed these steps:
Selected the interface in Monitor Mode and clicked Edit.
On the General page, under the General section, I entered a random IPv4 address (ensuring it does not conflict with any existing address on the network).
In the Topology section:
Clicked Edit.
In the Port To section, selected Undefined (Internal).
In the Security Zone section, selected According to topology: Internal zone.
Clicked OK to close both the Topology and Interface windows.
However, when I try to install the policies, the installation fails and I get an error.
Status: Failed
- The Topology information must be configured for objectXXXX, interface ethX-XX, in order to use the selected features.
- Failed to generate the rulebase
- Operation ended with errors.
I’ve also made sure the Anti-Spam and E-mail Security blades are not enabled, as they’re not supported in a Mirror Port configuration.
My question is:
Should I just add the Internal zone in the rule, even if it's an accept rule? Or is there something else I need to configure to make it work correctly
The gw is in S1C
What version/JHF is the gateway?
Which specific documentation?
This is what I have historically used:
https://support.checkpoint.com/results/sk/sk101670
Version: JHF98 R81.20
Configuring a Single Security Gateway in Monitor Mode
Procedure 3
Do you have rules that involve "Internet" or made changes to the standard Threat Prevention profiles?
Some of those features require an interface to be marked as External.
It sounds like none of your interfaces are in this case.
Right now, I have three Ethernet interfaces configured: one for the MAAS tunnel, one to access the gateway via SSH (management), and the standard 192.168.1.1 for management. However, I can't configure the other interface, which would be for monitoring, even after following all the steps (at least it seems that way to me)
I have maybe 5 rule and the last one is:
any > any > accpet
that accepts all traffic: NoNameSourceDestinationVPNServices & ApplicationsActionTrackInstall On
|
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY