Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor

Monitor Mode Interface Policy Installation Error Despite Correct Topology Settings

Hello everyone,
I'm having trouble installing policies on a firewall that is operating in Monitor Mode. According to the guide, I followed these steps:

  1. Selected the interface in Monitor Mode and clicked Edit.

  2. On the General page, under the General section, I entered a random IPv4 address (ensuring it does not conflict with any existing address on the network).

  3. In the Topology section:

    • Clicked Edit.

    • In the Port To section, selected Undefined (Internal).

    • In the Security Zone section, selected According to topology: Internal zone.

  4. Clicked OK to close both the Topology and Interface windows.

However, when I try to install the policies, the installation fails and I get an error.

Status: Failed
- The Topology information must be configured for objectXXXX, interface ethX-XX, in order to use the selected features.
- Failed to generate the rulebase
- Operation ended with errors.

I’ve also made sure the Anti-Spam and E-mail Security blades are not enabled, as they’re not supported in a Mirror Port configuration.

My question is:
Should I just add the Internal zone in the rule, even if it's an accept rule? Or is there something else I need to configure to make it work correctly

The gw is in S1C

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

What version/JHF is the gateway?
Which specific documentation?
This is what I have historically used:
https://support.checkpoint.com/results/sk/sk101670 

0 Kudos
RemoteUser
Advisor

Version: JHF98 R81.20
Configuring a Single Security Gateway in Monitor Mode 
Procedure 3

0 Kudos
PhoneBoy
Admin
Admin

Do you have rules that involve "Internet" or made changes to the standard Threat Prevention profiles?
Some of those features require an interface to be marked as External.
It sounds like none of your interfaces are in this case.

0 Kudos
RemoteUser
Advisor

Right now, I have three Ethernet interfaces configured: one for the MAAS tunnel, one to access the gateway via SSH (management), and the standard 192.168.1.1 for management. However, I can't configure the other interface, which would be for monitoring, even after following all the steps (at least it seems that way to me)

0 Kudos
RemoteUser
Advisor

I have maybe 5 rule and the last one is:
any > any > accpet

 that accepts all traffic:

NoNameSourceDestinationVPNServices & ApplicationsActionTrackInstall On

1

Accept All

*Any

*Any

Any

*Any

Accept

Log

Object of
Security Gateway
in Monitor Mode

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events