- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Without having a separate VRF for Management traffic I have added PBR rules to facilitate this for the Management interface which is connected to a downstream router that does the L3 routing for Internal networks. It is a simple PBR matching the source IP of the Management interface 10.254.254.61 and the 10.253.253.0/24 destination network where a client would be sourcing Management traffic ( HTTPS,SSH) The action table is also simple where the route back to the 10.253.253.0/24 destination network has next hop gateway IP 10.254.254.1 of the downstream router that the Checkpoint Management interface is connected to ( out-of-band from normal data traffic ). Of course there is a more generic route configured on the firewall for the internal private IP subnets pointing to the downstream router on a separate transit interface. The interesting part is that SSH management traffic gets routed appropriately via the PBR, so traffic ingresses the Management interface and egresses the Management interface. However management Gaia Webui 443 traffic does NOT seem to follow the PBR, instead the traffic ingresses the Management interface and egresses the transit interface with the more generic route. I have verified the traffic flows via fw monitor and disabled/enabled SecureXL just to make sure. The PBR does not define service ports. Any ideas?
R81.10 T110 on 6400 Cluster
"Locally-generated traffic" is a PBR limitation per sk167135.
VSX or MDPS may help achieve the separation that you desire.
"Locally-generated traffic" is a PBR limitation per sk167135.
VSX or MDPS may help achieve the separation that you desire.
I did review this SK but wasn't sure if this particular scenario is considered as locally generated as the session is sourced outside of the firewall. Any reasons for only SSH working ?
Is there any plan to resolve the Local-generated traffic limitation?
I recommend approaching your local Check Point office with an RFE if this is needed.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY