- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
One of our server is trying to access the domain "smtp.office365.com" with port 587. We configured Domain object and could see there are some intermittent drop in the firewall by the CLEAN UP RULE.
In the port 587, protocol SMTP is selected and after that we couldn't see drop but the traffic being bypassed.
Please explain by adding the protocol why the traffic is being bypassed.
I would suggest that you should:
- Explain the first configuration including defined objects, their definition and the used rule(s)
- explain how you have changed what where for the second configuration
-. explain the differences in behavior of both configurations and what you mean with bypassed traffic ?
Hi,
PLz see the attachment
In the attachment, server needs to reach Domain Objects with port 587 and there were drops in the logs.
As the port 587 is SMTP, we added the protocol SMTP in the corresponding port.
After that the traffic is bypassed in the logs its showing.
In the attachment you can understand whats going on.
As i do not see the drop logs i can not assume a reason for the drops - but what is meant with bypass ? I only know bypass behavior from TP, an access rule can only accept, reject or drop...
I think the bypass action comes from applicationcontrol. SMTP on Port 587 is Encrypted SMTP. And I think the firewall is smart enough to detect the first connection on standard port 25 and then after seeing a StartTLS command moving to port 587.But doing a bypass because the connection is encrypted and can‘t be inspected without MTA on the gateway.
If you could show us more from the log we can see more needed details.
Wolfgang
The drop is happening in the Final Clean UP RULE and in "fw ctl zdebug drop"it show only the clean up rule block.
Removing the Domain Object in the rule and when giving the resolvable IP in the destination there is no drop.
So is something happening with the the Domain Object or the port 587.
@sajin Much more likely, your domain object cannot be resolved on your FW. Did you check if it is there?
The drop is not happening regularly its intermittent. Among 7-10 accept packet we getting two drop packets.
Tried "fw up_execute" command and the IP is matching with the corresponding rule.
nslookup is working from the firewall.
Hi All,
I have a similar issue, does anyone has a solution handy.
Regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 9 | |
| 8 | |
| 8 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 3 | |
| 3 | |
| 3 |
Wed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY