Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
HeikoAnkenbrand
Champion Champion
Champion

Special functions via policy - name field

In the past, one of our customers, for example, used the prefix “fast_rule_” in the name field of a firewall policy. This caused the connection to be accelerated directly on the hyperscaler.

At the moment, I am looking for all such prefixes in policy names that trigger special functions.

>>> Are there any others?

Example:
Name_435345.png

Currently, I know of the following:

Name Description of the function
fast_rule_ Maestro Administration Guide - MHO Fast Forward 
PBR_  Firewall rule matching in PBR - sk167135 

 

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips
0 Kudos
5 Replies
the_rock
Legend
Legend

Wow Heiko, thats super interesting find...I did not even know something like could happen. Did you ever verify with TAC?

Andy

0 Kudos
HeikoAnkenbrand
Champion Champion
Champion

The two functions mentioned above do exist.

Ten years ago, with R7x, there was also an extension that forwarded L3/L4 traffic directly on the switch via API. Unfortunately, I’ve forgotten the abbreviation and can’t find the SK anymore.

However, the two parameters mentioned above have been around for quite a while, which is why I didn’t check with TAC again.

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips
the_rock
Legend
Legend

Learn something new every day...honestly, had no idea.

Andy

0 Kudos
PhoneBoy
Admin
Admin

I knew about PBR_ but did not know about fast_rule_.
Not familiar with others.

HeikoAnkenbrand
Champion Champion
Champion

The question is whether there are more.

I once managed layer 4 switches from a certain manufacturer via the policy name field under R7x as well. They were able to set local access lists and accelerate Layer 4 connections directly on the switch.

But for the life of me, I can’t remember the name or the SK anymore.

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events