Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor
Jump to solution

Which Layer Takes Precedence?

Hi all,
I need clarification on rule evaluation when using Ordered Layers (Access Control + Application Control).

Here’s the scenario:

In the Access Control layer (e.g. rule #25), I allow traffic from 192.168.10.2 to the "Internet" object.

In the Application Control layer (e.g. rule #5), I drop traffic from the same IP to the category "Gambling or malicious site".

If 192.168.10.2 tries to access a malicious site:
My question is simple:
Which rule takes precedence?
Does the final action follow the Drop in the Application Control layer, even though Access Control allowed it?

I want to confirm if traffic must be accepted by all layers to be ultimately allowed, meaning any Drop overrides previous Accepts, correct?

Thanks in advance!

0 Kudos
1 Solution

Accepted Solutions
Tal_Paz-Fridman
Employee
Employee

Look at this:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...

 

Order of Rule Enforcement in Ordered Layers

When a packet arrives at the Security Gateway, the Security Gateway checks it against the rules in the first Ordered Layer, sequentially from top to bottom, and enforces the first rule that matches a packet.

If the Action of the matching rule is Drop, the Security Gateway stops matching against later rules in the Policy Rule Base and drops the packet. If the Action is Accept, the Security Gateway continues to check rules in the next Ordered Layer.

View solution in original post

2 Replies
Tal_Paz-Fridman
Employee
Employee

Look at this:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...

 

Order of Rule Enforcement in Ordered Layers

When a packet arrives at the Security Gateway, the Security Gateway checks it against the rules in the first Ordered Layer, sequentially from top to bottom, and enforces the first rule that matches a packet.

If the Action of the matching rule is Drop, the Security Gateway stops matching against later rules in the Policy Rule Base and drops the packet. If the Action is Accept, the Security Gateway continues to check rules in the next Ordered Layer.

RemoteUser
Advisor

Thank you buddy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events