Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Wolfgang
MVP Gold
MVP Gold

questions regarding Security Zones

We have configured Security Zones on an interfaces and some rules with Security Zones as source or destination.

Traffic with destination IP-address of the interface in the defined Security Zone does not match via the rule with zones. I believe the interface IP-address should be included in the defined Security Zone of the interface, but maybe not ?

Another question regarding logging... Is it possible to use the Security Zones as a filter in the logs ?

0 Kudos
7 Replies
Bob_Zimmerman
MVP Gold
MVP Gold

Is the traffic from the zone to itself? If so, I would expect that to match traffic to the firewall.

If instead you're allowing traffic from one zone to another zone, I would expect that to not match traffic to the interface leading to the destination zone. The zone matches traffic which would come in or go out the interface. Traffic to an IP owned by the firewall stops at the routing table and wouldn't go out the interface.

The inherent difficulty of predicting what will match a zone object is a big part of why I dislike them.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

I believe you can do that, yes.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Lari_Luoma
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Zones are basically interface tags or groups. You add interfaces into a specific zone and then create rules based on those zones, for example you can have internal, external and DMZ zones. 
While you can allow traffic based on zones only, it's fairly broad unless you have very specific services behind each interface. Best practice with zones is to use inline layers. 
Parent rule is from zone 1 to zone 2. Then build more granular sub-policy where you can use identities, IPs, applications etc. to match traffic.

Wolfgang
MVP Gold
MVP Gold

@Lari_Luoma parent rules with zones and then inline layer with more granular rules is what we configure.

But return to my questions......

1. Is the interface IP included in the zone of the interface ?

2. Is it possible to define a log filter with zones ?

3. Are Security Zones working with automatic topology calculation ?

Screenshot 2026-09-24 093354.png

 

0 Kudos
Lari_Luoma
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

1. A Security Zone incude whatever traffic comes through that interface. It's not based on IP-addresses. 
2. You cannot directly filter based on zones in the logs. However, you can filter according to the rules or rule names that use zones.
3. Zone is an interface tag/definition and does not interfere with the topology in any way. 

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

For item 1, is the decision based on the routing topology, or is it based on actually passing through the interface?

Let's say you have a firewall with bond1.123 (address 10.0.123.1/24, zone A) and bond1.234 (address 10.0.234.1/24, zone B) a rule which allows traffic from zone A to zone A, and another rule which allows traffic from zone A to zone B.

If 10.0.123.5 tries to connect to 10.0.234.5, that should match the A-to-B rule.

If 10.0.123.5 tries to connect to 10.0.123.1, I would expect that to match the A-to-A rule. Is that what actually happens?

If 10.0.123.5 tries to connect to 10.0.234.1, that traffic won't ever hit bond1.234, so I expect it to not match the A-to-B rule. Is that what actually happens?

0 Kudos
Lari_Luoma
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

yes, those networks are behind the interfaces in zone A or zone B, so traffic between them should match the zone based rule. If you are only connecting to the interface IP address, I don't think that would match a zone though.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events