Hello Community,
we have an issue with dynamic objects imported from ACI and used in Access Control policy.
When we use static network objects, the traffic works fine. But when we replace it with dyn obj (imported form ACI) for the same subnet, the traffic does not match the rule and gets dropped by cleanup.
Environment:
- Check Point is synced with Identity Awareness on the gateway
- Check Point does not show any error in logs regarding the dynamic object
- In SmartConsole, the dynamic object shows the correct hosts inside
- with fw ctl zdebug + drop, we see traffic dropped by cleanup rule when the dynamic object is used as destination.
Tech Specs:
- Hyperscale Maestro Solution 9700 running VS
- Product version Check Point Gaia R81.20
- HOTFIX_R81_20_JUMBO_HF_MAIN Take: 113
Is this known limitation or bug when using ACI dyn objects?
Are there any recommendations for debugging this further, or a known fix/workaround other then replacing with a static subnet?
Thanks in advance!
K.