Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Benjamin_Hofst1
Participant
Jump to solution

Anonymizer matches all traffic

I am a bit struggling with an Anonymizer drop Rule. A rule basically like this 

internal to external Anonymizer drop

This rule matches any traffic from inside to outside. This rule starts to create 'accept' logs. The accept logs are logs were Application Control was not able to finish Application classification because of insufficient data transmitted. This is also happening for traffic that should be dropped by the cleanup rule. 

Does Check Point really accept / forward packets until the Classification did finish or not finish, even the traffic should be dropped by another Rule below this "internal to external Anonymizer drop" Rule (like the clean up rule). 

The Anonymizer App Group matches TCP Port 1-65535 and UDP 1-65535. I think this is the reason it matches "almost" all my traffic from inside to external. But i don't like it when the Firewall Accepts Traffic until the classification is done for Traffic that should be dropped by the cleanup Rule. 

Can I do something against that?

Regards

 

0 Kudos
6 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events