Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
the_rock
Legend
Legend
Jump to solution

Certain options missing under action column in management policy

Hey guys,

Hope someone might be able to help me with this, as Im totally stumped what might be "missing". So I was helping client with unrelated issue and realized that in their environment, when they click option more under policy action column, they do NOT get anything I see in my lab (below), except action and captive portal.

I verifed policy layer editor and they have exact same things selected , along with same blades, as I do in my lab.

Any idea whats missing? They also cant see ask and inform like I do in 1st screenshot.

Things we tried:

-made sure smart console is updated, reinstalled R81.20 smart console

-tested a different PC

-rebooted the mgmt

Version is R81.20 jhf 89.

Tx as always.

Andy

 

Screenshot_1.png

 

Screenshot_2.png

0 Kudos
3 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

An actual screenshot from their environment might help.
You should also check the blades enabled in the relevant policy layer as that will impact what shows in the Track column.

image.png

View solution in original post

Tal_Paz-Fridman
Employee
Employee

As @PhoneBoy suggested these options will be shown only if the Layer Editor has Applications & URL Filtering or Content Awareness enabled.

With just Firewall there is no need for them.

 

Layer Editor.png

 

 

View solution in original post

the_rock
Legend
Legend

Hey gents @Lesley @Amir_Senn @Chris_Atkinson @Tal_Paz-Fridman @PhoneBoy 

I figured it out, always learn something new every day, hehe 🙂

So, turns out their policy editor was not exactly same as mine, apologies, I missed something yesterday. Technically, if you ONLY have fw blade enabled inside policy layer, you will NOT see extra options, as I dont see them in final allow layer in my lab where I have fw blade enabled only and I do see those options in first 3 layers.

Thanks guys as always for the help and I attached few screenshots showing this.

Andy

Screenshot_1.png

 

Screenshot_2.png

 

Screenshot_3.png

 

Screenshot_4.png

 

Screenshot_5.png

 

Screenshot_6.png

 

Screenshot_7.png

 

View solution in original post

21 Replies
D_W
Advisor

Is identity awareness completely configured?

0 Kudos
the_rock
Legend
Legend

It is. In my lab, I only have IC configured and works fine. Btw, this is R81.20 jumbo 89, both mgmt and cluster.

Andy

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Do they see the same for a rule where the services column is populated rather than set to any?

CCSM R77/R80/ELITE
0 Kudos
the_rock
Legend
Legend

Hey Chris,

Thats correct, its exactly the same.

Best,

Andy

0 Kudos
Chris_Atkinson
Employee Employee
Employee

To confirm the blades are enabled in the gateway object itself, what about for a rule where the destination is ' Internet' ?

(Your post already indicates you checked the policy layer/package editor blades portion)

CCSM R77/R80/ELITE
0 Kudos
the_rock
Legend
Legend

Yes, blades are enabled. Its same issue even where Internet is the dst object. Literally, no matter what rule swe try this on, result is always the same.

Andy

0 Kudos
Lesley
Leader Leader
Leader

Compare the user check settings under the fw gateway object in smart console. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
the_rock
Legend
Legend

Thanks for that @Lesley , I was going to do that tomorrow as the next step, as I cant think of anything else that might be missing.

Andy

0 Kudos
PhoneBoy
Admin
Admin

An actual screenshot from their environment might help.
You should also check the blades enabled in the relevant policy layer as that will impact what shows in the Track column.

image.png

the_rock
Legend
Legend

Yep, will get that tomorrow.

Andy

0 Kudos
Tal_Paz-Fridman
Employee
Employee

As @PhoneBoy suggested these options will be shown only if the Layer Editor has Applications & URL Filtering or Content Awareness enabled.

With just Firewall there is no need for them.

 

Layer Editor.png

 

 

Chris_Atkinson
Employee Employee
Employee

@the_rock I thought from your original post you had checked this part already, please confirm when able. 🙂

CCSM R77/R80/ELITE
0 Kudos
the_rock
Legend
Legend

Yes, thats the first thing I checked 🙂

Andy

0 Kudos
Amir_Senn
Employee
Employee

All the heavy cannons are here gladly helping=)

Since everyone wrote the answer, I will just add that enabling APPI/URLF as part of the policy is not enough in case of inline layer inside the policy. So if the client is missing those action, maybe the inline layer is not defined as APPI/URLF.

Kind regards, Amir Senn
0 Kudos
the_rock
Legend
Legend

Hey @Amir_Senn 

Thanks for your input, always appreciated man! Hey, thinking about all this, I truly believe that what @Lesley said makes most sense to me, so will verify that with the customer today and update you guys.

Andy

0 Kudos
Amir_Senn
Employee
Employee

UC is on the GW side, the option to mark this is related to policy package. I managed to see the desired actions without any UC blades.

If UC definitions were the way to go it means by removing specific blades it will change setting on policy / make it invalid.

Kind regards, Amir Senn
the_rock
Legend
Legend

Ok, I see what you mean @Amir_Senn , thats also totally logical. But then Im not sure at all why customer does not see them, as their policy editor layer settings are EXACTLY SAME as mine.

Andy

0 Kudos
the_rock
Legend
Legend

@Amir_Senn 

One additional question for you, if you dont mind, please. So, customer mentioned to me last week and I cant for the life of me find where to do this in smart console or if its even possible. I found below thread, but dont believe its what they need.

Any idea? Essentially, say they want to block IP 10.10.10.50 (just as an example) to ONLY be able to access certain thing internally 100 times in 1 hour, thats it.

Possible?

Andy

https://community.checkpoint.com/t5/Security-Gateways/Limit-number-of-connections-from-one-IP-to-che...

0 Kudos
Amir_Senn
Employee
Employee

mmm.... not sure if this is the best solution (IDK the IPS attached) but probably possible with SmartEvent correlated event or even newer and better - Playblocks.

Kind regards, Amir Senn
0 Kudos
the_rock
Legend
Legend

k thank you!

Andy

0 Kudos
the_rock
Legend
Legend

Hey gents @Lesley @Amir_Senn @Chris_Atkinson @Tal_Paz-Fridman @PhoneBoy 

I figured it out, always learn something new every day, hehe 🙂

So, turns out their policy editor was not exactly same as mine, apologies, I missed something yesterday. Technically, if you ONLY have fw blade enabled inside policy layer, you will NOT see extra options, as I dont see them in final allow layer in my lab where I have fw blade enabled only and I do see those options in first 3 layers.

Thanks guys as always for the help and I attached few screenshots showing this.

Andy

Screenshot_1.png

 

Screenshot_2.png

 

Screenshot_3.png

 

Screenshot_4.png

 

Screenshot_5.png

 

Screenshot_6.png

 

Screenshot_7.png

 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events