- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
CheckMates Fest 2026
Watch Now!AI Security Masters
Hacking with AI: The Dark Side of Innovation
CheckMates Go:
CheckMates Fest
I am looking to implement an inline layer that can be used across multiple policies which apply to end users. The end users can come via different GWs and we need a consistent policy across multlple gateways.
My main question relates to access roles and how this works when you have the initial rule of the inline policy as a group of networks from which users come as the src.
Within the access roles, the same group is defined as a specific network. Can I still use the access role within the inline policy that has the initial rule with the group as the source?
So first rule
src: USERS-GROUP
dst: any
Action: Inline Layer - USER-POLICY
Sub rule
src: HR-USERS (Access Role) - Specific Network USERS-GROUP
dst: HR-SYSTEM
svc: HTTPS
Will the sub rule still apply so long as the source of the user will still be within the USERS-GROUP defined on the first rule?
Keep in mind, the way inline layers work is that if traffic hits parent rule (ie main inline layer rule), it will then check all the sub-rules (child rules) within that layer.
So based on example you gave, seems to me that would indeed work fine.
Keep in mind, the way inline layers work is that if traffic hits parent rule (ie main inline layer rule), it will then check all the sub-rules (child rules) within that layer.
So based on example you gave, seems to me that would indeed work fine.
I attached short video that I took from my lab, hope it makes sense.
Thanks, this would be my assumption that so long as connection was coming from a source based on the parent rule, the access role would be applied given that it contains the same source addresses.
Exactly. All you have to remember is that,like with any fw vendor on the planet probably, fact is once traffic hits rule where it gets dropped, there is no more checking done, regardless if you had 5 or 5 million rules : - )
So the any any accept for the default cleanup rule of a layer is just to pass it on to the next later, rather than an allow the traffic through?
Its technically both. If you think about it, say if you have inline layer and child rule is any any drop, traffic hits that inline layer, it will get dropped, no more checking, thats it.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 54 | |
| 41 | |
| 15 | |
| 14 | |
| 12 | |
| 11 | |
| 11 | |
| 11 | |
| 10 | |
| 8 |
Thu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANThu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY