- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi there,
I wanted to start using inline layers.
I am trying to the think how I would edit my user->internet web traffic as this would be the heaviest rule in the rulebase.
I have AC/URL, CA, ThreatPrevention (AV, AB and IPS) and HTTPs inspection blades on R80.30.
I currently have several rules that apply to all my users in AC/URLF and TP.
Would I create an inline layer with Firewall enabled and then sub-layers for each of the blades above? Should I go just one deep when creating these layers or layers within layers? Most of my rules apply to all users.
I created a Content Awareness layer in my rulebase to test and although it works ok, when I try to add extra rules with source/destination Any (parent rule has all my user networks as source) the policy installation throws an error as it doesn't like Any in the source or destination on more than one rules in the layer.
Moreover, I noted that the packets are inspected by my ordered layers irrespective of the fact that I have a catch all rule in the inline layer. Is this expected?
A.
If you have multiple ordered layers, traffic must hit an accept rule in each ordered layer to pass.
If traffic matches a parent rule for an inline layer, the traffic must match a rule in the inline layer to pass (in addition to other ordered layers).
Inline layers have their own “implicit allow/block” setting.
You can nest inline layers in inline layers, though I believe there are issues going more than a few layers deep and/or using too many layers in a policy.
Thanks. What about source and destination being Any in the child rules? For instance I want my user traffic to go through the AC/URLF blade, so I create an AC inline layer with multiple rules. Can I have source and destination Any for these rules, or is this not meant to be? Am I supposed to do this a different way?
Try to use the "Internet" object as the destination for Application Control & URL Filtering rules.
More best practices and generel advices can be obtained from here.
Source Any Destination Any rules tend to be used for cleanup rules (at the end).
You should be using "Internet" as the Destination unless these are custom resources for internal sites where "any" shouldn't be used either.
Hi Phoneboy,
Just checked my inline layers and noticed that the top level rule is being hit opposed to a rule lower down in the inline layer policy, are there any checks or changes I can make to avoid this happening?
Could you please send a screenshot of this and circle which rule is hit and which one should be hit, so we can give you better suggestion? The reason I say this is because you would have say parent rule in inline layer, which goes down to "child" rule if its hit or explicit clean up rule at the bottom of inline layer, but you can also have sub-inline layers inside the actual inline layers that are part of ordered layer.
Andy
Hi Andy,
Tried sending you a message however seems to of reached my limit for today
Yes, just send them to me directly. I will send you my email, so you can also email them to me. I want to see what seems to be the problem here...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 15 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY