Hi,
while testing ordered layers for a customer, i ran over a behaviour i cannot explain to myself - perhaps someone else can (?):
at top layer:
Accept communication "any to any with any service" but "tracking: none"
(cleanup rule of a small policy to block traffic from/to defined ips)
subordinated layer:
communication is allowed with tracking enabled (log)
my understanding is now, that in logs i get rulename and number of the access rule hit at the subordinated layer.. instead i get the cleanup allow rule of the top layer with tracking set to "none"
Looking into SmartTracker no informations regarding the matched rule is being given
Setup:
Virtual Management Server, virtual Check Point Gateway (GAiA) and physical smb device. all updated to las recent versions. behaviour can be seen with logs of both gateways
Someone has an idea what is wrong? or is this kind of an expected behaviour?