- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Hi All,
Am working on rule base cleanup and after i cleaned up few rules i see some hits in my old rules for any service..below is the example . We have R77.30 Mgmt server.
we have created the new rules on top of old rule, now when I checked the usage of old rules only for service I still see the usage in the old rules for the same ports which is allowed on new rules. Please let me know if this is fine to disable the old rules?
For example : Rule 101 (Old) ANY Service
Rule 102 (New) FTP, HTTP
But still seeing hits in old rules for same services.
Vijay
HI the rule order is New rule with limited service on top and same source and destination with ANY service in bottom.
Vijay
Hi Vijay,
If your more specific rule is placed above the less specific one, then the more specific rule should be being hit. Can you share more details around the rules please? And also the log entries if possible?
If your "new" rule is not being hit right now then disabling the old rule will more than likely result in a loss of service.
Regards
Mark
Hi,
My new rule with limited services like HTTP, STP is in top
My old rule with ANY services is bottom of this rule. Both has the same source and destination but the service differs.
VIjay
Hi Vijay,
I understand your rule ordering. However your problem is that your traffic isn't matching your new rule.
To help you diagnose this we need to see log entries to see what is happening in the environment.
Please post further information so that we can help you.
Regards
Mark
Did you push the policy on affected firewall ?
Yes,,,
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY