- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Verify Access Control Policy - desire feature?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Verify Access Control Policy - desire feature?
Hi,
we just recognized following:
Give is a SmartCenter with multiple policies sets. Each policy has a certain firewall assigned. One of the policy set is attached to a 'test firewall' gateway, and only for test purposes.
Running now the verifier on the SmartCenter, it checks *all* security policies, not only the active one (highlighted tab). And if there is something wrong with the 'test policy set', you are not able to verify/push one of the other policies.
Is this a desired feature or a bug?
I was originally under the impression that the policies are independent. At least, you do not use the same objects.
Regards,
Security Management Server R80.20 Jumbo Take 10
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In R80.20, at least, you have to choose the policy you wish to verify.
How are you verifying policy?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hi,
exactly as you described. Via main menu in SmartConsole.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hi,
good point.
Verification has been done on one of the policies.
The verification stopped with errors. However, the test policy had a broken cluster member. (misconfiguration on the test gateway)
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You wrote: if there is something wrong with the 'test policy set', you are not able to verify/push one of the other policies.
Can you provide more details and screenshots ? Never have encountered such an issue...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hi,
sorry, can't really share a screenshot (customer system)
And it we recognized this 2 times. Obviously when someone 'played' in the test policy/test-gw.
So, meanwhile I assume. There should be no impact between the poliy sets when you are not using the same objects.
Thanks
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can obfuscate / blacken any screenshot to hide customer details !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
