Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JH_Ranger
Participant

Legacy MAB Policy Enforcement Order

Hi CheckMates,

I am curious about the policy enforcement order of the Legacy MAB policy. I understand that with the Unified Policy, it's possible to create Inline/Ordered layers and implement the MAB into that. But when is the Legacy MAB policy enforced? Before or after the Access rules?

I noticed that some MAB rules (in the SmartDashboard) allow a SNX user to a certain resource, but since there isn't a corresponding rule in the Access Rulebase (FW Blade) the traffic is dropped. The logs show a similar story, an "Accept" of the packet hitting the MAB blade, immediately followed by a default drop by the FW blade.

Is it necessary to replicate all rules from the Legacy MAB into the Access policy as well?

Thanks,

R81.10 Take130.

0 Kudos
1 Reply
Wolfgang
Authority
Authority

@JH_Ranger you should don't mix rules for MAB in the unified policy or legacy policy, use only one of them.

Is it necessary to replicate all rules from the Legacy MAB into the Access policy as well? Yes it is, move all rules from legacy to unified.

2024-03-27 06_57_09.png

 

 

 

 

 

 

The behavior how it works with unified policy can be found in the documentation Mobile Access and the Unified Access Policy (checkpoint.com)

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events