I'm stuck why this doesn't work, but basically I'm trying to allow devices connected to the LAN network of my SMB device access to the internet over certain ports.
Background: Locally managed 1430 appliance running R77.20.87
Access Policy (Firewall) is set to strict.
![1430a.jpg 1430a.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/20783iA1214695BFD200C4/image-dimensions/497x153?v=v2)
I've created a manual rule in the policy to allow internet access (top rule under Outgoing access to the Internet):
![1430b.jpg 1430b.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/20784i87741C17504F3985/image-dimensions/781x316?v=v2)
The service group "CFU_Internet" contains http, https, and ICMP.
What I'm seeing is traffic from the LAN network (172.x.x.x) to the internet is getting dropped on the last rule in the policy (rule 5 under Incoming, Internal, and VPN traffic):
![2023-05-04_13-55-421430c.jpg 2023-05-04_13-55-421430c.jpg](https://community.checkpoint.com/t5/image/serverpage/image-id/20785i845829E26BB39E4B/image-dimensions/591x378?v=v2)
What am I missing? Why isn't this traffic allowed by the first manual rule I created?
Dave