- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi Guys,
I deployed a CP firewall running R80.10 and I am using App & URL Filtering however, I noticed an abnormal behavior.
For example, I have a policy for Symantec Updates so my policy looks like the following below,
Source: Internal Subnet
Destination: Any
Service & Application: Symantec-Updates
Action: Permit
When I check the logs for the particular rule, I noticed some traffic which supposed to be not there like going to other site not related to Symantec.
I would like to know why is like that, is that normal or my rule is not correct?
Thanks
First, I'd set the destination to "Internet" as opposed to any (unless some of the traffic is destined internally).
It also could be a false positive, in which case the TAC will need to investigate.
thanks for the feedback. Technically, "Internet" and "Any" should be the same right?
I find this thread especially educating on what is Internet when it comes to firewalls:
https://community.checkpoint.com/thread/6099-properly-defining-the-internet-within-a-security-policy
Any literally means anything, including the Internet.
Internet does not include your internal networks.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY