Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
yangxcg
Explorer

Application Matching

Hello everyone, may I ask a question? The default port for my SQL application is 3306. Due to business irregularities, the user uses port 3323 for my SQL application. Therefore, an inline layer policy has been added. When the parent policy 1 sets the service to specific port 3323 and the service/application in sub policy 1.1 to any, does the application in sub policy match traffic based on port or signature? That is, when matching the corresponding application in sub policy 1.1, the relationship between port and signature is either or:

reference resources: https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Cont...

According to the prompts inside, port and signature seem to have a strong binding relationship, which means that port and signature need to correspond.

However, after testing, it was found that when connecting to the My SQL database on port 3323 (non-standard port 3306), it can also log in normally and be recognized by the application control. Please help to clarify this. Thank you!

Please help to guide me, thank you!微信图片_20250616212938.png11111.pngpolicy.png

0 Kudos
2 Replies
the_rock
Legend
Legend

I had customer show me this before and we ended up opening TAC case and they did something on their end to fix it.

Andy

0 Kudos
Lesley
Authority Authority
Authority

Can you check here if everything is default and TCP 3323 has not been added?

 
 
 

test.jpg

 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events