Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
vanhieuptit4
Explorer

Check Point allows HTTP/HTTPS without rule

I'm using Check Point R82. I’ve configured NAT for ports 80 and 443 from the internet to a backend server. However, I noticed that HTTP/HTTPS traffic is reaching the backend even though no explicit policy rule has been created to allow it.

 I suspect some Implied Rule might be allowing this by default.

 I tried disabling some implied rule options but it didn’t work — is there any official or correct way to do this in R82?

Thanks in advance!

0 Kudos
4 Replies
Lesley
Authority Authority
Authority

Do you see this traffic in the traffic logs and if so can you paste it here?

-------
If you like this post please give a thumbs up(kudo)! 🙂
vanhieuptit4
Explorer

 

implied log.pngthis is log of firewall

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Have you already reviewed sk105740, sk180808 ?

CCSM R77/R80/ELITE
0 Kudos
Lesley
Authority Authority
Authority

Your NAT rule does not work because rule 0 goes before any other custom made rules. 

I assume you use external VIP IP of the firewall. If you use any other IP you have same issue? If you really want to use VIP IP you can follow this sk https://support.checkpoint.com/results/sk/sk178087

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events