Hi, I am tightening up our rulebase for some new internal network that I have created
I have hit the issue that I several rules that allow certain hosts internet access via having ANY in the destination. This now affects my new subnets as a possible way to access them as matching the ANY destination.
Does anyone have a clever suggestion of a way around this without rulebase changes such as a block rule before all affected rules hits that first then gets denied ( this has ramifications for rule ordering for the allowed accesses )?
The internet access need to be unrestricted hence any so restricting that is not an option
May Thanks
Neil
Clustered Checkpoint R81.10 Take 150 (x2 devices)