Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
bob111
Contributor

Https Inspection Internet Object

Hey guys,
In the https inspection policy there is an object called internet, I can guess from the name what it means but what is it actually? Is it like any? Also I saw somewhere that said that using the internet object determines weather the traffic is considered inbound or outbound which sounds weird, is that true?

0 Kudos
6 Replies
bob111
Contributor

Also, is there a difference between the inbound and outbound, or does it just depend on the certificate you should put in the certificate column of a certain rule

0 Kudos
AkosBakos
Advisor

Hi @bob111 

The Internet object in the Application Control & URL Filtering policy actually only applies to traffic that's leaving an interface marked as external.

https://community.checkpoint.com/t5/Management/quot-Internet-quot-object-Internet/m-p/21030#M16513

0 Kudos
bob111
Contributor

Thanks! Do you know when traffic is considered outbound or inbound in https inspection? Is it just according to the certificate you put in a rule?

0 Kudos
AkosBakos
Advisor

Hi,

I don’t think that the cert influances the direction of the traffic.

0 Kudos
AkosBakos
Advisor

Hi @bob111 

And the official SK: https://support.checkpoint.com/results/sk/sk64543

"Internet" means "include all traffic from Internal directed to External or DMZ according to gateway topology".

 

0 Kudos
the_rock
Legend
Legend

Internet object strictly means ONLY external ip addresses. Unlike any, which means both internal/external.

Personally, I use Internet object for urlf ordered layer, though can be used in any layer where urlf blade is enabled in policy layer settings.

Makes sense?

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events