I'm curious about check point's policy matching method.
Let's take an example
As shown below, sip and custom-made udp-5060 were included in one policy.
So which of the following two ports does the checkpoint match to?
As far as I know, Service is Any, and if there is a port conflict due to the 'match for any' option, it is determined randomly when installing the policy.
However, I cannot find any explanation as to the order in which they are matched when two conflicting ports are added to one policy.
If you know the policy matching logic or have any SK involved, please let me know
Have a nice day and I'll wait for your reply.