Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
OlegPowerC
Participant

Internet access rules for proxy and transparent

Hello.

I will use checkpoint as gateway to internet and as proxy server.

First i configured rule for proxy as rule 1 on pictureChProxy1.PNG

And it work.

After this I added rule 2 for transparet access.

After I disabled proxy on browser and enable rule 2 I get internet access.

My question is:

If I want to granulate access to internet with same rules for proxy and transparent, must I duplicate rules?

PS:

One deny rule can work for both method (proxy and transparent)

0 Kudos
9 Replies
PhoneBoy
Admin
Admin

The rules should work either in explicit proxy mode or transparent mode.
However, the gateway does not perform well in explicit proxy mode as the outbound traffic from the gateway will be F2F/slowpath (can't be accelerated by SecureXL).

0 Kudos
OlegPowerC
Participant

Thank You

0 Kudos
Supporto_Checkp
Collaborator

For the traffic from Explicit Proxy to Internet? Is Need a rule? Also a NAT rule?

0 Kudos
PhoneBoy
Admin
Admin

Traffic will be seen as originating from the gateway IP in Explicit Proxy, which will be permitted through Implied Rules.

0 Kudos
Supporto_Checkp
Collaborator

Thanks, and how can i apply app control or url filtering rule?

0 Kudos
PhoneBoy
Admin
Admin

Same as without Explicit Proxy, i.e. the way you configure the rules is exactly the same.

0 Kudos
Supporto_Checkp
Collaborator

so let me make an example:

Client 10.10.10.1

GW 10.10.10.254

Explicit proxy port=3128

Rule for explicit proxy:

10.10.10.1 ---> 10.10.10.254 service 3128 accept

10.10.1.1 --->  App control Service (for example Facebook) accept ??

 

0 Kudos
PhoneBoy
Admin
Admin

Correct

0 Kudos
G_W_Albrecht
MVP Silver
MVP Silver

https://support.checkpoint.com/results/sk/sk110013

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events