Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
handiansudianto
Advisor

Network & Application policy

Hello,

On the checkpoint how network policy and application work? Is the network policy will take precedence  than application policy?

On the network policy i have 2 rule (CP1 picture) :

  • Rule number 17 INTERNET_DC_VLAN301 is to allowing some server under VLAN301 accessing to the internet
  • Rule number 18 DC_VLAN301 is to drop rest the server under VLAN301

On the application policy i have rule to allowing all servers (all hosts under DC_VLAN301) access to some specific application such as sophos-update.

With both policy only hosts under group INTERNET_DC_VLAN301 can access to sophos-update even on the source on the application policy set to DC_VLAN301 which contains all host under subnet 301 (10.103.248.0/24)

So i want to know how to make network policy and application policy can work together?

0 Kudos
2 Replies
Chris_Atkinson
Employee Employee
Employee

With ordered layers traffic must match (accept) in both layers to be allowed, please refer:

Ordered Layers and Inline Layers (checkpoint.com)

 

CCSM R77/R80/ELITE
0 Kudos
PhoneBoy
Admin
Admin

You only need to maintain a separate Firewall and App Control policy if you manage any gateways running R77.x (or earlier) code.
Your best bet is to combine them, though that will require manual effort.

In general, if you have multiple policy layers, traffic must match an Accept rule in each ordered layer.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events