Hello-- larger existing CP customer testing Policy-based Routing (aka "PBR") and disappointed on current incantation.
Based on sk100500, it appears that PBR operates at layer4 and currently can't make any decisions based on upper layers -- nor can higher level blades features be applied to traffic AFTER a PBR decision.
Customer would like to do the following. Both not possible today.
- make PBR decision based on identity
- apply URLF policy to traffic following PBR decision.
Any road-map, work-arounds, or insight would be appreciated. Thanks -GA
reference Policy-based Routing -- SK100500
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
excerpts:
Routing and Firewall Processing
It is important to note that routing tables, including PBR tables, are checked after firewall processing is complete.
This means that in situations such as NAT, routing rules are checked against the original source address (refer to sk101562).
The following features/blades are not supported with PBR:
<basically... everything>