Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ascoyne
Contributor
Jump to solution

Rule expiration question

We have never used Time Objects or Rule Expiration so looking for information.

When we set a rule to expire using a Time Object, is the rule deleted or disabled?

0 Kudos
1 Solution

Accepted Solutions
Tal_Paz-Fridman
Employee
Employee

When you set a rule to expire using a Time Object the rule is not deleted; it is effectively disabled. This means that once the time object expires, the rule will no longer be enforced in the policy, but it remains in the Rule Base. If you want to re-enable the rule, you would need to update the time object or create a new one.

 

R81.20 SmartConsole Online Help:
https://sc1.checkpoint.com/documents/R81.20/SmartConsole_OLH/EN/Topics-OLH/NZWusyHm6c__hj6NSFa-VQ2.h...

"A rule using a time object applies only to connections that begin during the time object's time frame. If the connection extends past that time frame, it is allowed to continue. The relevant time zone is that of the Security Gateway enforcing the rule."

View solution in original post

0 Kudos
2 Replies
Tal_Paz-Fridman
Employee
Employee

When you set a rule to expire using a Time Object the rule is not deleted; it is effectively disabled. This means that once the time object expires, the rule will no longer be enforced in the policy, but it remains in the Rule Base. If you want to re-enable the rule, you would need to update the time object or create a new one.

 

R81.20 SmartConsole Online Help:
https://sc1.checkpoint.com/documents/R81.20/SmartConsole_OLH/EN/Topics-OLH/NZWusyHm6c__hj6NSFa-VQ2.h...

"A rule using a time object applies only to connections that begin during the time object's time frame. If the connection extends past that time frame, it is allowed to continue. The relevant time zone is that of the Security Gateway enforcing the rule."

0 Kudos
the_rock
Legend
Legend

@Tal_Paz-Fridman is 100% right. So technically, rule will NOT show as disabled per se, but will be "expired", if you will.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events