Well, in this case, it is really only intended for external interface, so that angle shouldn't matter at this point.
BACKGROUND: Customer wanted to implement an IP block list from a feed. I modified some scripts that Check Point originally supplied in an SK to work properly with the feed and create the SAM rules. That part works perfectly. The gateway just won't actually do anything with them.
Small example of configured SAM policy rules:
[Expert@MDC-PROD-FW02a:0]# fw samp get | more
operation=add uid=<5e09eea8,000020a9,0501010a,0000089f> target=all timeout=1367 action=drop log=log comment=intelligo_ip_block service=any source=range:
1.4.244.35-1.4.244.35 pkt-rate=0 req_type=quota
operation=add uid=<5e09eea8,000020ab,0501010a,0000089f> target=all timeout=1367 action=drop log=log comment=intelligo_ip_block service=any source=range:
1.4.246.250-1.4.246.250 pkt-rate=0 req_type=quota
operation=add uid=<5e09eea8,000020ac,0501010a,0000089f> target=all timeout=1367 action=drop log=log comment=intelligo_ip_block service=any source=range:
→ CCSE, CCTE