Hi,
I have created a rule to allow all IPads to reach to .apple.com domain. The problem is that not all IPads are reaching to that domain, but some still drop, this is my rule:
![ipad to apple.JPG ipad to apple.JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/23637iF76D52A0560C7820/image-size/large?v=v2&px=999)
Source: Ipad network
destination: .apple.com domain
services and application: any
Action:accept
Track:log
The IPad network is 10.10.32.0/19. After adding that rule some IPads are accepted to reach .apple.com:
![accept to 17.JPG accept to 17.JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/23638i8DDCF9E2F16FF702/image-size/large?v=v2&px=999)
And some still drop:
![drop to 17..JPG drop to 17..JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/23639iC87F7818AFC12228/image-size/large?v=v2&px=999)
So why some are still dropping? They are reaching to the Cleanup rule 59.12, where 59.3 is to accept all connections to Apple?!
59 is an Inline layer where IPad network is in the source of it.
What do I miss here?!