- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hey guys,
Just wondering if someone can clarify this for me and if it is expected because maybe of service (sip) used?
So, customer has setup as example 7-1 in below sk and all works fine, no issus, BUT, rather than bi-directional rule, they have 2 separate ones and randomly, logs that should show for rule 9, show for rule 10 and other way around.
Is that expected? We even ran fw up_execute and shows right rule)s).
Thoughts?
https://support.checkpoint.com/results/sk/sk95369
Tx as always!
Andy
Hey guys,
Just to update on this, spoke with TAC on unrelated case and asked them this question and lady said it is purely cosmetic, but its fixed if jumbo 99 installed on the mgmt, which is what we suggested to the customer.
Cheers,
Andy
I suspect that sometimes the traffic hits the VOIP handler (SIP service) and other times the other defined port. If you could share screenshot of the rules I can check it.
Yep, will ask customer for it.
Andy
Ah in this way. The my first comment is not relevant.
Is it not because of this:
So if traffic hits rule 9 it is an incomming call and rule 10 an outgoing call? Do you see something like this in the logs?
I would not recommend to put it all in one rule. Because then you open traffic between the subnets.
What if you make new rules like below? Then it is still secure and you follow the recommended steps in the guide:
Source:
HQ-Voice
BTC-Edgemark-HQ
Destination:
HQ-Voice
BTC-Edgemark-HQ
sip-tcp
sip
Source:
DR_VOICE-VLAN
BTC-Edgemark-HQ
Destination:
DR_VOICE-VLAN
BTC-Edgemark-HQ
sip-tcp
sip
etc
Hey @Lesley
I definitely asked them to try, lets see. Do you think though doing it this way would be any different?
Andy
Not sure we have to try. Because the documentation is very specific about it.
Btw, spoke with my colleague about this and we asked them to see if they can verify 2 things (well verify 1 and do the 2nd one if willing)
1) Check if there is an updates smart console to install
2) If they are willing to install latest jumbo 99 for mgmt ONLY, as I recall seeing people mention about display logs issue via smart console, just cant recall what take it was fixed it
Andy
Can be done quick, would give this a try. Only log issue I have seen that the interface direction in a log entry was incorrect due bug. Have not seen the issue with rules. This was bug ID:
|
PRJ-47984, |
Logging |
Some Access Rule Base logs may be generated with a wrong interface direction. The issue is cosmetic only. |
What version / take you have active now? can give a quick look. Share please gw and mgmt
Its on R81.20 just cant recall jumbo now, as we dont manage their equipment.
Andy
Hey guys,
Just to update on this, spoke with TAC on unrelated case and asked them this question and lady said it is purely cosmetic, but its fixed if jumbo 99 installed on the mgmt, which is what we suggested to the customer.
Cheers,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 18 | |
| 13 | |
| 12 | |
| 12 | |
| 10 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY