- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
I am going through CP labs (11 Security Management Lab.pdf) in Infinity R80.10 training and am observing that in this policy:
Rule 5.5 is being executed on the traffic that should've been subjected to the treatment by the cleanup rule 4.3.
Rules 4.x are in a layer with content filtering blade only and rules 5.x are in a layer with Applications and URLs.
Actually, all of the App Control and URL filtering rules continue working normally.
Can someone tell me why would this be the case?
That would imply the traffic did not match Rule 4, which would be the only way for traffic to get to Rule 5.5.
What is the traffic in question?
VODKA | Smirnoff was blocked with notification.
are you sure the source was within 192.168.101.0/24 but was still matched for parent rule 4 which is sources for 192.168.102.0/24 ?
Positive.
Can you share a screenshot of a log entry showing this?
Sorry, can't do: this was a cloud lab that is destroyed now and I was too slow to get the logs.
If I'll have time, I'll try to replicate it in my own lab.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY