Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Emil_T
Collaborator
Jump to solution

Custom Intelligence (IoC) Feeds protection directions - inbound / outbound

Hi

I need a clarification regarding protection direction of the feature. The article https://support.checkpoint.com/results/sk/sk132193 does not explicitly mention whether the protection applies to inbound, outbound or bi-directional traffic. I've come across some discussions around it, but would prefer a more clear / official answer.

Based on testing I performed, it appears that the feature blocks only inbound traffic. For example, if one sends ping (icmp echo request) from LAN to internet, the request is accepted, but the corresponding reply is blocked blocked. Same with telnet or any other protocol. The unidirectional enforcement may not align with standard security requirements which typically expect traffic  to be restricted in both directions.

 
 

image.png      image.png

 

  1. Is there any formal documentation or knowledge base article that confirms the intended protection direction ?

Thx

0 Kudos
1 Solution

Accepted Solutions
the_rock
MVP Gold
MVP Gold

I also got confirmation last year from TAC it would only apply inbound. The sk you mentioned is the best reference. 

Andy

Best,
Andy

View solution in original post

0 Kudos
4 Replies
the_rock
MVP Gold
MVP Gold

I also got confirmation last year from TAC it would only apply inbound. The sk you mentioned is the best reference. 

Andy

Best,
Andy
0 Kudos
Emil_T
Collaborator

The should really state it clearly in the documentation. It's very misleading.

0 Kudos
the_rock
MVP Gold
MVP Gold

I understand. You can always give feedback at the bottom and mention it.

Andy

Best,
Andy
0 Kudos
the_rock
MVP Gold
MVP Gold

I just gave the feedback and got automated email right away. I will update you once someone responds.

Andy

Best,
Andy

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events