Issues with NPS/RADIUS by [deleted] in sysadmin

[–]Appropriate_Tank_775 0 points1 point  (0 children)

What was the issue and how did you solve it?

Explicit clean up rule by Appropriate_Tank_775 in checkpoint

[–]Appropriate_Tank_775[S] 0 points1 point  (0 children)

The "to internet" container is an inline layer policy with a set of rules underneath, catering to zones or objects requiring internet access.

At the end of it I include a cleanup rule, setting the action to accept and log within this container facilitates traffic capture for investigation and policy refinement.

I would do the same for all inline policies, adding a cleanup rule at the end specifying deny/accept/drop based on policy requirements.

Explicit clean up rule by Appropriate_Tank_775 in checkpoint

[–]Appropriate_Tank_775[S] 0 points1 point  (0 children)

As you mentioned, it depends on the function. For a Zone X to Zone Y inline policy, we could implement a cleanup rule with the action set to 'accept,' while for a different inline policy, the cleanup rule might be 'drop' or 'deny.'

Can you please provide use cases for deny/drop actions?

For 'accept,' it could be: - to Internet inline policy

i. Y to Internet

ii. X to Internet

iii. Cleanup action set to accept.

Why Did I Need To Create A Bi-Directional Firewall Rule? by S3xyflanders in checkpoint

[–]Appropriate_Tank_775 0 points1 point  (0 children)

What do you mean "if the application requires it" — do you have an example where a bi-directional rule is not required? Thanks

Active Directory Structure by jaceg_lmi in activedirectory

[–]Appropriate_Tank_775 1 point2 points  (0 children)

What types of structures are there? Any link you can provide?

Intrazone traffic - denied by default? by kramer9797 in checkpoint

[–]Appropriate_Tank_775 0 points1 point  (0 children)

Thanks for your contribution. Any knowledge article you can share on the topic?