NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW-1] Install on GATEWAYS does not work with interface direction set to INBOUND



This is strange.

I manage several firewall from the same rulebase. When I want rules to
apply to all firewalls I use the GATEWAYS object in the "Install On" column
in the policy editor. If I only want the rules to apply to certain
firewalls then I only list the firewalls in the "Install On" column. So far
so good.

Recently this quit working and I'm at a loss to know why. As a workaround I
now must list all my firewalls in the "Install On" column, instead of using
GATEWAYS.

Doing some testing it seems that I can fix the problem, and revert back to
using the GATEWAYS target in the "Install On" column, ONLY if I change the
value of "Apply Gateway Rules to Interface Direction" to "Eitherbound". I
had left it, I thought, at the default of "Inbound" up until now.

How did I stumble upon this? Well I know that when you list the firewalls
individually in the "Install On" column that for that rule the policy is
applied "Eitherbound" so I thought that may have something to do with it.
And apparently it does, but why doesn't "Inbound" work any more?

----------------------------------------------------------------------------------------

Greg Winkler
Systems Manager, IT&S
Huntsman Corporation
Internet Mail: [email protected]
Voice:Fax:=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
If you have any questions on how to change your
subscription options, email Ron Alcatraz at:
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.