## Application Control Bug!?

Hi guys,

Yesterday, we had some problems with application control, which I didn't understand.

We use a central configured(SMP) 730 appliance with version R77.20.81 (990172541).

We also use the firewall blade in strict mode and the application control is activated too:

So we configured something like that:

Outgoing access to the Internet

| Source | Destination | Application | Service | Action |
| --- | --- | --- | --- | --- |
| LAN networks | Internet | ANY | 80, 443 | Accept |
| LAN networks | Internet | ANY | 50, 123 | Accept |

Incoming, Internal and VPN traffic

| Source | Destination | Application | Service | Action |
| --- | --- | --- | --- | --- |
| VPN Domains | VPN Domains | ANY | Any(encrypted) | Accept |

Additional we have the auto generated rules in the outgoing access tab(application control):

The undesired applications contains following elements:

So we tested the connection between to branches, which are connected via S2S VPN(which is working correctly).

The most protocols worked fine, but we had some problems with smp and rdp.

So i checked the log and found that:

There I could see that the application control blocks internal(vpn) traffic on the outgoing interface.

How we can see above, there aren't application block rules configured in the "Incoming, Internal and VPN traffic" section. Nevertheless the traffic over port 3389 between the internal networks 192.168.14.x and 192.168.10.y was blocked.

So I had to configure an outgoing rule for internal networks, which allows the communication between the defined vpn networks:

As soon as I activated this rule, the communication via the rdp and smb protocol was working properly.

Has someone the same problem?

Is this a application control bug?

Thanks a lot.

Best Regards

Severin Dellsperger

- Tags:
- [smb and smp](https://community.checkpoint.com/t5/tag/smb%20and%20smp/tg-p/board-id/smb-smp)

- [smb configuration](https://community.checkpoint.com/t5/tag/smb%20configuration/tg-p/board-id/smb-smp)

[3\\
\\
\\
Kudos](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1350/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33513?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

- [All forum topics](https://community.checkpoint.com/t5/Spark-Firewall-SMB/bd-p/smb-smp/page/131 "Spark Firewall (SMB)")
- [Previous Topic](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Alias-for-Ips/td-p/78518 "Alias for Ips")
- [Next Topic](https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-w-h-many-remote-access-users/td-p/78187 "SMB w/h many remote access users")

20 Replies

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2019-02-1402:07 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1351)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33514/highlight/true#M1351)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1351/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33514)

I would assume that this is the result of using a Strict Policy - you always have more work when enabling it as some things will not work without manual configuration. Here we see the reason why Default Policy is the suggested setting .

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1351/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33514?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[sdellsperger](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23318)

Contributor

‎2019-02-1402:16 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1352)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33515/highlight/true#M1352)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1352/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33515)

[In response to G\_W\_Albrecht](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33514/highlight/true#M1351)

Yeah, I understand what you mean, but theoretically it should work without this additional rule. It also doesn't make sense to put a rule with a internal network as destination to the outgoing section, no matter if the blade is used in strict or default mode, does it?

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33515?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2019-02-1402:25 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1353)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33516/highlight/true#M1353)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1353/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33516)

I think APP control considers everything that is not a local network to be 'Internet' (including peer VPN domains). That's why traffic is blocked, it matches auto generated rules. 'Incoming, Internal and VPN' is for firewall blade only.

[2\\
\\
\\
Kudos](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1353/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33516?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[Pedro\_Espindola](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4362)

Employee

‎2019-02-1404:07 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1354)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33517/highlight/true#M1354)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1354/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33517)

This Outgoing and Incoming separation sometimes causes some confusion.

The text "Incoming, Internal and VPN traffic" means "Incoming Internet and Incoming VPN Traffic"

Outgoing actually means "To the internet and applications to remote peers".

So you always need at least 2 rules for VPN if you want two-way traffic and it is not possible to just put both domains in one group and use as src and dst. Strict mode is weird, but I don't think that is a bug.

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1354/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33517?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[sdellsperger](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23318)

Contributor

‎2019-02-1404:23 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1355)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33518/highlight/true#M1355)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1355/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33518)

[In response to Pedro\_Espindola](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33517/highlight/true#M1354)

Im not sure if this is correct:

I can see traffic from local network to a vpn peer, which takes the Incoming/Internal interface.

For example:

If it would be like you said, there should be a external rule, but we can see the inbound interface...

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33518?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[Pedro\_Espindola](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4362)

Employee

‎2019-02-1404:40 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1356)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33519/highlight/true#M1356)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1356/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33519)

[In response to sdellsperger](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33518/highlight/true#M1355)

I see. Well, what I told you is what I found out from my experience, but you are right, the behavior does not match what the logs say.

You will also notice that outgoing traffic never generates firewall logs. So the way firewall and application layers work seem to be much more complicated than this simple "Outoing and Incoming" separation makes us believe.

Anyway, I think you will always need to allow the traffic in the outgoing rules in strict mode.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33519?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2019-02-1404:42 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1357)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33520/highlight/true#M1357)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1357/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33520)

[In response to Pedro\_Espindola](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33519/highlight/true#M1356)

Right - therefore it is called strict...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33520?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[sdellsperger](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23318)

Contributor

‎2019-02-1405:00 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1358)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33521/highlight/true#M1358)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1358/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33521)

[In response to Pedro\_Espindola](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33519/highlight/true#M1356)

Thanks for the info, nevertheless I'm very unhappy with this concept.

For me this all makes no sense.

Just saying "don't use strict mode, cause it's not recommended" doesn't sound like a solution for me.

Is there a official statement or documentation from checkpoint, where I can read this definitions?

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1358/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33521?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[Pedro\_Espindola](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4362)

Employee

‎2019-02-1405:48 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1359)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33522/highlight/true#M1359)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1359/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33522)

[In response to sdellsperger](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33521/highlight/true#M1358)

Recommending Standard mode does not mean "Don't use Strict mode". I use it sometimes and works fine, but it is a lot of work.

Plus, in Standard mode you also need VPN rules in the outgoing rule set. The difference is that you already have the automatic "accept all" cleanup rule, but the concept remains the same.

That is not even the reason why Strict mode is not recommended. The reason is that there are no IMPLIED rules, so you get drops in the most unexpected traffic, such as communication between cluster members. And configuring dozens of rules in WebUI is a pain and visually horrible, not at all organized like in SmartConsole.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33522?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[sdellsperger](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23318)

Contributor

‎2019-02-1406:12 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1361)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33524/highlight/true#M1361)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1361/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33524)

[In response to Pedro\_Espindola](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33522/highlight/true#M1359)

Yes you are right, but unfortunately it really seems nobody is using this firewalls in the strict mode, because its (too) much of work.

We never use VPN rules in the outgoing ruleset and it works always fine. We just have some problems with the application control...

I don't agree with you: If you wouldn't have implied rules in strict mode, the gateway coulnd't get updates online or wouldn't have problems with vpn connections, which isn't the fact...

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33524?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[Pedro\_Espindola](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4362)

Employee

‎2019-02-1505:00 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1365)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33528/highlight/true#M1365)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1365/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33528)

[In response to sdellsperger](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33524/highlight/true#M1361)

Ok. Then it has very few implied rules.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33528?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[sdellsperger](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23318)

Contributor

‎2019-02-1505:02 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1366)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33529/highlight/true#M1366)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1366/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33529)

[In response to Pedro\_Espindola](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33528/highlight/true#M1365)

Yes, I think there only essential rules for "This GW"-object.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33529?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2019-02-1406:02 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1360)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33523/highlight/true#M1360)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1360/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33523)

I agree for one thing... This way of separating traffic is misleading and confusing. And I have not seen so far good technical documentation about it.

Note that when you put "encrypt" for a rule you are only telling the gateway that it should first try to encrypt/decrypt packet and then process it. Once that happens it is then processed by the firewall and handed over to other blades for inspection. And those other blades do not necessarily follow the same way to determine packet direction. Like for example application control determines what is Internet based on automatic topology calculation. It is not aware that this was VPN traffic before that.For it 192.168.14.0/24 is just another Internet network because it does not have it configured as a local one.

There is nothing wrong with using Strict policy. But the way to configure it can definitely be better.

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1360/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33523?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[sdellsperger](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23318)

Contributor

‎2019-02-1407:34 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1362)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33525/highlight/true#M1362)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1362/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33525)

[In response to HristoGrigorov](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33523/highlight/true#M1360)

Yes, it's very confusing...

Thanks for your answer. Like you described it makes absolutely sense, the application control gets the packet after the firwall blade and checks if it's outgoing traffic and then blocks/allows the packets.

What do you mean with "There is nothing wrong with using Strict policy. But the way to configure it can definitely be better."?

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33525?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[PhoneBoy](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7)

Admin

‎2019-02-1407:58 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1363)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33526/highlight/true#M1363)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1363/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33526)

Strict policy generally means that any traffic you want to allow through the gateway must have an explicit rule.

With VPN in particular, there are two actions for a given packet:

- For outgoing traffic:
  - Access Policy enforcement based on the unencrypted traffic
  - Whether to encrypt the traffic, which is based on the VPN configuration
- For incoming traffic
  - Whether to decrypt the traffic, which is based on the VPN configuration
  - Access Policy Enforcement based on the unencrypted traffic

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1363/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33526?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[sdellsperger](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23318)

Contributor

‎2019-02-1512:12 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1364)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33527/highlight/true#M1364)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1364/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33527)

[In response to PhoneBoy](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33526/highlight/true#M1363)

Thank you for your answer.

I understand that I have to define explicit rules for any traffic in strict mode, but I don't understand the basic concept.

You said, we have to put and outgoing and a incoming rule for the unecrypted traffic(which makes sense in strict mode).

But in which section do I have to put my rules?

If we don't use the application control, we just use incoming and outgoing rules in the "Incoming, Internal and VPN traffic" section and it's working correctly. As soon we activate the application control, we have to add rules in the "Outgoing access to the Internet" to allow the outgoing (vpn) traffic.

We would like to activate application control only for outgoing Internet traffic and not for vpn traffic, is there any possibility to implement this?

I also don't understand the traffic flow.

How exactly does it work with the different firewall blades, is the following sequence correct?

Outgoing:

1.) Firewall blade(unecrypted traffic)

2.) Application control(unecrypted traffic)

3.) VPN blade(encrypts the traffic)

Incoming:

1.) VPN blade(decrypts the traffic)

2.) Firewall blade(unecrypred traffic)

3.) Application control(unecrypred traffic)

Maybe we can discuss this with a little example:

I've got two networks connected via Site-to-Site VPN tunnel.

network local: 192.168.1.0/24                        network remote: 10.0.0.0/24

I like to allow any traffic between the local and the remote traffic.

In addition packets which are destinated to the Internet should be checked by the application control.

Where and how do I have to put my rules that have following behaviour work propely:

This has to work:

\- SSH session from 192.168.1.10 to 10.0.0.10

- RDP session from 192.168.1.20 to 10.0.0.20

This mustn't work:

\- RDP session from 192.168.1.10 to 88.88.88.88

\- client connection to [www.virus-downloader.ru](http://www.virus-downloader.ru/)

I hope you understand, what we want to achieve.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33527?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[Emilio\_Espinosa](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2425)

Contributor

‎2019-02-1510:16 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1367)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33530/highlight/true#M1367)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1367/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33530)

[In response to sdellsperger](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33527/highlight/true#M1364)

It is just as you say. Outgoing rules include Application Control Blae and as such, it will analyze the traffic between your internal networks, including VPNs as well as your Outgoing traffic. If you don't want to analyze such traffic at all, add a rule bypassing traffic from a group of your internal networks to the same group.

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1367/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33530?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[PhoneBoy](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7)

Admin

‎2019-02-1512:30 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1368)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33531/highlight/true#M1368)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1368/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33531)

[In response to sdellsperger](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33527/highlight/true#M1364)

Basically, VPN outbound traffic is still outbound traffic.

If you want to allow all traffic from your subnet to the remote subnet, there needs to be an explicit rule stating that.

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1368/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33531?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[sdellsperger](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23318)

Contributor

‎2019-02-1804:47 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1369)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33532/highlight/true#M1369)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1369/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/33532)

[In response to PhoneBoy](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33531/highlight/true#M1368)

Thanks, now it makes sense...

Also a thank you to @ [Emilio Espinosa](https://community.checkpoint.com/people/70a27cd8-1569-359a-ba46-2ff45d7a5eeb)

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/33532?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

[Tom\_Hinoue](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8345)

Advisor

‎2020-03-1606:40 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=3275)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/78504/highlight/true#M3275)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/3275/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/78504)

I'd like to share that I was working on a similar case with TAC... and got feedback that the behavior was changed from R77.20.87 Build 990172998 to not inspect APPI for outgoing connections over S2S-VPN; where it did in former builds.

From R77.20.87 Build 990173004, we have a new option in Advanced Settings: \[Application Control and URL Filtering - Inspect VPN traffic\] which is now disabled by default.

Its worth upgrading to the latest R77.20.87 GA if you're using strict firewall policy.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/78504?t:ac=board-id/smb-smp/message-id/1350/thread-id/1350&t:cp=kudos/contributions/tapletcontributionspage&ticket=1yGENvXdoBQU_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

Post Reply

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

| User | Count |
| --- | --- |
| <br>[sx8n20394](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/107449) | 7 |
| <br>[israelfds95](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/93117) | 7 |
| <br>[jorgeluiznim](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/85528) | 5 |
| <br>[velo](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/110726) | 1 |
| <br>[BikeMan](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54723) | 1 |
| <br>[emmap](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054) | 1 |
| <br>[CEEJAY](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/112446) | 1 |
| <br>[Max\_Leorne](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/142185) | 1 |
| <br>[Chris\_Atkinson](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630) | 1 |

[View All ≫](https://community.checkpoint.com/t5/forums/kudosleaderboardpage/board-id/smb-smp/timerange/one_month/page/1/tab/authors)

Trending Discussions

[Reach My Device – A Native Option for Secure Remote Access to Quantum Spark Appliances](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reach-My-Device-A-Native-Option-for-Secure-Remote-Access-to/td-p/280076)

[Downgrading a Quantum Spark Appliance: From 'Upgrade Not Supported' to a Working Boot Loader Recover](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Downgrading-a-Quantum-Spark-Appliance-From-Upgrade-Not-Supported/td-p/279888)

[L2TP Remote Access VPN - Can't Connect on SMB 2550 R82.00.10](https://community.checkpoint.com/t5/Spark-Firewall-SMB/L2TP-Remote-Access-VPN-Can-t-Connect-on-SMB-2550-R82-00-10/td-p/279943)

Upcoming Events

Sort by:

- [All](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513#)
- [Virtual](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513#)
- [In-Person](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513#)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Tue 28 Jul 2026 @ 11:00 AM (EDT)

[Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats](https://community.checkpoint.com/t5/CheckMates-Events/Under-the-Hood-Check-Point-and-Illumio-Modern-Network-Defense/ev-p/279701)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 12:00 PM (SGT)

[The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280019)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 02:00 PM (IDT)

[The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280021)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 03:00 PM (CEST)

[The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280020)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 11:00 AM (EDT)

[TechTalk: On-Premise SD-WAN Management](https://community.checkpoint.com/t5/CheckMates-Events/TechTalk-On-Premise-SD-WAN-Management/ev-p/279370)

Thu 30 Jul 2026 @ 11:30 AM (CDT)

[CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/CheckMates-Live-DFW-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279920)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Tue 28 Jul 2026 @ 11:00 AM (EDT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 12:00 PM (SGT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 02:00 PM (IDT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 03:00 PM (CEST)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 11:00 AM (EDT)

[TechTalk: On-Premise SD-WAN Management](https://community.checkpoint.com/t5/CheckMates-Events/TechTalk-On-Premise-SD-WAN-Management/ev-p/279370)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Thu 30 Jul 2026 @ 10:00 AM (PDT)

[AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway](https://community.checkpoint.com/t5/CheckMates-Events/AI-Security-Masters-E12-READY-OR-NOT-Securing-the-AI-Enterprise/ev-p/277411)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Tue 11 Aug 2026 @ 11:30 AM (EDT)

[New York City: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/New-York-City-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279476)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 13 Aug 2026 @ 11:30 AM (EDT)

[Waltham, MA: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/Waltham-MA-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279475)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 20 Aug 2026 @ 08:30 AM (COT)

[Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA](https://community.checkpoint.com/t5/CheckMates-Events/Medellin-Workspace-Evolution-Hybrid-Mesh-Management-Visibilidad/ev-p/280003)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 20 Aug 2026 @ 06:00 PM (COT)

[Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad](https://community.checkpoint.com/t5/CheckMates-Events/Medellin-Workspace-Intelligence-IA-Generativa-en-Acci%C3%B3n-para/ev-p/280004)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 27 Aug 2026 @ 09:00 AM (CEST)

[Check Point Hands-On SASE and Cloud Workshop - Zurich](https://community.checkpoint.com/t5/CheckMates-Events/Check-Point-Hands-On-SASE-and-Cloud-Workshop-Zurich/ev-p/279914)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Wed 21 Oct 2026 @ 09:00 AM (BST)

[AI Security Workshop - Glasgow](https://community.checkpoint.com/t5/CheckMates-Events/AI-Security-Workshop-Glasgow/ev-p/278505)

[CheckMates Events](https://community.checkpoint.com/t5/CheckMates-Events/eb-p/events)

[Top](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-Control-Bug/m-p/33513)

About CheckMates

- [Getting Started & FAQ](https://community.checkpoint.com/t5/help/faqpage)
- [Community Guidelines](https://community.checkpoint.com/t5/user/TermsOfServicePage)

Learn Check Point

- [Check Point for Beginners](https://community.checkpoint.com/t5/Check-Point-for-Beginners-2-0/bg-p/check-point-for-beginners-2-0)
- [Check Point Trivia](https://community.checkpoint.com/t5/Check-Point-Trivia/bg-p/trivia)
- [CheckFlix Videos](https://community.checkpoint.com/t5/CheckFlix/ct-p/checkflix)

Advanced Learning

- [Check Point Security Masters](https://community.checkpoint.com/t5/Check-Point-Security-Masters/gp-p/ccsm)
- [Tip of the Week](https://community.checkpoint.com/t5/SecureKnowledge-Tip-of-the-Week/bg-p/secureknowledge)
- [TechTalks](https://community.checkpoint.com/t5/TechTalks/ct-p/techtalks%20role=)
- [Training and Certification](https://community.checkpoint.com/t5/Training-and-Certification/bd-p/training-and-certification)

Resources

- [CheckMates Toolbox](https://community.checkpoint.com/t5/CheckMates-Toolbox/ct-p/CheckMatesToolbox)
- [Developers (Code Hub)](https://community.checkpoint.com/t5/Developers-API-CLI/bd-p/codehub)
- [Product Announcements](https://community.checkpoint.com/t5/Product-Announcements/bg-p/products-blog)
- [Upcoming Events](https://community.checkpoint.com/t5/Upcoming-Events/bg-p/checkmates-live)

Non-English Discussions

- [Español](https://community.checkpoint.com/t5/Espa%C3%B1ol/bd-p/spanish)
- [French](https://community.checkpoint.com/t5/Fran%C3%A7ais/bd-p/francais)
- [Japanese](https://community.checkpoint.com/t5/Japanese-%E6%97%A5%E6%9C%AC%E8%AA%9E/bd-p/Japanese)
- [Português](https://community.checkpoint.com/t5/Portugu%C3%AAs/bd-p/portuguese)
- [Russian](https://community.checkpoint.com/t5/Russian/bd-p/russian)
- [Chinese](https://community.checkpoint.com/t5/Chinese/bd-p/taiwan)

YOU DESERVE THE BEST SECURITY

We’re Social. Follow Us [CheckMates on LinkedIn](http://linkedin.com/company/cpcheckmates)  [Check Point on YouTube](https://www.youtube.com/user/CPGlobal) [CheckMates on Facebook](https://www.facebook.com/cpcheckmates/) [CheckMates on Instagram](https://www.instagram.com/cpcheckmates/)

©1994-2026 Check Point Software Technologies Ltd. All rights reserved. [Copyright](https://www.checkpoint.com/copyright/) [Privacy Policy](https://www.checkpoint.com/privacy/) [About Us](https://www.checkpoint.com/about-us/) [UserCenter](https://usercenter.checkpoint.com/)

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
