> Source: [sk118035](https://support.checkpoint.com/results/sk/sk118035)

# sk118035 - Managing Firewall Access Policy in Spark Management

| Property | Value |
|----------|-------|
| Solution ID | sk118035 |
| Date Created | 2017-07-17 |
| Last Modified | 2024-09-26 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1500, 1900, 2000, 1600, 1800 |

## Solution

### Introduction

The [**Quantum Spark Management**](https://portal.checkpoint.com/dashboard/sparkmanagement) application in [Infinity Portal](https://portal.checkpoint.com/) (this application replaced the "Security Management Portal", see [sk180467](https://support.checkpoint.com/results/sk/sk180467)) can manage the central **Access Policy** for these Quantum Spark Gateway models:

* Small and Medium Business Appliances (600, 700)
* Branch Office Appliances (1100, 1400, 1500, 1600, 1800, 1900, 2000)
* Rugged Appliances (1200R)

In Quantum Spark Management, an administrator can configure Access Policy rules in a **Plan** (that is assigned to many Gateways) or a specific **Gateway** object.   
These Access Policy rules apply to:

* Outgoing access to the Internet
* Incoming, Internal and VPN traffic

On each Quantum Spark Gateway, a local administrator can configure local Access Policy rules that supplement the central Access Policy rules (the the central Access Policy rules always have a higher priority).

In Quantum Spark Management, an administrator can configure the central rules that must apply in these cases:

* Central rules that must apply **before** the local rules - the "**Pre local rules** ".  
  On a Quantum Spark Gateway, these "Pre local rules" have priority over local rules that a local administrator configured.

* Central rules that must apply **after** the local rules - the "**Post local rules** ".  
  On a Quantum Spark Gateway, the local rules that a local administrator configured have priority over these "Post local rules".

### **Notes**

* The Quantum Spark Gateway enforces the rules in this order:
  1. "Pre local rules" configured in Quantum Spark Management (appear as read-only on the Quantum Spark Gateway)
  2. Local rules configured on the Quantum Spark Gateway
  3. "Post local rules" configured in Quantum Spark Management (appear as read-only on the Quantum Spark Gateway)

### Availability

* This feature is supported on Quantum Spark Gateways running these firmware versions:
  * R81.10.00 and higher
  * R80.20.30 and higher
  * R77.20.81 and higher
* Applying the Next Generation mode on Quantum Spark Gateways running firmware versions lower than R80.20.30 is not supported, and such policy is ignored.
* Rules with Updatable Objects, except Geo Location, are supported only on Quantum Spark Gateways running firmware versions R80.20.35 and higher.
* Rules with Wildcard objects are supported only on Quantum Spark Gateways running firmware versions R81.10.08 and higher.
* Rules with multiple objects are supported only on Quantum Spark Gateways running firmware versions R81.10.15 or higher.

### Known Limitations

1. Rules for Zone objects are not enforced, if the target Quantum Spark Gateway does not have the relevant physical ports.

   For example:
   1. Rules with the source or destination "DMZ Network", or "LAN Network" / "DMZ Network" are disabled on Quantum Spark Gateways without a DMZ port (1530, 1550 models).
   2. Rules with "Wireless Networks" objects are disabled on Quantum Spark Gateways that do not have Wi-Fi.
   3. Rules with the source "Internet" for incoming traffic are disabled.
   4. Service objects with multiple ports are not supported on 1500, 1600, and 1800 appliances. The administrator must not create a service object with multiple ports.
2. Access Policy mode limitations:

   1. Rules for Updatable objects and applications that do not exist on the Quantum Spark Gateway are ignored.
   2. Rules for IPv6 objects are ignored when the IPv6 mode is disabled on the Quantum Spark Gateway.
3. For general known limitations, see:

   * [sk178604 - Check Point R81.10.X for 1500, 1600, 1800, 1900, and 2000 appliance Known Limitations](https://support.checkpoint.com/results/sk/sk178604)

   * [sk159772 - Check Point R80.20.X for 1500, 1600, and 1800 Appliances Features, Known Limitations and Resolved Issues](https://support.checkpoint.com/results/sk/sk159772).

   * [sk105380 - Check Point R77.20.X for 600 / 700 / 910 / 1100 / 1200R / 1400 Appliance Features and Known Limitations](https://support.checkpoint.com/results/sk/sk105380).

### Documentation

* [Quantum Spark Management Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Quantum-Spark-Management/Default.htm)

* [sk179615 - Quantum Spark Appliances - Releases R81.10.X](https://support.checkpoint.com/results/sk/sk179615)

* [sk165734 - Quantum Spark Appliances - Releases R80.20.X](https://support.checkpoint.com/results/sk/sk165734)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
