> Source: [sk119497](https://support.checkpoint.com/results/sk/sk119497)

# sk119497 - Implied rules are generated but not displayed in the Implied Rules view

| Property | Value |
|----------|-------|
| Solution ID | sk119497 |
| Date Created | 2017-08-08 |
| Last Modified | 2025-07-09 |
| Technical Level | General |
| Products | SmartConsole |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * Implied rules are generated but not displayed in the **Implied Rules** view.
* Connections may match implied rules that are not displayed in the **Implied Rules** view.

## Cause

There are implied rules that are only generated when certain blades are enabled, and according to the specific blades' logic.

Not all of these implied rules are displayed in the current GUI view for **Implied Rules**.

## Solution

#### To view the Implied Rules in SmartConsole R80.10 and higher:

> ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk119497/ImpliedViewR80101708080906.png)

#### To view the Implied Rules in SmartDashboard R77.30 and lower:

> ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk119497/ImpliedViewR77301708080904.png)

Below is a list of implied rules that **never** appear in the **Implied Rules** view and when the Management Server creates them:

**Notes:**

* All the implied rules below have the position 'First'.
* "Service" indicates the service objects or IP protocol and port.

Enter the string to filter this table:

|------------------------------------------------|---------------------------------|-------------------------------|---------------------------------------------------------------------|------------|------------------------------------------------------------------------------------------------------------------------------------|
| **Name**                                       | **Source**                      | **Destination**               | **Service**                                                         | **Action** | **Generation condition**                                                                                                           |
| accept_outgoing_connectra                      | Gateway                         | Any                           | Connectra outgoing services                                         | Accept     | 1. Mobile Access blade is enabled 2. IP protocol and port defined in the "connectra_outgoing_services" table                       |
| accept_tunnel_test_community                   | Gateway                         | Any                           | tunnel_test                                                         | Accept     | IPSec VPN blade is enabled                                                                                                         |
| accept_tunnel_test_traditional                 | Gateway                         | Any                           | tunnel_test                                                         | Accept     | IPSec VPN blade is enabled                                                                                                         |
| accept_l2tp                                    | Gateway Any                     | Any Gateway                   | L2TP                                                                | Accept     | 1. IPSec VPN blade enabled 2. Remote Access VPN is enabled                                                                         |
| accept_fw_ica_services_port                    | Any                             | Management Server Gateway     | FW_ica_services                                                     | Accept     | Enabled by default                                                                                                                 |
| accept_fw1_seam                                | SmartEvent clients              | SmartEvent servers            | CP_seam                                                             | Accept     | Enabled by default                                                                                                                 |
| accept_uaa_communication                       | User Authority products         | User Authority products       | FW1_uaa                                                             | Accept     | Legacy Authentication is enabled                                                                                                   |
| accept_av_http                                 | Internal                        | Gateway                       | TCP port 12873                                                      | Accept     | Anti-Virus blade enabled                                                                                                           |
| te_allow_internal_communication                | Threat Emulation Gateways       | Threat Emulation Gateways     | TCP port 18194                                                      | Accept     | Threat Emulation blade enabled                                                                                                     |
| accept_fw1_cvp                                 | Gateway                         | CVP server                    | CVP service port                                                    | Accept     | Resource with CVP is configured                                                                                                    |
| accept_scv_status                              | Remote Access VPN Clients       | Any                           | UDP port 18233                                                      | Accept     | 1. IPSec VPN blade is enabled 2. Remote Access VPN is enabled                                                                      |
| enable_tcpt                                    | Any                             | Gateway                       | Visitor Mode port                                                   | Accept     | Visitor Mode is enabled in the IPSec VPN blade                                                                                     |
| enable_portal_http                             | Internal / All interfaces       | Gateway                       | http https                                                          | Accept     | Access to the Multi-Portal is configured as "Through all interfaces" or "Through internal interfaces"                              |
| enable_portal_wins                             | Gateway                         | Any                           | nbname                                                              | Accept     | Mobile Access blade is enabled                                                                                                     |
| enable_portal_dns                              | Gateway                         | Any                           | domain-udp                                                          | Accept     | Mobile Access blade is enabled                                                                                                     |
| accept_app_mode_back_conn                      | native_app_servers              | Any                           | Any                                                                 | Accept     | 1. Mobile Access blade is enabled 2. SNX Application mode is enabled                                                               |
| accept_connectra_proxy_http                    | Any                             | http_proxy_ips                | Any                                                                 | Accept     | 1. Mobile Access blade is enabled 2. HTTP proxy is enabled: IF (\<Gateway-OBJECT\> --\> http_proxy_setting --\> use_http_proxy==1) |
| accept_connectra_proxy_https                   | Any                             | https_proxy_ips               | Any                                                                 | Accept     | 1. Mobile Access blade is enabled 2. HTTP proxy is enabled: IF (\<Gateway-OBJECT\> --\> http_proxy_setting --\> use_http_proxy==1) |
| accept_dynamic_routing_sync                    | Cluster Members                 | Cluster Members               | FIBMGR                                                              | Accept     | ClusterXL Gateway                                                                                                                  |
| accept_ica_ssl                                 | GUI clients                     | Management Server             | FW1_ica_mgmt_tools                                                  | Accept     | Enabled by default                                                                                                                 |
| accept_swtp_sms                                | Any                             | Management Server             | SWTP_SMS                                                            | Accept     | A UTM-1 Edge device object is configured in SmartConsole                                                                           |
| accept_swtp_gw                                 | Management Server               | Any                           | TCP source port 9282, destination port 9281                         | Accept     | A UTM-1 Edge device object is configured in SmartConsole                                                                           |
| drop_blocklist_traffic                         | Malicious IP addresses          | Any                           | Any                                                                 | Drop       | 1. IPS blade is enabled 2. "Malicious IPs" protection is enabled                                                                   |
| accept_vpn_ca_enrolment                        | Management Server               | CA servers                    | CA servers ports                                                    | Accept     | IPSec VPN blade is enabled                                                                                                         |
| accept_av_signature_update                     | Gateway Management              | Any                           | http https                                                          | Accept     | Anti-Virus blade is enabled                                                                                                        |
| accept_integrity_server_ports                  | Integrity servers               | Gateway                       | TCP port 5054                                                       | Accept     | Endpoint Policy Management blade is enabled                                                                                        |
| accept_dlpgws_smtp_traffic_from_internal       | Internal Mail server            | Gateway                       | TCP destination port 25                                             | Accept     | 1. Dedicated DLP Gateway 2. "Reply by" is enabled from an internal interface                                                       |
| accept_dlpgws_usercheck_traffic_from_internal  | Internal interface              | Gateway                       | TCP destination port 18300                                          | Accept     | 1. Dedicated DLP Gateway 2. "Reply by" is enabled from an internal interface                                                       |
| accept_dlpgws_smtp_traffic_from_any            | Mail server                     | Gateway                       | TCP destination port 25                                             | Accept     | 1. Dedicated DLP Gateway 2. "Reply by" enabled from an internal interface                                                          |
| accept_dlpgws_usercheck_traffic_from_any       | Any                             | Gateway                       | TCP destination port 18300                                          | Accept     | 1. Dedicated DLP Gateway 2. "Reply by" is enabled from an internal interface                                                       |
| accept_dlpgws_exchange_agents_clear_traffic    | DLP Exchange agent              | Gateway                       | TCP destination port 18301 or 18181 or 18187                        | Accept     | DLP Exchange Agent is enabled on this Gateway                                                                                      |
| accept_dlpgws_exchange_agents_ica              | DLP Exchange agent              | Gateway                       | TCP destination port 18210                                          | Accept     | DLP Exchange Agent is enabled on this Gateway                                                                                      |
| accept_dedicated_dlpgws_exchange_clear_traffic | DLP Exchange agent              | Gateway                       | TCP destination port 18301 or 18181 or 18187                        | Accept     | 1. Dedicated DLP Gateway 2. DLP Exchange Agent is enabled on this Gateway                                                          |
| accept_dedicated_dlpgws_smtp_traffic           | Mail server                     | Gateway                       | TCP destination port 25                                             | Accept     | 1. DLP blade is enabled 2. "Reply by" is enabled                                                                                   |
| accept_dlpgws_traffic                          | Any                             | Gateway                       | TCP destination port 18300 or 443 or 80 or 4434 or 22 ICMP requests | Accept     | Dedicated DLP Gateway                                                                                                              |
| accept_dlpgws_dedicated_traffic_ica            | Any                             | Gateway                       | TCP destination port 18210                                          | Accept     | Dedicated DLP Gateway                                                                                                              |
| drop_other_traffic_to_dlpgws                   | Any                             | Gateway                       | Any                                                                 | Drop       | Dedicated DLP Gateway                                                                                                              |
| nac_implied_pep_services                       | Identity Awareness PEP Gateways | Any                           | TCP destination port 15105                                          | Accept     | Identity Awareness blade is enabled                                                                                                |
| nac_implied_pdp_services                       | Identity Awareness PDP Gateways | Any                           | TCP destination port 28581                                          | Accept     | Identity Awareness blade is enabled                                                                                                |
| nac_implied_captive_allow                      | Any                             | Captive Portal IP addresses   | http https                                                          | Accept     | 1. Identity Awareness blade is enabled 2. Captive Portal is enabled                                                                |
| nac_implied_radius_clients_services            | RADIUS-authorized clients       | Gateway                       | UDP (RADIUS Accounting port)                                        | Accept     | 1. Identity Awareness blade is enabled 2. RADIUS Accounting is enabled                                                             |
| client_auth_portal_allow                       | Internal                        | Gateway                       | Client Authentication service                                       | Accept     | Client Authentication is used                                                                                                      |
| accept_os_cluster_sync                         | Cluster Members                 | Cluster Members               | TCP port 1129                                                       | Accept     | ClusterXL is enabled                                                                                                               |
| nac_implied_clean_radius_clients_services      | Any                             | Gateway                       | UDP (RADIUS Accounting port)                                        | Accept     | 1. Identity Awareness blade is enabled 2. RADIUS Accounting is enabled                                                             |
| accept_mail_connections_to_gw                  | Any                             | Gateway                       | SMTP                                                                | Accept     | MTA is enabled (Gateway object \> Mail Transfer Agent section)                                                                     |
| accept_remote_smartlog                         | Log Servers Management Server   | Management Server Log Servers | TCP port 8211                                                       | Accept     | By default                                                                                                                         |

{#Unique_IDTable}

**Related Solutions**:

* [sk110218 - How to enable logging of informative implied rules on Security Gateway R80.10 and higher](https://support.checkpoint.com/results/sk/sk110218?server=il)
* [sk179346 - Configuring Explicit Rules instead of Implied Rules](https://support.checkpoint.com/results/sk/sk179346)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
