> Source: [sk97731](https://support.checkpoint.com/results/sk/sk97731)

# sk97731 - Traffic from internal interface to another internal interface is blocked by Application Control and URL Filtering rules with destination "Internet"

| Property | Value |
|----------|-------|
| Solution ID | sk97731 |
| Date Created | 2013-12-15 |
| Last Modified | 2017-07-17 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- Traffic from internal interface to another internal interface is blocked by Application Control \& URL Filtering rules with destination "Internet".

## Cause

The blocked internal network does not appear in the Topology definitions of the internal interfaces. Anti-Spoofing is enabled on the internal interfaces.

"Internet" object is defined as "All traffic leading to external interfaces". This definition is not correct in case the topology of one (or more) of the internal interfaces is configured as "Not defined".

In that case, the Security Gateway refers to the routing table to determine the traffic direction.

When the topology of all internal interfaces is defined, the Security Gateway determines whether a network is internal/external by checking the topology definitions, rather than traffic direction, as stated in the "Internet" object.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
