I would like to put in my vote for a feature negative objects, one that i've used quiet a bit with checkpoint.
As you select a object for a rule as a source destination or service you could select a checkbox next to that server to define it as a negative object
that is instead of the below rule:
sslvpnusers--websurfing--any--allowed
you could define a much more desired rule like the one below:
sslvpnusers--websurfing--notlocalnetworks--allowed
This thread was automatically locked due to age.