<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 'Web Browser' category blocks legitimate URLs in Browse</title>
    <link>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168432#M26</link>
    <description>&lt;P&gt;Version R81.10&lt;BR /&gt;JHF:&amp;nbsp; T66&lt;/P&gt;&lt;P&gt;Screenshot of the policy, highlight both requested rules:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rules.png" style="width: 951px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19196i52B036B05451BF76/image-size/large?v=v2&amp;amp;px=999" role="button" title="Rules.png" alt="Rules.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In Logs I can see that URL filter blade Accepts the traffic accordingly, but then APP Control BLocks it:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Logs.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19197iECB3DCDD3F684C09/image-size/large?v=v2&amp;amp;px=999" role="button" title="Logs.png" alt="Logs.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jan 2023 19:42:28 GMT</pubDate>
    <dc:creator>Yuber_Sierra_av</dc:creator>
    <dc:date>2023-01-19T19:42:28Z</dc:date>
    <item>
      <title>'Web Browser' category blocks legitimate URLs</title>
      <link>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168393#M24</link>
      <description>&lt;P&gt;Hello friends,&lt;/P&gt;&lt;P&gt;Would appreciate your help if you could give me some advise with this problem regarding URL Filtering/App Control blade:&lt;/P&gt;&lt;P&gt;Users are experiencing a very strange behavior when browsing some web pages:&lt;/P&gt;&lt;P&gt;First time users click a link, they get the blocked message despite the URL they are trying to access is categorized whitin the allowed categories for such users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then, they go back and click the same link again, this time they are allowed access.&lt;/P&gt;&lt;P&gt;Review of the log shows that App control is blocking the browser (Edge, Chrome). If I allow such Apps then the policies are bypassed and users can access all categories:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Blocked access.jpg" style="width: 557px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19188i8AA1D6C9B457AE8E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Blocked access.jpg" alt="Blocked access.jpg" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;Action:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect&lt;/P&gt;&lt;P&gt;Application Name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Microsoft Edge&lt;/P&gt;&lt;P&gt;Application Description:&amp;nbsp;&amp;nbsp; Microsoft Edge is a web browser developed by Microsoft.&lt;/P&gt;&lt;P&gt;Primary Category:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Web Browser&lt;/P&gt;&lt;P&gt;Matched Category:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Web Browser&lt;/P&gt;&lt;P&gt;Additional Categories:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Web Browser&lt;/P&gt;&lt;P&gt;Application Risk:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unknown&lt;/P&gt;&lt;P&gt;Resource:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://vehiculos.tucarro.com.co/_PublishedToday_YES" target="_blank" rel="noopener"&gt;https://vehiculos.tucarro.com.co/_PublishedToday_YES&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Browse Time:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;User Check:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;/P&gt;&lt;P&gt;UserCheck Message to User: La aplicación Microsoft Edge esta bloqueada de acuerdo a las politicas de seguridad de la compañia Category: Web Browser Para mas informacion favor comunicarse con soporte a usuarios.&lt;/P&gt;&lt;P&gt;UserCheck Interaction Name:Blocked Message&lt;/P&gt;&lt;P&gt;Access Rule Name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cleanup rule&lt;/P&gt;&lt;P&gt;Access Rule Number:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 109.17&lt;/P&gt;&lt;P&gt;Policy Rule UID:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65566f27-e62b-4907-a52a-478888eb2780&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 16:07:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168393#M24</guid>
      <dc:creator>Yuber_Sierra_av</dc:creator>
      <dc:date>2023-01-19T16:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: 'Web Browser' category blocks legitimate URLs</title>
      <link>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168422#M25</link>
      <description>&lt;P&gt;Version/JHF of the gateway?&lt;BR /&gt;Screenshots of the precise rules in question would be helpful.&lt;BR /&gt;Specifically, the one that should allow traffic, the one that is blocking it, as well as the parent rule for your inline layer (109).&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 18:15:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168422#M25</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-19T18:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: 'Web Browser' category blocks legitimate URLs</title>
      <link>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168432#M26</link>
      <description>&lt;P&gt;Version R81.10&lt;BR /&gt;JHF:&amp;nbsp; T66&lt;/P&gt;&lt;P&gt;Screenshot of the policy, highlight both requested rules:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rules.png" style="width: 951px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19196i52B036B05451BF76/image-size/large?v=v2&amp;amp;px=999" role="button" title="Rules.png" alt="Rules.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In Logs I can see that URL filter blade Accepts the traffic accordingly, but then APP Control BLocks it:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Logs.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19197iECB3DCDD3F684C09/image-size/large?v=v2&amp;amp;px=999" role="button" title="Logs.png" alt="Logs.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 19:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168432#M26</guid>
      <dc:creator>Yuber_Sierra_av</dc:creator>
      <dc:date>2023-01-19T19:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: 'Web Browser' category blocks legitimate URLs</title>
      <link>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168439#M27</link>
      <description>&lt;P&gt;Screenshot of your log entry shows matching rule 109.17 but screenshot of rules shows 107.17 &amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 20:20:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168439#M27</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-01-19T20:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: 'Web Browser' category blocks legitimate URLs</title>
      <link>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168440#M28</link>
      <description>&lt;P&gt;Yes, that is because after I created the post had to delete two rules above the parent rule., so, rules are the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 20:23:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168440#M28</guid>
      <dc:creator>Yuber_Sierra_av</dc:creator>
      <dc:date>2023-01-19T20:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: 'Web Browser' category blocks legitimate URLs</title>
      <link>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168444#M29</link>
      <description>&lt;P&gt;Understand.&lt;/P&gt;
&lt;P&gt;Rule shows a block from ApplicationControl and the rule which allow the traffic match by URLFilter. These are different blades and maybe as an idea you can change your rules. Create a new rule allowing traffic with application „edge“ or category „WebBrowser“ and as an new inline layer you can define your URLFilter rules.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 20:36:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168444#M29</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-01-19T20:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: 'Web Browser' category blocks legitimate URLs</title>
      <link>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168446#M30</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;. The block rule match app control, but allow shows URL filtering. How is your policy configured? Do you have 2 ordered layers? Usually, what I always recommend to people is to have 1st layer as regular network layer with only fw enabled in policy settings and then 2nd layer with urlf + appc blades on.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 20:46:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168446#M30</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-19T20:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: 'Web Browser' category blocks legitimate URLs</title>
      <link>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168450#M31</link>
      <description>&lt;P&gt;What applications are in the group located in Rule 107.8?&lt;BR /&gt;Note that App Control isn't blocking it, per-se, but for some reason the (initial) traffic isn't matching whatever is listed in Rule 107.8...or any other rule in that layer.&lt;BR /&gt;Which means the cleanup rule for that inline layer logs the application (or URL Filtering category) that is "best match" for the traffic in question, which is probably Web Browsing.&lt;/P&gt;
&lt;P&gt;This will probably require a TAC case to properly troubleshoot.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 21:43:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168450#M31</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-19T21:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: 'Web Browser' category blocks legitimate URLs</title>
      <link>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168543#M32</link>
      <description>&lt;P&gt;The group "Navegacion_WebLevel3" in rule 107.8 contains the URL Filering categories allowed for the corresponding AD group "Weblevel3_AD", including "Vehicles" which is the category that matches the URL that was blocked:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;For&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="http://articulo.tucarro.com.co" target="_blank" rel="noopener"&gt;http://articulo.tucarro.com.co&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Categories:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Vehicles&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 14:15:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168543#M32</guid>
      <dc:creator>Yuber_Sierra_av</dc:creator>
      <dc:date>2023-01-20T14:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: 'Web Browser' category blocks legitimate URLs</title>
      <link>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168592#M33</link>
      <description>&lt;P&gt;Generally speaking, a certain amount of traffic has to flow before we can identify a specific website/application.&lt;BR /&gt;Clearly it's not getting enough traffic to make that determination before it closes the connection, therefore it falls to the Cleanup Rule for the layer.&lt;BR /&gt;Why this is happening would need to be investigated by the TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 19:43:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Web-Browser-category-blocks-legitimate-URLs/m-p/168592#M33</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-20T19:43:41Z</dc:date>
    </item>
  </channel>
</rss>

