<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block .exe file download in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4894#M101334</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Wrong! NGFW is enough, see here:&lt;/P&gt;&lt;P class=""&gt;&lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-2052-infinity-r8010-cool-feature-of-the-day-content-awareness"&gt;https://community.checkpoint.com/docs/DOC-2052-infinity-r8010-cool-feature-of-the-day-content-awareness&lt;/A&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Mar 2018 06:58:20 GMT</pubDate>
    <dc:creator>Norbert_Bohusch</dc:creator>
    <dc:date>2018-03-28T06:58:20Z</dc:date>
    <item>
      <title>Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4885#M101325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got the queries, if it is possible to implement a policy which block the client from downloading the executable(exe) files in &amp;nbsp;checkpoint.&lt;/P&gt;&lt;P&gt;Our client were using fortinet 200D where we found such policy. So, we need to make that same policy to checkpoint.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sagar Manandhar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2017 23:18:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4885#M101325</guid>
      <dc:creator>Sagar_Manandhar</dc:creator>
      <dc:date>2017-08-02T23:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4886#M101326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Refer to the following SK:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111493" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111493"&gt;How to block any File Type Family to Anti-Virus scan in R77.XX&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These instructions should also apply for R80.x as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Aug 2017 02:23:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4886#M101326</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-03T02:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4887#M101327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Starting with R80.10 this could also be achieved by using the new Content Awareness features. So there would be no need for an Anti-Virus license (NGTP bundle), but an NGFW bundle would be sufficient.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Aug 2017 06:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4887#M101327</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2017-08-03T06:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4888#M101328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;simply create this rule:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/57817_block-download.png" style="width: 620px; height: 45px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to enable Content Awareness:&lt;/P&gt;&lt;P&gt;1. Make sure you have an R80.10 Gateway&lt;/P&gt;&lt;P&gt;2. Edit the gateway and enable the Content Awareness blade.&lt;/P&gt;&lt;P&gt;3. Edit the current security policy layer and enable the Content Awareness blade.&lt;/P&gt;&lt;P&gt;4. The new "Content" column will show up in the rulebase.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Aug 2017 08:31:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4888#M101328</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2017-08-03T08:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4889#M101329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I wish I could mark both our solutions as correct in Jive &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Aug 2017 15:05:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4889#M101329</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-03T15:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4890#M101330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah. So if you have lower version than R80.10. You can achieve it by &amp;nbsp;Antivirus blade as well as DLP blade.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Nov 2017 12:05:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4890#M101330</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2017-11-30T12:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4891#M101331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i did it. but it is not working. ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 09:09:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4891#M101331</guid>
      <dc:creator>dorj_erdeneochi</dc:creator>
      <dc:date>2018-03-26T09:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4892#M101332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from what i know AV blade check only file extension and not the MimeType of the file&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2018 11:01:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4892#M101332</guid>
      <dc:creator>Dor_Marcovitch</dc:creator>
      <dc:date>2018-03-26T11:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4893#M101333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Guys,&lt;/P&gt;&lt;P&gt;correct me If I am wrong, for activation Content Awareness blade, I need DLP license which is not part of NGFW nor NGTP/TX bundle.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2018 06:51:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4893#M101333</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2018-03-28T06:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4894#M101334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Wrong! NGFW is enough, see here:&lt;/P&gt;&lt;P class=""&gt;&lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-2052-infinity-r8010-cool-feature-of-the-day-content-awareness"&gt;https://community.checkpoint.com/docs/DOC-2052-infinity-r8010-cool-feature-of-the-day-content-awareness&lt;/A&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2018 06:58:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4894#M101334</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2018-03-28T06:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4895#M101335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How does customers add this specific the file type families. is it possible for customer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 07:18:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4895#M101335</guid>
      <dc:creator>dorj_erdeneochi</dc:creator>
      <dc:date>2018-03-29T07:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4896#M101336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64215_data1.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64216_data2.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 09:03:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4896#M101336</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-03-29T09:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4897#M101337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For my own clarity, this seems to work with &lt;SPAN style="text-decoration: underline;"&gt;both&lt;/SPAN&gt; HTTP and HTTPS in my lab.&amp;nbsp; I am not doing HTTPS inspection, can I ask how this works with HTTPS?&amp;nbsp; My assumption was that I'd still be able to download an EXE, but I was wrong.&amp;nbsp; I don't know too much about Content Awareness possibilities, but it is intriguing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2019 14:28:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4897#M101337</guid>
      <dc:creator>Kevin_Vargo</dc:creator>
      <dc:date>2019-01-22T14:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: Block .exe file download</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4898#M101338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Trying to configure a Content Awareness rule for this scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an inline rule configured for web browsing (rule 17):&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79818_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;I have more detailed inline rules below this (rule 17.x)&lt;/P&gt;&lt;P&gt;I wish to create content awareness checks at the lower levels of the inline rule but the Content column is greyed out?&lt;/P&gt;&lt;P&gt;R80.20 SM Admin Guide shows that this should be possible.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79819_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 06:25:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-exe-file-download/m-p/4898#M101338</guid>
      <dc:creator>Pedro_Silva</dc:creator>
      <dc:date>2019-03-06T06:25:34Z</dc:date>
    </item>
  </channel>
</rss>

