<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot create exception for &amp;quot;Phishing_website.mzle&amp;quot; protection in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/283033#M106960</link>
    <description>&lt;P&gt;Vladmir, did you ever get this resolved?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2026 18:08:27 GMT</pubDate>
    <dc:creator>Mark12345</dc:creator>
    <dc:date>2026-09-29T18:08:27Z</dc:date>
    <item>
      <title>Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52282#M57863</link>
      <description>&lt;P&gt;I am on a verge of loosing my cool after spending half a day on a seemingly trivial task of trying to create an exception for the Threat Prevention policy.&lt;/P&gt;
&lt;P&gt;The goal is to allow my client's PCs to receive the Phishing training communication from the KnowBe4.&lt;/P&gt;
&lt;P&gt;The vendor has three IPs but each campaign generates new resources.&lt;/P&gt;
&lt;P&gt;Every time client tries to go to the spoofed site, i.e. "gmail.net-login.com", the gateway promptly bags it with:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1038iC892A09D3D6C8C6F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Time: 2019-04-30T19:18:48Z&lt;BR /&gt;Interface Direction: inbound&lt;BR /&gt;Interface Name: eth3&lt;BR /&gt;Id: c0a8071f-0100-00c0-5cc8-9f9800000001&lt;BR /&gt;Sequencenum: 1&lt;BR /&gt;Threat Prevention Policy: Clean_Slate&lt;BR /&gt;Threat Prevention Policy Date:2019-04-30T19:17:59Z&lt;BR /&gt;Source: 10.101.30.101&lt;BR /&gt;Source Port: 50859&lt;BR /&gt;Destination Country: Israel&lt;BR /&gt;Destination: 62.0.58.94&lt;BR /&gt;Destination Port: 80&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Session Identification Number:0x5cc89f98,0x1,0x1f07a8c0,0xc0000001&lt;BR /&gt;Protection Name: Phishing_website.mzle&lt;BR /&gt;Description: Connection to DNS trap bogus IP. See sk74060 for more information.&lt;BR /&gt;Confidence Level: High&lt;BR /&gt;Severity: High&lt;BR /&gt;Malware Action: Malicious network activity&lt;BR /&gt;Protection Type: DNS Trap&lt;BR /&gt;Threat Prevention Rule Id: FE9921CA-B861-425E-B0F2-19A1D217EFAD&lt;BR /&gt;Protection ID: 0018B6567&lt;BR /&gt;Log ID: 2&lt;BR /&gt;Scope: 10.101.30.101&lt;BR /&gt;Source User Name: ADuser2 Two (aduser2@higherintelligence.com)&lt;BR /&gt;Source Machine Name: win10net30@higherintelligence.com&lt;BR /&gt;User: ADuser2 Two (aduser2@higherintelligence.com)&lt;BR /&gt;Action: Prevent&lt;BR /&gt;Type: Log&lt;BR /&gt;Policy Name: Clean_Slate&lt;BR /&gt;Policy Management: SMS8030EA&lt;BR /&gt;Db Tag: {BAC69145-F44A-4148-9603-7CEBB47B7A42}&lt;BR /&gt;Policy Date: 2019-04-30T14:32:16Z&lt;BR /&gt;Blade: Anti-Virus&lt;BR /&gt;Origin: GW8030EA&lt;BR /&gt;Service: TCP/80&lt;BR /&gt;Product Family: Threat&lt;BR /&gt;Resource: gmail.net-login.com&lt;BR /&gt;Marker: @A@@B@1556596801@C@31302&lt;BR /&gt;Log Server Origin: 192.168.7.30&lt;BR /&gt;Orig Log Server Ip: 192.168.7.30&lt;BR /&gt;Index Time: 2019-04-30T19:19:54Z&lt;BR /&gt;Lastupdatetime: 1556651989000&lt;BR /&gt;Lastupdateseqnum: 1&lt;BR /&gt;Rounded Sent Bytes: 0&lt;BR /&gt;Rounded Bytes: 0&lt;BR /&gt;Stored: true&lt;BR /&gt;Rounded Received Bytes: 0&lt;BR /&gt;Suppressed Logs: 21&lt;BR /&gt;Sent Bytes: 0&lt;BR /&gt;Received Bytes: 0&lt;BR /&gt;Interface: eth3&lt;BR /&gt;Description: 10.101.30.101 performed malicious network activity that was prevented with DNS Trap&lt;BR /&gt;Threat Profile: Go to profile&lt;BR /&gt;Bytes (sent\received): 0 B \ 0 B&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Trying to exempt the traffic by negating the destination group in the TP rules, creating manual exemptions with either "Detect" or "Inactive", doing same by creating the exemptions from the logs, does not change the behavior. DNS trap is activated every time.&lt;/P&gt;
&lt;P&gt;Searching for the Protection Name: "&lt;STRONG&gt;Phishing_website.mzle&lt;/STRONG&gt;" in either "Protections" or IPS Protections, does not help. The thing is not there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Even creating a Categorization Exception:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 665px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1039i409A0EAC6B9965A6/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As unfeasible as it is for this particular task, still does not work.&lt;/P&gt;
&lt;P&gt;HELP!!!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 22:52:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52282#M57863</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-04-30T22:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52368#M57864</link>
      <description>I believe you can create a Threat Prevention rule where if the destination of the traffic is one of those specific IP addresses, the profile is a Detect only profile, inactive, or similar.&lt;BR /&gt;Have you tried that?</description>
      <pubDate>Thu, 02 May 2019 01:45:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52368#M57864</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-02T01:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52372#M57865</link>
      <description>&lt;P&gt;You would not believe how many different combinations of rules, policies, profiles and exceptions I have tried &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Presently, this is the policy with 2 profiles, one of them has no AV blade, as that's the one that seem to be triggering this protection, but I have tried it with single profiles with negated cells as well:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1051i337AC6C176E60202/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The exceptions are now in "Detect" mode, but I have tried it with "Inactive" as well:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1052i55FBADF6E5A3A6B4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not to mention that the actual spoofed domain resolving to those IPs is in the "Categorization Exemption".&lt;/P&gt;
&lt;P&gt;All of it is still does not work.&lt;/P&gt;
&lt;P&gt;Even if it would, it is not really a long term solution for Spoofing training vendors: they spin-up instances on AWS behind dynamically allocated IPs and newly crafted domains every time.&lt;/P&gt;
&lt;P&gt;That being said, the exemptions must work and they do not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 01:58:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52372#M57865</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-02T01:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52373#M57866</link>
      <description>&lt;P&gt;P.S. I think that the best solution for all involved will be for these companies to feed their exercise domains to the Threat Cloud for whitelisting and differentiated categorization.&lt;/P&gt;
&lt;P&gt;This way, they will not be bagged by the protections and reduce manual labor for admins fighting with this issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 02:05:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52373#M57866</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-02T02:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52387#M57867</link>
      <description>&lt;P&gt;Hi Vladimir&lt;/P&gt;
&lt;P&gt;Categorization Exemption is for URLF, not AV/AB ..&lt;/P&gt;
&lt;P&gt;After setting up all those exception experiments - what logs do you see in SmartLog? Prevent logs for what?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe the issue is that you didn't exempt the internal DNS server from inspection? is there one? if so - IT asks for gmail.net-login.com's IP address and gets the bogus address...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 06:49:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52387#M57867</guid>
      <dc:creator>TP_Master</dc:creator>
      <dc:date>2019-05-02T06:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52470#M57868</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8166"&gt;@TP_Master&lt;/a&gt;&amp;nbsp;, please see the very first post in this threat describing the event that I am seeing.&lt;/P&gt;
&lt;P&gt;Of course the internal DNS forwarded itself is not exempt from overall inspection, but how does this figures into the AV triggering DNS Trap?&lt;/P&gt;
&lt;P&gt;while gmail.net-login.com is definitely a spoofing URL, it does resolve to a number of IPs when tested from outside of Check Point protected environment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What then decides that the returned address supposed to be replaced by the DNS Trap?&lt;/P&gt;
&lt;P&gt;How that action could be exempt, if neither IPs nor application or URL exceptions are working?&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 01:02:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52470#M57868</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-03T01:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52477#M57869</link>
      <description>My theory is this - the DNS request is sent from your computer to the internal DNS server. It is then forwarded by the internal DNS server to the exteranl one through the Check Point GW. *this request is found by AV and the response is with the DNS Trap bogus IP*. &lt;BR /&gt;Subsequently, it is sent to the computer which tries to access gmail.net-login.com but goes to the bogus IP which is blocked... &lt;BR /&gt;&lt;BR /&gt;Try to add exemption for this domain when the protected scope is your internal DNS server. &lt;BR /&gt;&lt;BR /&gt;Does that make sense?</description>
      <pubDate>Fri, 03 May 2019 06:05:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52477#M57869</guid>
      <dc:creator>TP_Master</dc:creator>
      <dc:date>2019-05-03T06:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52952#M57870</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8166"&gt;@TP_Master&lt;/a&gt;&amp;nbsp;, in this environment there is a common protection scope for the entire organization (i.e single default TP rule with scope "Any".&lt;/P&gt;
&lt;P&gt;So the exception should, theoretically, work for both, the clients as well as internal DNS forwarders.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 00:28:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52952#M57870</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-09T00:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52954#M57871</link>
      <description>&lt;P&gt;It is actually funny: KnowBe4 emailed me response with the URLs to the txt files listing their phishing domains.&lt;/P&gt;
&lt;P&gt;Along the way it was bagged by:&lt;/P&gt;
&lt;P&gt;1. Office 365&lt;/P&gt;
&lt;P&gt;2. Check Point gateway&lt;/P&gt;
&lt;P&gt;3. Kaspersky AV on the endpoint&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only solution that did not pay any heed to this message was Check Point CloudGuard SaaS for Office 365.&lt;/P&gt;
&lt;P&gt;Makes me wander if it is a good sign or the bad one...&lt;/P&gt;
&lt;P&gt;I am yet to see the darned lists.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 00:35:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52954#M57871</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-09T00:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52963#M57872</link>
      <description>It is true if you had an exception with "any" in the scope, source and destination fields. In your screenshot there isn't one..</description>
      <pubDate>Thu, 09 May 2019 06:08:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/52963#M57872</guid>
      <dc:creator>TP_Master</dc:creator>
      <dc:date>2019-05-09T06:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/53042#M57873</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8166"&gt;@TP_Master&lt;/a&gt;&amp;nbsp;, in client's environment it is, but as you've rightly noticed, in my lab it is different.&lt;/P&gt;
&lt;P&gt;Regardless, the problem is that the destination IPs of the spoofed domains are dynamic.&lt;/P&gt;
&lt;P&gt;So trying to exempt them in the TP policy using scope, source and/or destination will not work.&lt;/P&gt;
&lt;P&gt;I have to figure out how to bypass the TP based on domain names and FQDNs which TP Policy does not support and categorization exception does not work.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 16:19:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/53042#M57873</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-09T16:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/53207#M57874</link>
      <description>Have you tried to add a site and add it to the exception? (in the site/protection column)</description>
      <pubDate>Sat, 11 May 2019 21:11:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/53207#M57874</guid>
      <dc:creator>TP_Master</dc:creator>
      <dc:date>2019-05-11T21:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/56286#M57875</link>
      <description>&lt;P&gt;Having the same issue and CG SAAS is bagging our messages as well.&amp;nbsp; We have overcome the SAAS issues but the gateway doesn't seem to like any exception we put in&amp;nbsp; KB4 support is little no help&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 15:51:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/56286#M57875</guid>
      <dc:creator>dantlitz</dc:creator>
      <dc:date>2019-06-20T15:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/56343#M57876</link>
      <description>&lt;P&gt;Have you try to disable dns trap on tp profile?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:02:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/56343#M57876</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2019-06-21T09:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/56370#M57877</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2229"&gt;@Marco_Valenti&lt;/a&gt;&amp;nbsp;, I think KnowBe4 got this site whitelisted with the Threat Cloud, because it does not cause same issues anymore in my clients case.&lt;/P&gt;
&lt;P&gt;Their other landing page was being blocked by Quad9 secure DNS service and I have notified KB4 about all of these issues.&lt;/P&gt;
&lt;P&gt;Got the response that they are working with the threat intelligence vendors to get their domains cleared.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 11:52:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/56370#M57877</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-06-21T11:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/117770#M57878</link>
      <description>&lt;P&gt;I'm having this same issue only with a vendor named InfoSec IQ, used to be Security IQ.&amp;nbsp; Anyway, I tried basically everything you tried.&amp;nbsp; I am now asking the vendor to whitelist their domains with the Threat Cloud.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 19:02:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/117770#M57878</guid>
      <dc:creator>Biggsy</dc:creator>
      <dc:date>2021-05-05T19:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/168611#M57879</link>
      <description>&lt;P&gt;We use KB4 too and this is exactly the issue I'm running into. I right clicked the Prevent log card and "added exception" and then removed the source so it is ANY, but the URL is still blocked. Based on your solution I opened a case up with KB4. I tried to get the category changed, but CP still marked it as phishing. Waiting to see if that would help or I might open a CP case up to see how I can add an exception there since our spam filter also did mark it as phishing.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 22:28:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/168611#M57879</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2023-01-20T22:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create exception for "Phishing_website.mzle" protection</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/283033#M106960</link>
      <description>&lt;P&gt;Vladmir, did you ever get this resolved?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2026 18:08:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Cannot-create-exception-for-quot-Phishing-website-mzle-quot/m-p/283033#M106960</guid>
      <dc:creator>Mark12345</dc:creator>
      <dc:date>2026-09-29T18:08:27Z</dc:date>
    </item>
  </channel>
</rss>

