<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL filtering not working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering-not-working/m-p/66364#M12209</link>
    <description>It's possible that matching the CN of the certificate doesn't support wildcards.&lt;BR /&gt;Best to check with the TAC.&lt;BR /&gt;In any case, highly recommend upgrading from R80.10.&lt;BR /&gt;&lt;BR /&gt;Another option is to use the Application Control Signature tool and create a SNI-based signature for the site in question.&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103051" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103051&lt;/A&gt;</description>
    <pubDate>Thu, 31 Oct 2019 14:56:20 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-10-31T14:56:20Z</dc:date>
    <item>
      <title>URL filtering not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering-not-working/m-p/65901#M12205</link>
      <description>&lt;P&gt;On the Checkpoint management server we have ordered layer for our access rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Access&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application and URL filtering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need to whitelist certain subnet to access certain specific urls and the rest of the Internet access from those subnet is denied by the default deny rule in the Application&amp;nbsp; and Url filetering rule base. Below are some of the urls I need whitelisted.&lt;/P&gt;&lt;P&gt;&lt;A href="https://restapi.surveygizmo.eu/v5/" target="_blank"&gt;https://api.nuger.org&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.nuget.org/" href="https://www.nuget.org/" target="_blank" rel="noopener"&gt;https://www.nuget.org/&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So for this access I created a new custom&amp;nbsp;&lt;STRONG&gt;Application/Site&amp;nbsp;&lt;/STRONG&gt;and created a rule in the application/url filtering rulebase with source as the subnet, destination as any and in service/applications I put the newly created custom application/site and action permit&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When i check the custom Application/site i created I could see http, https is allowed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now when i try to access the website from the host in that subnet it is still getting blocked as per the default deny rule in the Application and url filtering rule base,even though I have kept the new created rule above default deny.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can someone please help me to understand why this is causing this and what is the solution.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 09:11:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering-not-working/m-p/65901#M12205</guid>
      <dc:creator>Sree_checkpoint</dc:creator>
      <dc:date>2019-10-25T09:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering-not-working/m-p/65956#M12206</link>
      <description>Unless you are using R80.20 with JHF 117 or above or R80.30, the way we determine what site you are connecting to with HTTPS is the CN of the certificate of the site in question.&lt;BR /&gt;For api.nuger.org, the CN says surveymonkey.eu.&lt;BR /&gt;For &lt;A href="http://www.nuget.org" target="_blank"&gt;www.nuget.org&lt;/A&gt;, the CN says *.nuget.org.&lt;BR /&gt;&lt;BR /&gt;That means you will either need to:&lt;BR /&gt;1. Change your rules to match what the CN says for the sites in question.&lt;BR /&gt;2. Upgrade to R80.20 JHF 117+ or R80.30 where we filter based on verified client SNI.</description>
      <pubDate>Fri, 25 Oct 2019 23:07:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering-not-working/m-p/65956#M12206</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-25T23:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering-not-working/m-p/66269#M12207</link>
      <description>&lt;P&gt;My gateway is on R80.10 and hardware is open server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the newly created application/url list I have put the CN of the website&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for &lt;A href="https://www.nuget.org" target="_blank"&gt;https://www.nuget.org&lt;/A&gt; , in the application/url list i have put *.nuget.org. Still the https traffic to this url is getting blocked by the default deny instead of the allowed rule.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 16:10:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering-not-working/m-p/66269#M12207</guid>
      <dc:creator>Sree_checkpoint</dc:creator>
      <dc:date>2019-10-30T16:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering-not-working/m-p/66276#M12208</link>
      <description>&lt;P&gt;On our policy then would be entering as&lt;/P&gt;&lt;P&gt;*nuget.org*&lt;/P&gt;&lt;P&gt;As the allowed URL&lt;/P&gt;&lt;P&gt;URLs are defined a Regular Express is unchecked.&lt;/P&gt;&lt;P&gt;Gateway is R77.30&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 19:28:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering-not-working/m-p/66276#M12208</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-10-30T19:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering-not-working/m-p/66364#M12209</link>
      <description>It's possible that matching the CN of the certificate doesn't support wildcards.&lt;BR /&gt;Best to check with the TAC.&lt;BR /&gt;In any case, highly recommend upgrading from R80.10.&lt;BR /&gt;&lt;BR /&gt;Another option is to use the Application Control Signature tool and create a SNI-based signature for the site in question.&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103051" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103051&lt;/A&gt;</description>
      <pubDate>Thu, 31 Oct 2019 14:56:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering-not-working/m-p/66364#M12209</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-31T14:56:20Z</dc:date>
    </item>
  </channel>
</rss>

