<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Understanding url filtering app control on https sites... in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58759#M12486</link>
    <description>&lt;P&gt;Trying to understand some behavior:&amp;nbsp; we have an access control rule that blocks uncategorized sites.&amp;nbsp; Below site is visited and access to it is blocked as uncategorized, it is an https site and yet is categorized as business/economy.&amp;nbsp; &amp;nbsp;The destination is visible via the logs as seen below, yet eventhough the destination is recognized, URL filtering still says it is uncategorized.&amp;nbsp; I'm assuming this is because it is https and the IP address only is scrutinized but just wanted to understand why, if the destination is visible, it isn't categorized as such.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="second.JPG" style="width: 879px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1948i4CDD20CA01D781CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="second.JPG" alt="second.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="first flag.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1949i7FBFB2E30F326749/image-size/large?v=v2&amp;amp;px=999" role="button" title="first flag.JPG" alt="first flag.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jul 2019 21:57:56 GMT</pubDate>
    <dc:creator>Troy_Yeske</dc:creator>
    <dc:date>2019-07-22T21:57:56Z</dc:date>
    <item>
      <title>Understanding url filtering app control on https sites...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58759#M12486</link>
      <description>&lt;P&gt;Trying to understand some behavior:&amp;nbsp; we have an access control rule that blocks uncategorized sites.&amp;nbsp; Below site is visited and access to it is blocked as uncategorized, it is an https site and yet is categorized as business/economy.&amp;nbsp; &amp;nbsp;The destination is visible via the logs as seen below, yet eventhough the destination is recognized, URL filtering still says it is uncategorized.&amp;nbsp; I'm assuming this is because it is https and the IP address only is scrutinized but just wanted to understand why, if the destination is visible, it isn't categorized as such.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="second.JPG" style="width: 879px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1948i4CDD20CA01D781CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="second.JPG" alt="second.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="first flag.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1949i7FBFB2E30F326749/image-size/large?v=v2&amp;amp;px=999" role="button" title="first flag.JPG" alt="first flag.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2019 21:57:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58759#M12486</guid>
      <dc:creator>Troy_Yeske</dc:creator>
      <dc:date>2019-07-22T21:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding url filtering app control on https sites...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58761#M12487</link>
      <description>checkpoint may not categorized some encrypted HTTPS traffic ... try to tick this In Application &amp;amp; Url Filtering Settings under Url Filtering -&amp;gt; Categorize HTTPS websites. else I think you need to enable HTTPS inspection for outbound,,</description>
      <pubDate>Tue, 23 Jul 2019 00:05:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58761#M12487</guid>
      <dc:creator>Neil_ARZ</dc:creator>
      <dc:date>2019-07-23T00:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding url filtering app control on https sites...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58808#M12488</link>
      <description>&lt;P&gt;Thanks, I do have the categorize https sites check box enabled.&amp;nbsp; Just wondering why the destination URL is identified in the logs, the site is categorized by CHKPT, yet it is still marked 'uncategorized'.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 11:54:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58808#M12488</guid>
      <dc:creator>Troy_Yeske</dc:creator>
      <dc:date>2019-07-23T11:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding url filtering app control on https sites...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58830#M12489</link>
      <description>&lt;P&gt;For me the last resort would be activating HTTPS inspection for Outbound.&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTTPS traffic was encrypted and&amp;nbsp; Checkpoint was unable to categorized the sites because of it .&lt;/P&gt;&lt;P&gt;If https inspection is active with URL and App blade, I am sure it will have an effect on URL categorization. .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 16:05:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58830#M12489</guid>
      <dc:creator>Neil_ARZ</dc:creator>
      <dc:date>2019-07-23T16:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding url filtering app control on https sites...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58855#M12490</link>
      <description>Did you check that the gateway can reach the Check Point cloud?&lt;BR /&gt;sk83520 and/or &lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/sk83520-how-to-check-connectivity-to-CP/td-p/31867" target="_blank"&gt;https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/sk83520-how-to-check-connectivity-to-CP/td-p/31867&lt;/A&gt;</description>
      <pubDate>Tue, 23 Jul 2019 23:22:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58855#M12490</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-23T23:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding url filtering app control on https sites...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58881#M12491</link>
      <description>&lt;P&gt;Hi Troy,&lt;/P&gt;
&lt;P&gt;In your example below the domain you see in the log is by reverse lookup of the destination IP. It is not used for URL categorization.&lt;/P&gt;
&lt;P&gt;For SSL traffic SNI (R80.30 and higher)/Certificate CN is used for URL categorization (in case HTTPS Categorization is enabled and SSL inspection is disabled).&lt;/P&gt;
&lt;P&gt;We have tested this in our labs and traffic to oati.com is categorized as Buisness/Economy.&lt;/P&gt;
&lt;P&gt;I suggest you retest it. If still an issue please open a ticket to support.&lt;/P&gt;
&lt;P&gt;*The only scenario I can think of where we will not categorize according to SNI/CN is when certificate is invalid (or SNI is not part of certificate SAN).&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Tal&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 08:02:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58881#M12491</guid>
      <dc:creator>Tal_Ben_Avraham</dc:creator>
      <dc:date>2019-07-24T08:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding url filtering app control on https sites...</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58966#M12492</link>
      <description>&lt;P&gt;Note:&amp;nbsp; it was explained to me that the &lt;A href="http://www.ciso.oati.com" target="_blank"&gt;www.ciso.oati.com&lt;/A&gt; that shows up in the destination field is the result of a rdns query and we don't base categorization off that naturally, hence the 'uncategorized' categorization from URLF/App Control&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2019 14:12:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Understanding-url-filtering-app-control-on-https-sites/m-p/58966#M12492</guid>
      <dc:creator>Troy_Yeske</dc:creator>
      <dc:date>2019-07-25T14:12:54Z</dc:date>
    </item>
  </channel>
</rss>

