<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL protocol in application control rules in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSL-protocol-in-application-control-rules/m-p/93846#M12542</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;When access to a permitted website is blocked, if we open it with Internet Explorer we can access it and once we have accessed it from Internet Explorer we can access it from the rest of the browsers.&lt;/P&gt;&lt;P&gt;This is a very strange behaviour. Maybe it is necessary to allow the ssl_v2 and v3 service?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Aug 2020 12:37:35 GMT</pubDate>
    <dc:creator>rloureiro</dc:creator>
    <dc:date>2020-08-11T12:37:35Z</dc:date>
    <item>
      <title>SSL protocol in application control rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSL-protocol-in-application-control-rules/m-p/59730#M12540</link>
      <description>&lt;P&gt;we have a strange behaviour with ssl protocol and application control.&lt;/P&gt;&lt;P&gt;customer notify us that some sites that should be blocked by the application control were accessible (like facebook)&lt;/P&gt;&lt;P&gt;rules are configured in whitelist mode (allowing specific categories and applications and a block all rule a the bottom)&lt;/P&gt;&lt;P&gt;after investigating we notice that there was an application control rule that enabled https to internet that allow facebook and many other sites,&amp;nbsp;once disabled that rule all these sites were correctly blocked by the application control rules but we got also lot's of traffic blocked as "SSL protocol" and we needed to recover the rule.&lt;/P&gt;&lt;P&gt;how can we enable ssl protocol and block these sites at the same time?&lt;/P&gt;&lt;P&gt;one solution would be to change the policies to a blacklist mode but the customer want to keep the rules in whitelist mode.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 15:15:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSL-protocol-in-application-control-rules/m-p/59730#M12540</guid>
      <dc:creator>andy_currigan</dc:creator>
      <dc:date>2019-08-06T15:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSL protocol in application control rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSL-protocol-in-application-control-rules/m-p/59765#M12541</link>
      <description>SSL protocol is a fairly generic application signature, matching all HTTPS traffic.&lt;BR /&gt;This could include uncategorized websites, which may not be what you want to allow.&lt;BR /&gt;Your best bet is to whitelist the specific SSL traffic you wish to allow by source/destination or create some sort of signature for the traffic you wish to allow.</description>
      <pubDate>Wed, 07 Aug 2019 02:30:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSL-protocol-in-application-control-rules/m-p/59765#M12541</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-08-07T02:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSL protocol in application control rules</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSL-protocol-in-application-control-rules/m-p/93846#M12542</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;When access to a permitted website is blocked, if we open it with Internet Explorer we can access it and once we have accessed it from Internet Explorer we can access it from the rest of the browsers.&lt;/P&gt;&lt;P&gt;This is a very strange behaviour. Maybe it is necessary to allow the ssl_v2 and v3 service?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 12:37:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SSL-protocol-in-application-control-rules/m-p/93846#M12542</guid>
      <dc:creator>rloureiro</dc:creator>
      <dc:date>2020-08-11T12:37:35Z</dc:date>
    </item>
  </channel>
</rss>

