<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Content Awareness does not match to rule in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56472#M12744</link>
    <description>The actual log messages (accept and drop) would be helpful here.&lt;BR /&gt;Not to mention elaborating on exact version/JHF level.</description>
    <pubDate>Sun, 23 Jun 2019 20:08:20 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-06-23T20:08:20Z</dc:date>
    <item>
      <title>Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56374#M12731</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have two web site:&amp;nbsp;&lt;A href="https://habr.com" target="_blank" rel="noopener"&gt;https://habr.com&lt;/A&gt; and&amp;nbsp; &lt;A href="https://habrastorage.org" target="_blank" rel="noopener"&gt;https://habrastorage.org&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;&amp;nbsp;habr.com use images from&amp;nbsp;&lt;A href="https://habrastorage.org/" target="_blank" rel="noopener"&gt;https://habrastorage.org/&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;&lt;A href="https://habrastorage.org/" target="_blank" rel="noopener"&gt;https://habrastorage.org/&lt;/A&gt; include in&amp;nbsp;URLs Categories : File Storage&amp;nbsp; and Sharing .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need to&amp;nbsp; block&amp;nbsp; URLs Categories : File Storage&amp;nbsp; and Sharing, but&amp;nbsp; images on&amp;nbsp;habr.com&amp;nbsp; &amp;nbsp;need to be work.&lt;/P&gt;&lt;P&gt;We create two rules&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 943px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1643iEF047B8DF4D69088/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 945px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1642i1CE7F1B46AF7A1FC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;but it isn't work...&amp;nbsp;&lt;/P&gt;&lt;P&gt;for example image:&amp;nbsp;&amp;nbsp;&lt;A href="https://habrastorage.org/getpro/habr/post_images/b09/090/87b/b0909087b281cd74df8fc2de8735758b.png" target="_blank" rel="noopener"&gt;https://habrastorage.org/getpro/habr/post_images/b09/090/87b/b0909087b281cd74df8fc2de8735758b.png&lt;/A&gt;&lt;/P&gt;&lt;P&gt;not match on firts rule. it match on the second rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 12:19:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56374#M12731</guid>
      <dc:creator>Fedor_Agafonov1</dc:creator>
      <dc:date>2019-06-21T12:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56381#M12732</link>
      <description>&lt;P&gt;Please verify that&amp;nbsp;&lt;SPAN&gt;habr.com has "File Storage and Sharing" category associated with it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can create a custom app with its domain name and assign all necessary categories.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Alternatively, you can assign whatever category you want to the custom app for this domain, but use it in the top rule "Services and Application" column.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 12:59:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56381#M12732</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-06-21T12:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56382#M12733</link>
      <description>&lt;P&gt;Do you have HTTPS Inspection enabled?&amp;nbsp; My guess is no.&amp;nbsp; The second rule works because the application can be detected based on the site name without full HTTPS Inspection.&amp;nbsp; The first rule doesn't work because Content Awareness cannot see the prohibited content you are trying to match inside the encrypted HTTPS connection unless HTTP Inspection is enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 13:00:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56382#M12733</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-06-21T13:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56385#M12734</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;, you got to be right about HTTPS. After re-reading the original post, I see that the category does match on a second rule and not just dropping on cleanup. That's pretty convincing.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 13:23:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56385#M12734</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-06-21T13:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56415#M12735</link>
      <description>Https inspection is enable, and work good.&lt;BR /&gt;We also enable kernel parameter "fw ctl set int fileapp_parse_html 1" . (sk114640)</description>
      <pubDate>Sat, 22 Jun 2019 13:40:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56415#M12735</guid>
      <dc:creator>Fedor_Agafonov1</dc:creator>
      <dc:date>2019-06-22T13:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56416#M12736</link>
      <description>Https inspection is enable.</description>
      <pubDate>Sat, 22 Jun 2019 13:42:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56416#M12736</guid>
      <dc:creator>Fedor_Agafonov1</dc:creator>
      <dc:date>2019-06-22T13:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56417#M12737</link>
      <description>habr.com has is not associate "File Storage and Sharing".&lt;BR /&gt;habr.com use image from &lt;A href="https://habrastorage.org/" target="_blank"&gt;https://habrastorage.org/&lt;/A&gt; only.&lt;BR /&gt;&lt;A href="https://habrastorage.org/" target="_blank"&gt;https://habrastorage.org/&lt;/A&gt; is associate "File Storage and Sharing"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 22 Jun 2019 13:46:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56417#M12737</guid>
      <dc:creator>Fedor_Agafonov1</dc:creator>
      <dc:date>2019-06-22T13:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56418#M12738</link>
      <description>&lt;P&gt;Can you create and test a new rule by downloading .png files from elsewhere?&lt;/P&gt;
&lt;P&gt;I'd like to see if it is a problem related to the content recognition.&lt;/P&gt;
&lt;P&gt;Another good test would be to change the extension (for instance .docx to .png and try to download that file.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2019 13:53:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56418#M12738</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-06-22T13:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56419#M12739</link>
      <description>&lt;P&gt;As a test in your first rule in the Content field, set for "Any Direction, Any File" (not just "Any").&amp;nbsp; Do the PNG images now match the first rule?&amp;nbsp; Just trying to see if Content Awareness is detecting things correctly at all in your situation...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2019 14:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56419#M12739</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-06-22T14:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56424#M12740</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1648i43AB3CE4FB4ACDD0/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;not match.&lt;/P&gt;&lt;P&gt;Also match on second rule.&lt;/P&gt;&lt;P&gt;in habr i see:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 326px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1649i0BAEF5AA35CB4B6F/image-dimensions/326x358?v=v2" width="326" height="358" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;habrastarage.org is block:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 217px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1651i33645C0ED962FF96/image-dimensions/217x108?v=v2" width="217" height="108" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2019 14:40:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56424#M12740</guid>
      <dc:creator>Fedor_Agafonov1</dc:creator>
      <dc:date>2019-06-22T14:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56425#M12741</link>
      <description>We tryed. It's not worked. If on inline policy have block rule on Categories, content awarnes not work on previevs rule.</description>
      <pubDate>Sat, 22 Jun 2019 15:00:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56425#M12741</guid>
      <dc:creator>Fedor_Agafonov1</dc:creator>
      <dc:date>2019-06-22T15:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56430#M12742</link>
      <description>&lt;P&gt;Why did you change the destination from "Any" to "Internet" in your second rule?&amp;nbsp; Is your firewall topology configured completely and correctly so that object "Internet" is calculated properly?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2019 17:36:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56430#M12742</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-06-22T17:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56452#M12743</link>
      <description>&lt;P&gt;Any chance you are downloading the files using QUIC?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jun 2019 13:28:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56452#M12743</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-06-23T13:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56472#M12744</link>
      <description>The actual log messages (accept and drop) would be helpful here.&lt;BR /&gt;Not to mention elaborating on exact version/JHF level.</description>
      <pubDate>Sun, 23 Jun 2019 20:08:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56472#M12744</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-23T20:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness does not match to rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56527#M12745</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;QUIC is bloked.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 09:21:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-does-not-match-to-rule/m-p/56527#M12745</guid>
      <dc:creator>Fedor_Agafonov1</dc:creator>
      <dc:date>2019-06-24T09:21:51Z</dc:date>
    </item>
  </channel>
</rss>

