<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block specific File extention in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/34308#M13883</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.. is an idea but till we can use it we have to upgrade the cluster nodes to R80.10.. (which will be in some days).. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Aug 2018 08:23:04 GMT</pubDate>
    <dc:creator>Robert_Mueller</dc:creator>
    <dc:date>2018-08-09T08:23:04Z</dc:date>
    <item>
      <title>Block specific File extention</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/34304#M13879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to block specific file extentions? I my case iqy and slk files. I know that they are supported in the newest Engine but how can I block them? I can't specify them in the SmartConsole and I've tried to block them with the "prohibited file types" (tecli command) but it wont work...&lt;/P&gt;&lt;P&gt;I wan to block all files with that extentions when they arrive via Mail...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 11:53:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/34304#M13879</guid>
      <dc:creator>Robert_Mueller</dc:creator>
      <dc:date>2018-06-27T11:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific File extention</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/34305#M13880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use DLP feature to block specific file types. Again you need to check that specific file types which you have mentioned is there in database or not.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2018 12:44:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/34305#M13880</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-06-27T12:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific File extention</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/34306#M13881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we extended TE´s file blocking capabilities since engine version 6.14 (&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95235" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95235"&gt;Threat Emulation Engine Update - What&amp;amp;apos;s New?&lt;/A&gt;&amp;nbsp;)- here is how to use it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk123140" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk123140"&gt;How to configure Threat Emulation blade to block files according to file types&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to enable "plain" context in case you want to block file types directly attached to e.g. an email:&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;STRONG&gt;Enabling plain prohibited file types&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Enabling the prohibited file types feature in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;plain&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;context.&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;On the Security Gateway, run the&amp;nbsp;following&amp;nbsp;command:&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px; padding-left: 30px;"&gt;&lt;EM&gt;[Expert@HostName:0]# tecli advanced prohibited enable_plain 1&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;/P&gt;&lt;P style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN style="color: #3d3d3d;"&gt;Regards Thomas&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 09:35:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/34306#M13881</guid>
      <dc:creator>Thomas_Werner</dc:creator>
      <dc:date>2018-06-28T09:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific File extention</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/34307#M13882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you could use the content awarness blade.&lt;/P&gt;&lt;P&gt;You can create a new data type that matches your specific file extension and use it in access rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" height="216" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67999_8.png" width="526" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benoit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 08:20:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/34307#M13882</guid>
      <dc:creator>Benoit_Verove</dc:creator>
      <dc:date>2018-08-09T08:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific File extention</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/34308#M13883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.. is an idea but till we can use it we have to upgrade the cluster nodes to R80.10.. (which will be in some days).. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 08:23:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/34308#M13883</guid>
      <dc:creator>Robert_Mueller</dc:creator>
      <dc:date>2018-08-09T08:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific File extention</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/57825#M13884</link>
      <description>&lt;P&gt;I enabled Content Awareness, created a rule to block executable files, pushed policy.&lt;/P&gt;&lt;P&gt;I am still able to download exe files.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 18:46:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-specific-File-extention/m-p/57825#M13884</guid>
      <dc:creator>An_Nguyen</dc:creator>
      <dc:date>2019-07-09T18:46:13Z</dc:date>
    </item>
  </channel>
</rss>

