<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow access to specific truncated URL's in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108754#M14723</link>
    <description>&lt;P&gt;I'm actually not sure if it is enabled or not. I inherited this Checkpoint, and have no experience with them prior, so figuring things out as I go.&amp;nbsp; How do I tell if it is enabled, and if not, how do I enable it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2021 13:10:06 GMT</pubDate>
    <dc:creator>shawmcbigdis</dc:creator>
    <dc:date>2021-01-25T13:10:06Z</dc:date>
    <item>
      <title>Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108346#M14608</link>
      <description>&lt;P&gt;Is there a way to allow access to specific truncated URL's, in this case ones at "youtu.be" ? It seems the checkpoint blocks them all by default, I tried creating a custom application/site with the specific links I want in it, but it is still being blocked;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="URL.PNG" style="width: 639px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10277i27E51D918AD16B69/image-size/large?v=v2&amp;amp;px=999" role="button" title="URL.PNG" alt="URL.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The policy is just an allow any any basically;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10278i434AE6E832F58D39/image-size/large?v=v2&amp;amp;px=999" role="button" title="policy.PNG" alt="policy.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The checkpoint ver is R80.30. I'm pretty new to Checkpoint, so I assume I am just missing something. Either that, or there is no way around the truncated URL block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 21:44:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108346#M14608</guid>
      <dc:creator>shawmcbigdis</dc:creator>
      <dc:date>2021-01-20T21:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108354#M14610</link>
      <description>&lt;P&gt;First of all, without HTTPS Inspection enabled, nothing like this will work since it's impossible for the gateway to see the URL otherwise.&lt;BR /&gt;Second of all, a YouTube page involves many connections, which may not be caught by this rule and blocked by the other rules.&lt;/P&gt;
&lt;P&gt;You might need to enable something like YouTube Strict mode.&lt;BR /&gt;You can force that on the gateway with HTTPS Inspection enabled and:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk146993&amp;amp;partition=Advanced&amp;amp;product=Application" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk146993&amp;amp;partition=Advanced&amp;amp;product=Application&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Corresponding Google Help article:&amp;nbsp;&lt;A href="https://support.google.com/a/answer/6214622?hl=en&amp;amp;ref_topic=6248111#zippy=,option-http-headers" target="_blank"&gt;https://support.google.com/a/answer/6214622?hl=en&amp;amp;ref_topic=6248111#zippy=,option-http-headers&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Then you can control what videos your users can see.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 02:11:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108354#M14610</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-21T02:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108393#M14619</link>
      <description>&lt;P&gt;I don't think I explained that very well. We do not block YouTube at all. Users can go to any youtube video as youtube.com is completely allowed.&lt;/P&gt;&lt;P&gt;The issue is the truncated links. I work for a state agency, and a different state agency posted some training videos on youtube, but for some reason the only links they put on the website for them are the truncated ones. Truncated links are a known security issue, so I don't want to allow all of them, just these 5 so users can get to the training videos.&lt;/P&gt;&lt;P&gt;So we are not trying to restrict youtube to certain videos, I am trying to allow certain truncated links.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 13:21:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108393#M14619</guid>
      <dc:creator>shawmcbigdis</dc:creator>
      <dc:date>2021-01-21T13:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108709#M14708</link>
      <description>&lt;P&gt;You still need HTTPS Inspection enabled to "see" the precise URL.&lt;BR /&gt;Do you have this enabled or not?&lt;BR /&gt;Without it, you will not be able to allow access to these precise URLs since they are HTTPS links.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 05:31:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108709#M14708</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-25T05:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108754#M14723</link>
      <description>&lt;P&gt;I'm actually not sure if it is enabled or not. I inherited this Checkpoint, and have no experience with them prior, so figuring things out as I go.&amp;nbsp; How do I tell if it is enabled, and if not, how do I enable it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 13:10:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108754#M14723</guid>
      <dc:creator>shawmcbigdis</dc:creator>
      <dc:date>2021-01-25T13:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108788#M14731</link>
      <description>&lt;P&gt;You can look on the gateway object:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-01-25 at 8.53.07 AM.png" style="width: 750px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10341iD86EC0EDFF03F940/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-01-25 at 8.53.07 AM.png" alt="Screen Shot 2021-01-25 at 8.53.07 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The fact it doesn't work suggest it's probably not enabled.&lt;BR /&gt;Note: this has significant impact to your users and your overall gateway performance, not to mention requires some level of planning to do correctly.&lt;BR /&gt;This is not something that can or should be enabled lightly.&lt;/P&gt;
&lt;P&gt;What I suggest in this case is, since you generally allow access to YouTube anyway, allow access to its URL shortener prior to the rule that blocks URL shorteners (e.g. just the URL &lt;A href="https://youtu.be" target="_blank"&gt;https://youtu.be&lt;/A&gt;)&amp;nbsp;&lt;BR /&gt;This should work since we only need to see the certificate (more precisely the SNI portion) and it's not really a general purpose URL shortener.&lt;BR /&gt;When R80.30 shipped, SNI verification did require HTTPS Inspection be enabled (could be with an any any bypass rule), but I believe this is addressed in recent JHF (above Take 111) as well as in R80.40 and above.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 17:15:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108788#M14731</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-25T17:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108818#M14745</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;Message me privately and I can help you. I did https inspection for few customers and Im pretty experienced in it, if I say so myself : ). Im confident I can give you some insight. But, phoneboy is 100% correct...this will NEVER work without that feature enabled, because firewall will never know what is supposed to inspect. Technically, if you have url filtering blade enabled, you can allow those custom categories, but again, it might be tricky to make it work like that. Anyway, hit me up offline and lets fix this on webex or zoom.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 03:22:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108818#M14745</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-26T03:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108871#M14762</link>
      <description>&lt;P&gt;Thanks PhoneBoy, that did it. I would have rather narrowed it down to those specific URL's, but like you said this isn't a general purpose URL shortner, but the YouTube specific one. I have put a request in to the other agency to use the full links on their webpage also, so hopefully I can remove this in the future.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 13:11:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/108871#M14762</guid>
      <dc:creator>shawmcbigdis</dc:creator>
      <dc:date>2021-01-26T13:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/192616#M35607</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Taking advantage of the reason for this thread, I make the following query.&lt;/P&gt;
&lt;P&gt;Is it mandatory to activate HTTPS Inspection, when you activate the APPC+URLF blades?&lt;/P&gt;
&lt;P&gt;I have done a lab, where I activate these 2 blades, and manually block certain URLs that are in HTTPS, and the firewall, without problems, blocks the traffic, thus obeying my explicit rule.&lt;/P&gt;
&lt;P&gt;So, it leaves me with the doubt, is it mandatory to activate HTTPS Inspection?&lt;BR /&gt;Or is it more related to a "Best Practice" issue?&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 06:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/192616#M35607</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-14T06:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/192637#M35610</link>
      <description>&lt;P&gt;Its not mandatory, but since probably 98% of sites nowdays are https, thats where benefits of https inspection come in.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 10:01:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/192637#M35610</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-14T10:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/192649#M35612</link>
      <description>&lt;P&gt;This link bro explains inspection very well...its not official CP one, but same would apply.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.thesslstore.com/blog/ssl-inspection/" target="_blank"&gt;https://www.thesslstore.com/blog/ssl-inspection/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 13:26:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/192649#M35612</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-14T13:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Allow access to specific truncated URL's</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/192682#M35630</link>
      <description>&lt;P&gt;Mandatory? No.&lt;BR /&gt;However, it will be required to do any form of content inspection (either threats, DLP, or other).&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 22:49:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-access-to-specific-truncated-URL-s/m-p/192682#M35630</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-14T22:49:32Z</dc:date>
    </item>
  </channel>
</rss>

