<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Content Awareness not properly blocking files in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/112994#M15748</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;can you show us the UserCheck item settings? Maybe the fallback setting is set to "accept".&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 10 Mar 2021 16:08:10 GMT</pubDate>
    <dc:creator>Benedikt_Weissl</dc:creator>
    <dc:date>2021-03-10T16:08:10Z</dc:date>
    <item>
      <title>Content Awareness not properly blocking files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/112989#M15744</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;hope you're doing all well. We are in the process of evaluating the Check Point Threat Prevention Suite (against another solution) and we're stuck at Content Awareness right now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We just wanted to test a very basic rule to block executable files but we get very strange results - some files doesn't get blocked at all or only sometimes. TLS Inspection is enabled and the browser is limited to TLS 1.2 as we heard it may cause problems if the browser tries 1.3 and Check Point doesn't support it currently (R80.40 JHF 89).&lt;/P&gt;&lt;P&gt;The rule looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10807i6392E2044C1004FA/image-size/large?v=v2&amp;amp;px=999" role="button" title="rule.PNG" alt="rule.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The log entry looks like this when the file isn't blocked:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="redirect_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10808i238AAC63D5A9DB28/image-size/medium?v=v2&amp;amp;px=400" role="button" title="redirect_2.png" alt="redirect_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We can cleary see that the connections is Inspected and also the Rule and Data Type gets recognized correctly but the download is still possible.&lt;/P&gt;&lt;P&gt;We already tried a different host, putting the rule out of the inline layer and many small other things. Do you have any suggestion how to troubleshoot and what could be wrong?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 15:15:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/112989#M15744</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-03-10T15:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not properly blocking files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/112994#M15748</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;can you show us the UserCheck item settings? Maybe the fallback setting is set to "accept".&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 16:08:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/112994#M15748</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-03-10T16:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not properly blocking files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/113005#M15751</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;which exact setting are you referring to? I couldn't find UserCheck setting for any fallback:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="usercheck_1.PNG" style="width: 674px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10810i4A9D6F2BE0852B4E/image-size/large?v=v2&amp;amp;px=999" role="button" title="usercheck_1.PNG" alt="usercheck_1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On Content Awareness it's set at fail-open:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ca_1.PNG" style="width: 480px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10812iFD090FEB2431CB8E/image-size/large?v=v2&amp;amp;px=999" role="button" title="ca_1.PNG" alt="ca_1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 17:32:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/113005#M15751</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-03-10T17:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not properly blocking files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/113145#M15758</link>
      <description>&lt;P&gt;Then its a different UserCheck object, i thought it might be this setting and user notification can't be displayed:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_4bfebfe702ea8dBenedikt_Weissl_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="usercheck.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10917iA4A28C4706838481/image-size/medium?v=v2&amp;amp;px=400" role="button" title="usercheck.JPG" alt="usercheck.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 10:13:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/113145#M15758</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-03-11T10:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not properly blocking files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/113146#M15759</link>
      <description>&lt;P&gt;Ok, I see. The fallback option only appears on Ask-Templates but not on Drop-Templates.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 10:15:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/113146#M15759</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-03-11T10:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not properly blocking files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/113224#M15768</link>
      <description>&lt;P&gt;If you’re seeing an action of Redirect (which is what the log card says), it’s probably attempting to show the UserCheck drop page.&lt;BR /&gt;As it requires some data to be transferred to detect if it’s an EXE, it will appear as if a download starts but it should terminate before the file is completely downloaded.&lt;/P&gt;
&lt;P&gt;For downloaded files, showing a block page is probably counterproductive since the web browser won’t show that to the end user.&lt;BR /&gt;In fact: I would remove the UserCheck action from the rule.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 20:00:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/113224#M15768</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-11T20:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not properly blocking files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/113281#M15778</link>
      <description>&lt;P&gt;The drop page shouldn't be a problem as it shows correctly for other files that get blocked by the policy. I just tried changing the rule to just drop without UserCheck and the problem still exists. It's also a requirement for us to show the user that a file gets blocked on purpose and not just the fail message from the browser.&lt;/P&gt;&lt;P&gt;Let's see if TAC has any other ideas.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 08:19:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/113281#M15778</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-03-12T08:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not properly blocking files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/123446#M17730</link>
      <description>&lt;P&gt;I just came across my own old topic here and wanted to add the solution we found together in a great TAC session a few weeks ago.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem was in the HTTPS Inspection and not Content Awareness itself. We had the settings at "Background" and not "Hold" mode for a reason I don't remeber and that caused the issue. We also tried the UserCheck agent that I never heard of before and now we're also getting a pop-up if an error cannot be displayed in the browser.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 16:53:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-properly-blocking-files/m-p/123446#M17730</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-07-09T16:53:10Z</dc:date>
    </item>
  </channel>
</rss>

