<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserCheck/WebBlocked messages accessing all Internet sites in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-WebBlocked-messages-accessing-all-Internet-sites/m-p/121828#M17412</link>
    <description>&lt;P&gt;Thats a bit odd that users would get blocked page is https inspection is off. Can you send a screenshot if possible?&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jun 2021 13:46:22 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-06-22T13:46:22Z</dc:date>
    <item>
      <title>UserCheck/WebBlocked messages accessing all Internet sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-WebBlocked-messages-accessing-all-Internet-sites/m-p/121766#M17392</link>
      <description>&lt;P&gt;(2) 5000 appliances in HA active/passive - R80.30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;6/17: User A:&amp;nbsp;suddenly receiving UserCheck/WebBlocked messages accessing ANY/ALL Internet sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;IT support rebooted workstation,&amp;nbsp; logged in using their own credentials and they also got the UserCheck/WebBlocked messaged.&amp;nbsp; IT support installed USB-Ethernet Adapter to try to fix issue (?):, user acquired another ip on same subnet and was able to access Internet.&amp;nbsp; About a day later, USB-Ethernet Adapter removed&amp;nbsp; , user connection normalized. User able to access Internet. No other services (email, etc) impacted.&lt;/P&gt;&lt;P&gt;6/16: User B: suddenly receiving UserCheck/WebBlocked messages accessing ANY/ALL Internet sites&lt;/P&gt;&lt;P&gt;IT Support changed user over to WIFI (?) and user was able to access Internet.&amp;nbsp;No other services (email, etc) impacted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;All Internet access rules based on IdentityAwareness/AD query/. UserA/UserB log shows their requests&amp;nbsp; matching on a BlockedMessage rule which uses ip address only and action= deny for all Internet access.&amp;nbsp; Seems like User_A/B have "lost" their AD group mappings so their Internet access doesn't match on &amp;nbsp;rules based on IdentityAwareness/AD query and matches on the rule based on ip address, action=deny...Checking&amp;nbsp; pepd/ pdpd logs and AD server but nothing yet.&amp;nbsp; No recent changes - IA/AD query/UserCheck configs all active for 1 year+ w/no issues.&amp;nbsp; &amp;nbsp;Any suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 22:03:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-WebBlocked-messages-accessing-all-Internet-sites/m-p/121766#M17392</guid>
      <dc:creator>vlw38</dc:creator>
      <dc:date>2021-06-21T22:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck/WebBlocked messages accessing all Internet sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-WebBlocked-messages-accessing-all-Internet-sites/m-p/121773#M17393</link>
      <description>&lt;P&gt;What do your https inspection rules look like? When you have user belonging to say access role that would get blocked to for example, gambling sites, do you see block page and if you run command pdp monitor user username, what does it show? Say user ID is johnwayne, what would pdp monitor user johnwayne show you? Does it show that user belong to the right groups? Have you tried doing pdp update all?&lt;/P&gt;
&lt;P&gt;Is this brand new issue, has been happening for some time?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 00:18:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-WebBlocked-messages-accessing-all-Internet-sites/m-p/121773#M17393</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-22T00:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck/WebBlocked messages accessing all Internet sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-WebBlocked-messages-accessing-all-Internet-sites/m-p/121827#M17411</link>
      <description>&lt;P&gt;Thank you for responding.&amp;nbsp; HTTPS inspection not enabled. Ran PDP monitor and both users(s) belong to the correct groups. Have not tried pdp update all.&amp;nbsp; This is brand new issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 13:41:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-WebBlocked-messages-accessing-all-Internet-sites/m-p/121827#M17411</guid>
      <dc:creator>vlw38</dc:creator>
      <dc:date>2021-06-22T13:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: UserCheck/WebBlocked messages accessing all Internet sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-WebBlocked-messages-accessing-all-Internet-sites/m-p/121828#M17412</link>
      <description>&lt;P&gt;Thats a bit odd that users would get blocked page is https inspection is off. Can you send a screenshot if possible?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 13:46:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/UserCheck-WebBlocked-messages-accessing-all-Internet-sites/m-p/121828#M17412</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-22T13:46:22Z</dc:date>
    </item>
  </channel>
</rss>

