<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Uncategorized URL Allowed By CheckPoint??? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122772#M17568</link>
    <description>&lt;P&gt;Like I said, it may be that the traffic initially looks like something your rules allow for.&lt;BR /&gt;This would require some additional troubleshooting and information.&lt;BR /&gt;I'd probably start with this:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92743" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92743&lt;/A&gt;&lt;BR /&gt;But I really recommend bringing this through the TAC.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jul 2021 22:15:28 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-07-01T22:15:28Z</dc:date>
    <item>
      <title>Uncategorized URL Allowed By CheckPoint???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122398#M17520</link>
      <description>&lt;P&gt;Can someone tell me why the transfercarenacka.com URL / domain was allowed when we did not allow the "Uncategorized" category? We allow the "Computers / Internet" category which contabo.net matches, but you can see that transfercarenacka.com is uncategorized by URL filtering in the screenshot below. So why would it be allowed? Under Matched Rules, it shows that it matched our our whitelist rule which does NOT include the "Uncategorized" category.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CheckPoint URL Filtering - Uncategorized Allowed.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12351i0EB7FCF8B5D5B480/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CheckPoint URL Filtering - Uncategorized Allowed.png" alt="CheckPoint URL Filtering - Uncategorized Allowed.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 17:59:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122398#M17520</guid>
      <dc:creator>B_P</dc:creator>
      <dc:date>2021-06-28T17:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Uncategorized URL Allowed By CheckPoint???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122421#M17526</link>
      <description>&lt;P&gt;What is the precise rule allowing this traffic?&lt;BR /&gt;Also what is the version/JHF level of the gateway?&lt;BR /&gt;It may be the CN of the site certificate is allowed but you are not using a version that supports SNI verification.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 03:04:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122421#M17526</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-29T03:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Uncategorized URL Allowed By CheckPoint???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122653#M17547</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;What is the precise rule allowing this traffic?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The Source is a bunch of different networks, the Destination is the "Internet" and the Services &amp;amp; Application is a group containing various URL Categories.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Also what is the version/JHF level of the gateway?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;R80.40 JHF 118&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;It may be the CN of the site certificate is allowed but you are not using a version that supports SNI verification.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The gateway already identified the website as an Uncategorized URL (as you can see in the picture above). Are you suggesting that the Firewall will ignore its own categorization?&lt;/P&gt;&lt;P&gt;BTW, we got the desired behavior by adding another rule directly above the original rule (as described above), but made the Services &amp;amp; Application be Uncategorized and Action set to Drop. Which that absolutely should not have been necessary. The gateway was otherwise allowing stuff it should not have been. How can this be?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 01:02:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122653#M17547</guid>
      <dc:creator>B_P</dc:creator>
      <dc:date>2021-07-01T01:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Uncategorized URL Allowed By CheckPoint???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122658#M17549</link>
      <description>&lt;P&gt;If your requirement is to drop web traffic to uncategorized sites, you may need an explicit rule to drop it.&lt;BR /&gt;The reason why is that for&amp;nbsp;Application Control/URL Filtering to work, traffic has to be permitted to pass from the specified source/destination/service ports.&lt;BR /&gt;Only after some traffic has passed can traffic be properly classified, matched to the relevant rule, and the appropriate action applied.&lt;/P&gt;
&lt;P&gt;Note that identification is a continual process.&lt;BR /&gt;A given flow can initially be allowed because it looks like an allowed application.&lt;BR /&gt;Once it looks like an explicitly unallowed application, the flow will be dropped.&lt;/P&gt;
&lt;P&gt;If the connection terminates before an identification can occur, then the traffic will ultimately be allowed.&lt;BR /&gt;That could be what's happening here, but I'd need to see the full log card, and/or do some additional troubleshooting that would likely be better done by the TAC versus in a public forum.&lt;/P&gt;
&lt;P&gt;Regardless, you're better off always including an explicit rule to drop uncategorized sites if that is part of your requirements.&lt;BR /&gt;It generally doesn't take more than a few kilobytes of traffic to identify these connections.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 02:53:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122658#M17549</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-01T02:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: Uncategorized URL Allowed By CheckPoint???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122765#M17567</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Only after some traffic has passed can traffic be properly classified, matched to the relevant rule, and the appropriate action applied.&lt;/P&gt;&lt;P&gt;A given flow can initially be allowed because it looks like an allowed application.&lt;BR /&gt;Once it looks like an explicitly unallowed application, the flow will be dropped.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I'm aware of that, but if you sit there hitting refresh a bunch of times and other computers access the website as well, the firewall should know the site should be blocked, no? I've seen in the past where a website may load the first time, but subsequent hits will not; which I would be ok with that. But in this scenario, it just continually allowed it.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Regardless, you're better off always including an explicit rule to drop uncategorized sites if that is part of your requirements.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;If you do not allow something, it should not be allowed. If the firewall is allowing stuff it should not be, that is kind of a problem, no?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 20:44:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122765#M17567</guid>
      <dc:creator>B_P</dc:creator>
      <dc:date>2021-07-01T20:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Uncategorized URL Allowed By CheckPoint???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122772#M17568</link>
      <description>&lt;P&gt;Like I said, it may be that the traffic initially looks like something your rules allow for.&lt;BR /&gt;This would require some additional troubleshooting and information.&lt;BR /&gt;I'd probably start with this:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92743" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92743&lt;/A&gt;&lt;BR /&gt;But I really recommend bringing this through the TAC.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 22:15:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uncategorized-URL-Allowed-By-CheckPoint/m-p/122772#M17568</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-01T22:15:28Z</dc:date>
    </item>
  </channel>
</rss>

