<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic App &amp; URL Filtering Behavior in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/App-URL-Filtering-Behavior/m-p/23238#M1785</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I deployed a CP firewall running R80.10 and I am using App &amp;amp; URL Filtering however, I noticed an abnormal behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I have a policy for Symantec Updates so my policy looks like the following below,&lt;/P&gt;&lt;P&gt;Source: Internal Subnet&lt;/P&gt;&lt;P&gt;Destination: Any&lt;/P&gt;&lt;P&gt;Service &amp;amp; Application: Symantec-Updates&lt;/P&gt;&lt;P&gt;Action: Permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I check the logs for the particular rule, I noticed some traffic which supposed to be not there like going to other site not related to Symantec.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know why is like that, is that normal or my rule is not correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Jan 2019 13:01:54 GMT</pubDate>
    <dc:creator>fatalXerror</dc:creator>
    <dc:date>2019-01-10T13:01:54Z</dc:date>
    <item>
      <title>App &amp; URL Filtering Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/App-URL-Filtering-Behavior/m-p/23238#M1785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I deployed a CP firewall running R80.10 and I am using App &amp;amp; URL Filtering however, I noticed an abnormal behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, I have a policy for Symantec Updates so my policy looks like the following below,&lt;/P&gt;&lt;P&gt;Source: Internal Subnet&lt;/P&gt;&lt;P&gt;Destination: Any&lt;/P&gt;&lt;P&gt;Service &amp;amp; Application: Symantec-Updates&lt;/P&gt;&lt;P&gt;Action: Permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I check the logs for the particular rule, I noticed some traffic which supposed to be not there like going to other site not related to Symantec.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know why is like that, is that normal or my rule is not correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 13:01:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/App-URL-Filtering-Behavior/m-p/23238#M1785</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-01-10T13:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: App &amp; URL Filtering Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/App-URL-Filtering-Behavior/m-p/23239#M1786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First, I'd set the destination to "Internet" as opposed to any (unless some of the traffic is destined internally).&lt;/P&gt;&lt;P&gt;It also could be a false positive, in which case the TAC will need to investigate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Jan 2019 21:07:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/App-URL-Filtering-Behavior/m-p/23239#M1786</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-12T21:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: App &amp; URL Filtering Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/App-URL-Filtering-Behavior/m-p/23240#M1787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch-Abernathy&lt;/A&gt;‌,&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for the feedback. Technically, "Internet" and "Any" should be the same right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 06:24:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/App-URL-Filtering-Behavior/m-p/23240#M1787</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-01-14T06:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: App &amp; URL Filtering Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/App-URL-Filtering-Behavior/m-p/23241#M1788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I find this thread especially educating on what is Internet when it comes to firewalls:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/6099-properly-defining-the-internet-within-a-security-policy" target="_blank"&gt;https://community.checkpoint.com/thread/6099-properly-defining-the-internet-within-a-security-policy&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:11:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/App-URL-Filtering-Behavior/m-p/23241#M1788</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2019-06-21T09:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: App &amp; URL Filtering Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/App-URL-Filtering-Behavior/m-p/23242#M1789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any literally means anything, including the Internet.&lt;/P&gt;&lt;P&gt;Internet does not include your internal networks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 13:36:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/App-URL-Filtering-Behavior/m-p/23242#M1789</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-14T13:36:25Z</dc:date>
    </item>
  </channel>
</rss>

