<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how do go about blocking a particular resource that i see on the ips log? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129881#M19064</link>
    <description>&lt;P&gt;Oh thank you once again for the quick reply, I will try it out and update here and if it doesn't work I will reach out to you thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 21 Sep 2021 18:08:21 GMT</pubDate>
    <dc:creator>kb1</dc:creator>
    <dc:date>2021-09-21T18:08:21Z</dc:date>
    <item>
      <title>how do go about blocking a particular resource that i see on the ips log?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129875#M19060</link>
      <description>&lt;P&gt;so i see this log on the checkpoint:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IPS log.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13751i950EF835636E4DA1/image-size/large?v=v2&amp;amp;px=999" role="button" title="IPS log.PNG" alt="IPS log.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;How do i go about blocking this resource "syndication.exoclick.com" on port 53? do i need to create a url rule for that? and how would it look like (we have url filtering blade enabled but not https inspection, categorize https inspection is enabled though). And if not url filtering then how else would i block it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 17:29:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129875#M19060</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-09-21T17:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: how do go about blocking a particular resource that i see on the ips log?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129877#M19061</link>
      <description>&lt;P&gt;Just my personal opinion...what I would do is create a rule that has a source as custom application/site object and in there, simply add under url list *syndication.exoclick*&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I find that doing it that way works 100% of the time, at least from my experience. Slap that as the source, destination any, action block, log and thats it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 17:54:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129877#M19061</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-21T17:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: how do go about blocking a particular resource that i see on the ips log?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129879#M19062</link>
      <description>&lt;P&gt;Thanks for replying but shouldn't it be a destination? You say source but it should be destination right?and source should be our internal network? And service selected should be 53?&lt;/P&gt;&lt;P&gt;And just to be clear *syndication.exoclick* will cover the "syndication.exoclick.com" url?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 18:01:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129879#M19062</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-09-21T18:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: how do go about blocking a particular resource that i see on the ips log?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129880#M19063</link>
      <description>&lt;P&gt;Yes, but my apologies, my first reply is wrong, my bad.&lt;/P&gt;
&lt;P&gt;Let me rephrase that...you cant do it as source or dst, you do it under service/application tabs...need more coffee :)). So once you had created that custom app/site, you have a rule like this, just tested it in my lab:&lt;/P&gt;
&lt;P&gt;source -&amp;gt; any&lt;/P&gt;
&lt;P&gt;destination -&amp;gt; Internet&lt;/P&gt;
&lt;P&gt;vpn -&amp;gt; any&lt;/P&gt;
&lt;P&gt;services &amp;amp; application -&amp;gt; custom app/site object you create (I named it sundication.exoclick and in "match by" I simply added *syndication.exoclick* and yes, 100% covers anything or any sub domain for that. Its literally if you wanted to block anything facebook under the sun, you could do the same *facebook*. I tried it many times and works like a charm.&lt;/P&gt;
&lt;P&gt;action -&amp;gt; block&lt;/P&gt;
&lt;P&gt;track -&amp;gt; log&lt;/P&gt;
&lt;P&gt;If you have any issues, hit me up and we can do remote.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 18:06:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129880#M19063</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-21T18:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: how do go about blocking a particular resource that i see on the ips log?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129881#M19064</link>
      <description>&lt;P&gt;Oh thank you once again for the quick reply, I will try it out and update here and if it doesn't work I will reach out to you thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 18:08:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129881#M19064</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2021-09-21T18:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: how do go about blocking a particular resource that i see on the ips log?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129882#M19065</link>
      <description>&lt;P&gt;Any time!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 18:09:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129882#M19065</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-21T18:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: how do go about blocking a particular resource that i see on the ips log?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129883#M19066</link>
      <description>&lt;P&gt;Forgot to mention, yes, you can also add services to rule like that, so if you ONLY wish to block service with port 53, you can do so, no problem...BUT, just be vigilant not to inadvertently block access to important service for network that should have it, thats all.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 18:17:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129883#M19066</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-21T18:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: how do go about blocking a particular resource that i see on the ips log?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129889#M19067</link>
      <description>&lt;P&gt;Using a custom application/site won’t work for things that aren’t http/https.&lt;BR /&gt;It is the sort of thing enabling DNS Trap will help with, which basically rewrites these lookups to “trap” IP addresses.&lt;BR /&gt;Note that prior to R81, these events show up as Detect even though they are effectively prevented.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 18:47:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/how-do-go-about-blocking-a-particular-resource-that-i-see-on-the/m-p/129889#M19067</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-21T18:47:09Z</dc:date>
    </item>
  </channel>
</rss>

