<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue on matching rules after upgrading to 81.10 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144937#M22605</link>
    <description>&lt;P&gt;HTTPS Inspection is needed to do full threat prevention and content inspection on encrypted traffic.&lt;/P&gt;
&lt;P&gt;SNI is used to identify domains you are accessing without decrypting the connection.&lt;BR /&gt;It can also be used to determine whether or not a connection requires full HTTPS Inspection (i.e. as part of a bypass rule).&lt;/P&gt;</description>
    <pubDate>Mon, 28 Mar 2022 23:51:32 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-03-28T23:51:32Z</dc:date>
    <item>
      <title>Issue on matching rules after upgrading to 81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144755#M22573</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;after upgrading our gateways and secure management server to 81.10, there is suddenly a matching issue. I am attaching images.&lt;/P&gt;&lt;P&gt;Rules we working appropriate before the update. What are you proposing in this case? (images attached)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="photo1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15848iAF3FBEF91E65C3F6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="photo1.PNG" alt="photo1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="photo2.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15849i5CEB872AC38A9F4D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="photo2.PNG" alt="photo2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and in some cases I am seeing these:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="photo3.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15850i858966436D2ACC46/image-size/medium?v=v2&amp;amp;px=400" role="button" title="photo3.PNG" alt="photo3.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="photo4.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15851iFE852320292F1049/image-size/medium?v=v2&amp;amp;px=400" role="button" title="photo4.PNG" alt="photo4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 05:09:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144755#M22573</guid>
      <dc:creator>Netadmin2020</dc:creator>
      <dc:date>2022-03-25T05:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Error on updating - Internal error in a hook script: bin/hook_cvpn_HOTFIX_R80_40_JUMBO_</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144729#M22576</link>
      <description>&lt;P&gt;after going to 81.10, I am experiencing a new issue. Suddenly the is a matching issue on many destinations.Images attached.&lt;/P&gt;&lt;P&gt;Rules were working appropriate on 80.40...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 22:21:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144729#M22576</guid>
      <dc:creator>Netadmin2020</dc:creator>
      <dc:date>2022-03-24T22:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issue on matching rules after upgrading to 81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144762#M22577</link>
      <description>&lt;P&gt;I would suggest to contact TAC !&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 08:15:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144762#M22577</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-25T08:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issue on matching rules after upgrading to 81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144789#M22583</link>
      <description>&lt;P&gt;Those drops are probably:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111643&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111643&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;BR /&gt;The ones with HTTPS Inspection are probably related to the SNI probing we do to validate SNI (which can be spoofed).&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 13:03:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144789#M22583</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-03-25T13:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Issue on matching rules after upgrading to 81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144828#M22592</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/43654"&gt;@Netadmin2020&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;M name is&amp;nbsp; Naama Specktor and I am checkpoint employee ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you opened a TAC SR , I will appreciate it if you will share the number .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Naama&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Mar 2022 07:24:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144828#M22592</guid>
      <dc:creator>Naama_Specktor</dc:creator>
      <dc:date>2022-03-27T07:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: Issue on matching rules after upgrading to 81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144829#M22593</link>
      <description>&lt;P&gt;I have already inform our partner for the current issue. I am little bit confused about https inspection and sni.Which is the best practice?&lt;/P&gt;&lt;P&gt;I am on 81.10, your proposal is to apply https bypass to everything and leave the sni to do the job?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Mar 2022 07:53:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144829#M22593</guid>
      <dc:creator>Netadmin2020</dc:creator>
      <dc:date>2022-03-27T07:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: Issue on matching rules after upgrading to 81.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144937#M22605</link>
      <description>&lt;P&gt;HTTPS Inspection is needed to do full threat prevention and content inspection on encrypted traffic.&lt;/P&gt;
&lt;P&gt;SNI is used to identify domains you are accessing without decrypting the connection.&lt;BR /&gt;It can also be used to determine whether or not a connection requires full HTTPS Inspection (i.e. as part of a bypass rule).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 23:51:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-on-matching-rules-after-upgrading-to-81-10/m-p/144937#M22605</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-03-28T23:51:32Z</dc:date>
    </item>
  </channel>
</rss>

