<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic URL filtering in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering/m-p/144964#M22616</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;anyone can share me the best practice URL filtering on Checkpoint&amp;nbsp;&lt;/P&gt;&lt;P&gt;it is possible if the url/app&amp;nbsp; layer allows specific sources and destination with specific service&amp;nbsp;&lt;/P&gt;&lt;P&gt;The cleanup rule at url/ app layer&amp;nbsp;&lt;STRONG&gt; drop any&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---&amp;gt;&amp;gt; Based on my experience&amp;nbsp;&lt;/P&gt;&lt;P&gt;at URL and APP layer&amp;nbsp;&lt;/P&gt;&lt;P&gt;Deny specific destination URL or app&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15869i8E2ECDBDA6A49DBD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 853px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15866i8B26AE1A23DDCA61/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;I hope everyone can understand what I descript here.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Thanks&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2022 09:56:48 GMT</pubDate>
    <dc:creator>leangm</dc:creator>
    <dc:date>2022-03-29T09:56:48Z</dc:date>
    <item>
      <title>URL filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering/m-p/144964#M22616</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;anyone can share me the best practice URL filtering on Checkpoint&amp;nbsp;&lt;/P&gt;&lt;P&gt;it is possible if the url/app&amp;nbsp; layer allows specific sources and destination with specific service&amp;nbsp;&lt;/P&gt;&lt;P&gt;The cleanup rule at url/ app layer&amp;nbsp;&lt;STRONG&gt; drop any&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---&amp;gt;&amp;gt; Based on my experience&amp;nbsp;&lt;/P&gt;&lt;P&gt;at URL and APP layer&amp;nbsp;&lt;/P&gt;&lt;P&gt;Deny specific destination URL or app&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15869i8E2ECDBDA6A49DBD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 853px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15866i8B26AE1A23DDCA61/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;I hope everyone can understand what I descript here.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Thanks&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 09:56:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering/m-p/144964#M22616</guid>
      <dc:creator>leangm</dc:creator>
      <dc:date>2022-03-29T09:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: URL filtering</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering/m-p/144966#M22617</link>
      <description>&lt;P&gt;Do NOT do that...all traffic will be dropped. When you have more than 1 ordered layer, traffic has to be accepted on every ordered layer, see below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Ordered-Layers-and-Inline-Layers.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also, see link below, best practice for app control / url filtering and access control:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Best-Practices-for-Access-Control-Rules.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Best-Practices-for-Access-Control-Rules.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112249&amp;amp;partition=Basic&amp;amp;product=Application" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112249&amp;amp;partition=Basic&amp;amp;product=Application&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 09:50:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-filtering/m-p/144966#M22617</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-29T09:50:24Z</dc:date>
    </item>
  </channel>
</rss>

