<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Acessing URL matched and DROP with different rule (Logs showing additional domain address) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155175#M26428</link>
    <description>&lt;P&gt;Honestly, if I were in your situation, best thing I would look for is logs in smart dashboard and also maybe search for keywords in messages files...so for example, if you are wondering about specific site, say &lt;A href="http://www.cnn.com" target="_blank"&gt;www.cnn.com&lt;/A&gt;&amp;nbsp;(just as an example), you could do something like this from gateway master member (if its a cluster)&lt;/P&gt;
&lt;P&gt;grep -i cnn /var/log/messages*&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 17 Aug 2022 21:17:45 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-08-17T21:17:45Z</dc:date>
    <item>
      <title>Acessing URL matched and DROP with different rule (Logs showing additional domain address)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155115#M26424</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We are accessing a&amp;nbsp;genuine URL but its DROP by matching a drop rule.&lt;/P&gt;&lt;P&gt;We check the logs and find out that its showing destination as a as accessing URL but also a additional domain address "&lt;STRONG&gt;workisboring.com&lt;/STRONG&gt;".&lt;/P&gt;&lt;P&gt;For&amp;nbsp;&lt;STRONG&gt;workisboring.com &lt;/STRONG&gt;we already created a DROP rule for this which matched in our case for intial 5 to 10 min for 1st time access and then its matched the accept rule and able to access the URL and then again we checked the logs find out that its matched the accept rule but this time we have not saw the additinal&amp;nbsp;&lt;STRONG&gt;workisboring.com &lt;/STRONG&gt;because now its matched on different rule.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Let me knnown Team what is the issue that time?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PHOTO-2022-08-17-10-12-34.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17446i102FEF190574C7A1/image-size/large?v=v2&amp;amp;px=999" role="button" title="PHOTO-2022-08-17-10-12-34.jpg" alt="PHOTO-2022-08-17-10-12-34.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 07:46:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155115#M26424</guid>
      <dc:creator>Bulu_N</dc:creator>
      <dc:date>2022-08-17T07:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: Acessing URL matched and DROP with different rule (Logs showing additional domain address)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155130#M26425</link>
      <description>&lt;P&gt;What precise rule is it matching on?&lt;BR /&gt;What precise rule do you believe it should be matching on?&lt;BR /&gt;Is HTTPS Inspection being used?&lt;BR /&gt;What version/JHF?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 14:06:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155130#M26425</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-08-17T14:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Acessing URL matched and DROP with different rule (Logs showing additional domain address)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155134#M26426</link>
      <description>&lt;P&gt;Here are my questions...&lt;/P&gt;
&lt;P&gt;1) What rule is it dropped on?&lt;/P&gt;
&lt;P&gt;2) Are you using ORDERED or INLINE layer for URL filtering?&lt;/P&gt;
&lt;P&gt;3) Did this ever work before?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 14:15:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155134#M26426</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-17T14:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Acessing URL matched and DROP with different rule (Logs showing additional domain address)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155169#M26427</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi&amp;nbsp;Andy,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thank you so much for the response.&lt;/P&gt;&lt;P&gt;Here are my Answers :&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) What rule is it dropped on?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Rule number is 3 and 4 which is we using for block the incoming and outgoing connection towards black&lt;/STRONG&gt;&lt;STRONG&gt;list IP address&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;we mentioned sources as ANY and destination as blacklisted &lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;on&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;rule number 3 which we are multiple Blacklisted IP address as well as domain address also &amp;nbsp;rule 4 for outgoing source will be Black listed IP address.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2) Are you using ORDERED or INLINE layer for URL filtering?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;ORDERED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;3) Did this ever work before?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Yes its working fine before but after upgrading to R81.10 we face this kind of issue&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;so during the firs time only we face this issue for few minutes and then it’s automatically working fine and till 3 days gone we haven’t see the access issue.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I Need a RCA for this pls help&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 20:05:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155169#M26427</guid>
      <dc:creator>Bulu_N</dc:creator>
      <dc:date>2022-08-17T20:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Acessing URL matched and DROP with different rule (Logs showing additional domain address)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155175#M26428</link>
      <description>&lt;P&gt;Honestly, if I were in your situation, best thing I would look for is logs in smart dashboard and also maybe search for keywords in messages files...so for example, if you are wondering about specific site, say &lt;A href="http://www.cnn.com" target="_blank"&gt;www.cnn.com&lt;/A&gt;&amp;nbsp;(just as an example), you could do something like this from gateway master member (if its a cluster)&lt;/P&gt;
&lt;P&gt;grep -i cnn /var/log/messages*&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 21:17:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155175#M26428</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-17T21:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Acessing URL matched and DROP with different rule (Logs showing additional domain address)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155225#M26429</link>
      <description>&lt;P&gt;If you need a formal RCA, please open a TAC case.&lt;/P&gt;
&lt;P&gt;That said, it's pretty obvious there is something in the traffic that causes it to be classified differently at different points of time.&lt;BR /&gt;As we are continually analyzing traffic flows, this is normal.&lt;BR /&gt;Packet captures of the relevant traffic are likely required to understand what's happening and why.&lt;BR /&gt;There are likely other debugs necessary here that the TAC can advise you on.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 15:19:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155225#M26429</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-08-18T15:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Acessing URL matched and DROP with different rule (Logs showing additional domain address)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155234#M26430</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/52830"&gt;@Bulu_N&lt;/a&gt;&amp;nbsp;...I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;and his last response. Those are all GREAT points, so TAC case would probably be best in your case.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Aug 2022 16:41:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155234#M26430</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-18T16:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Acessing URL matched and DROP with different rule (Logs showing additional domain address)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155354#M26431</link>
      <description>&lt;P&gt;Manage and settings / blades / application control And URL filtering / advanced settings / general / Fail mode&lt;BR /&gt;is it set to fail-open or fail-closed ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if its failed-closed I would check var/log/messages for the same time as you saw drops for any indication of errors.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 02:29:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Acessing-URL-matched-and-DROP-with-different-rule-Logs-showing/m-p/155354#M26431</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2022-08-22T02:29:06Z</dc:date>
    </item>
  </channel>
</rss>

