<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does anyone know if there are any restrictions on scanning malicious URLs when using monitor mod in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-anyone-know-if-there-are-any-restrictions-on-scanning/m-p/168349#M30464</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/41270"&gt;@ChoiYunSoo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you are asking in the wrong board. The forum for Harmony Email &amp;amp; Collaboration is here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Email-and-Collaboration/bd-p/cloudguard-saas" target="_blank"&gt;https://community.checkpoint.com/t5/Email-and-Collaboration/bd-p/cloudguard-saas&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Abigael&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jan 2023 12:47:46 GMT</pubDate>
    <dc:creator>Abigael_Levy</dc:creator>
    <dc:date>2023-01-19T12:47:46Z</dc:date>
    <item>
      <title>Does anyone know if there are any restrictions on scanning malicious URLs when using monitor mode?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-anyone-know-if-there-are-any-restrictions-on-scanning/m-p/168347#M30463</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know if there are any restrictions on scanning malicious URLs when using monitor mode?&lt;/P&gt;&lt;P&gt;I am currently testing the check point e-mail security function in the internal environment in monitor mode.&lt;/P&gt;&lt;P&gt;Since it is a traffic mirror environment, MTA is disabled and only Threat Emulation, anti-virus, and anti-bot functions are enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Functions such as file emulation are showing satisfactory test results.&lt;/P&gt;&lt;P&gt;However, in the case of mailcious URLs attached to e-mails, it seems that they cannot be inspected properly in Monitor mode.&lt;/P&gt;&lt;P&gt;As far as I know, malicious URLs should generate logs after performing reputation-based inspection.&lt;/P&gt;&lt;P&gt;Reputation.However, in the current test environment, no logs related to URLs are left.&lt;/P&gt;&lt;P&gt;It looks like it probably doesn't perform any checks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tested in a real environment, not a mirror environment, to check if the test URL information was incorrect.&lt;/P&gt;&lt;P&gt;In a real environment, I checked the normal URL inspection log as expected.&lt;/P&gt;&lt;P&gt;As mentioned at the beginning, if there are any restrictions when using the monitor mode in these inspection logics, please let us know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 12:28:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-anyone-know-if-there-are-any-restrictions-on-scanning/m-p/168347#M30463</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2023-01-19T12:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know if there are any restrictions on scanning malicious URLs when using monitor mod</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-anyone-know-if-there-are-any-restrictions-on-scanning/m-p/168349#M30464</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/41270"&gt;@ChoiYunSoo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you are asking in the wrong board. The forum for Harmony Email &amp;amp; Collaboration is here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Email-and-Collaboration/bd-p/cloudguard-saas" target="_blank"&gt;https://community.checkpoint.com/t5/Email-and-Collaboration/bd-p/cloudguard-saas&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Abigael&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 12:47:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-anyone-know-if-there-are-any-restrictions-on-scanning/m-p/168349#M30464</guid>
      <dc:creator>Abigael_Levy</dc:creator>
      <dc:date>2023-01-19T12:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know if there are any restrictions on scanning malicious URLs when using monitor mod</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-anyone-know-if-there-are-any-restrictions-on-scanning/m-p/168354#M30465</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27338"&gt;@Abigael_Levy&lt;/a&gt;&amp;nbsp;moved to more appropriate space&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 13:35:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-anyone-know-if-there-are-any-restrictions-on-scanning/m-p/168354#M30465</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-19T13:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know if there are any restrictions on scanning malicious URLs when using monitor mod</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-anyone-know-if-there-are-any-restrictions-on-scanning/m-p/168381#M30466</link>
      <description>&lt;P&gt;Anything usually done by the MTA cannot be done in this case, especially if the communication is TLS encrypted.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 15:27:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-anyone-know-if-there-are-any-restrictions-on-scanning/m-p/168381#M30466</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-19T15:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Does anyone know if there are any restrictions on scanning malicious URLs when using monitor mod</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-anyone-know-if-there-are-any-restrictions-on-scanning/m-p/168421#M30467</link>
      <description>&lt;P&gt;This is referring to a Quantum Security Gateway running off a Mirror Port, so unrelated to Harmony Email and Collaboration &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;I believe MTA mode is required for scanning malicious URLs in email.&lt;BR /&gt;We definitely won't see malicious URLs in SMTP traffic when running off a Mirror Port if TLS is used.&lt;BR /&gt;Having said that, if you're seeing Threat Emulation for documents, malicious links inside of those documents should be scanned.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 18:09:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-anyone-know-if-there-are-any-restrictions-on-scanning/m-p/168421#M30467</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-19T18:09:53Z</dc:date>
    </item>
  </channel>
</rss>

