<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Content Awareness not working properly in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/178826#M32760</link>
    <description>&lt;P&gt;The admin guide documents this as follows:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CTNT.PNG" style="width: 961px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20593i0C1D9A06FA28DE46/image-size/large?v=v2&amp;amp;px=999" role="button" title="CTNT.PNG" alt="CTNT.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Quantum_SecurityGateway_Guide/Topics-FWG/Content-Awareness-Blade.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Quantum_SecurityGateway_Guide/Topics-FWG/Content-Awareness-Blade.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additional caveats are outlined as follows:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="note.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20594i5F82560931EA3C18/image-size/large?v=v2&amp;amp;px=999" role="button" title="note.png" alt="note.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuide/Topics-SECMG/The-Columns-of-the-Access-Control-Rule-Base.htm?Highlight=%22content%20column%22" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuide/Topics-SECMG/The-Columns-of-the-Access-Control-Rule-Base.htm?Highlight=%22content%20column%22&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some best practices:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BP.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20595i8E1EFE5450B7C81F/image-size/large?v=v2&amp;amp;px=999" role="button" title="BP.PNG" alt="BP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuide/Topics-SECMG/Best-Practices-for-Access-Control-Rules.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuide/Topics-SECMG/Best-Practices-for-Access-Control-Rules.htm&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 23 Apr 2023 10:39:15 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-04-23T10:39:15Z</dc:date>
    <item>
      <title>Content Awareness not working properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/178598#M32741</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I’m using Content Awareness to block for exe files, however, I’m having difficulties making it work properly.&lt;/P&gt;&lt;P&gt;At the moment it is a very simple rule:&lt;/P&gt;&lt;P&gt;src=IP’s of internal hosts&lt;/P&gt;&lt;P&gt;Dst = Internet&lt;/P&gt;&lt;P&gt;Services &amp;amp; Applications = Any&lt;/P&gt;&lt;P&gt;Content = (Any Direction) Executable File&lt;/P&gt;&lt;P&gt;Action = Drop&lt;/P&gt;&lt;P&gt;I’m testing with 7-zip from &lt;A href="https://www.7-zip.org/download.html" target="_blank"&gt;https://www.7-zip.org/download.html&lt;/A&gt;. When I download the x64 version it downloads and doesn’t register the exe file. However, when I download the x32 version it blocks it accordring to the rule.&lt;/P&gt;&lt;P&gt;I’m also using HTTPS Inspection and it inspects traffic in both instances according to policy.&lt;/P&gt;&lt;P&gt;Version: R81, Take 81&lt;/P&gt;&lt;P&gt;Have any of you experienced anything like this and have any ideas as to how to fix it?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:10:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/178598#M32741</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2023-04-20T09:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not working properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/178772#M32742</link>
      <description>&lt;P&gt;What precise rule accepts the traffic otherwise?&lt;BR /&gt;In any case, I recommend a TAC case to assist in troubleshooting: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 20:10:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/178772#M32742</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-21T20:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not working properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/178775#M32743</link>
      <description>&lt;P&gt;Thats wrong and I will tell you why. I know it may sound stupid what I will say now, but, when it comes to content awareness, using services as any will never work properly. You need to use http and https in there.&lt;/P&gt;
&lt;P&gt;Give that a go and see what happens. If still same issue, please send a screenshot (blur out any sensitive info). I spent way too many hours with TAC escalations working on this lol&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 20:20:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/178775#M32743</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-21T20:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not working properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/178826#M32760</link>
      <description>&lt;P&gt;The admin guide documents this as follows:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CTNT.PNG" style="width: 961px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20593i0C1D9A06FA28DE46/image-size/large?v=v2&amp;amp;px=999" role="button" title="CTNT.PNG" alt="CTNT.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Quantum_SecurityGateway_Guide/Topics-FWG/Content-Awareness-Blade.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Quantum_SecurityGateway_Guide/Topics-FWG/Content-Awareness-Blade.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additional caveats are outlined as follows:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="note.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20594i5F82560931EA3C18/image-size/large?v=v2&amp;amp;px=999" role="button" title="note.png" alt="note.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuide/Topics-SECMG/The-Columns-of-the-Access-Control-Rule-Base.htm?Highlight=%22content%20column%22" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuide/Topics-SECMG/The-Columns-of-the-Access-Control-Rule-Base.htm?Highlight=%22content%20column%22&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some best practices:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BP.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20595i8E1EFE5450B7C81F/image-size/large?v=v2&amp;amp;px=999" role="button" title="BP.PNG" alt="BP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuide/Topics-SECMG/Best-Practices-for-Access-Control-Rules.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuide/Topics-SECMG/Best-Practices-for-Access-Control-Rules.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 10:39:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/178826#M32760</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-23T10:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not working properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/178837#M32763</link>
      <description>&lt;P&gt;See, the issue is, I only worked with 1 esc. guy who knew anything about content awareness. Now, in all fairness, I cant blame TAC for that, as its probably not something lots of customers use, so I dont expect to get someone with solid knowledge about it, its more trial and error as they say. Thats why I have it configured in the lab, so no one cares if it breaks, easy to reconfigure again : - )&lt;/P&gt;</description>
      <pubDate>Sun, 23 Apr 2023 14:50:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/178837#M32763</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-23T14:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not working properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/179059#M32820</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;I've now tried this and it didn't solve the issue, unfortunately, However, I seem to have been able to create a scenario, when it works - and when it doesn't.&lt;/P&gt;&lt;P&gt;If I open Chrome in Incognito and paste this URL into my browser:&amp;nbsp;Thanks for your reply.&lt;/P&gt;&lt;P&gt;I've now tried this and it didn't solve the issue, unfortunately, However, I seem to have been able to create a scenario, when it works - and when it doesn't.&lt;/P&gt;&lt;P&gt;If I open Chrome in Incognito and paste this URL (mirror site to download VLC, but slightly sanitized) into my browser:&amp;nbsp;&lt;A href="https://mirror.safe-con[.]dk/vlc/vlc/3.0.18/win64/vlc-3.0.18-win64.exe" target="_blank" rel="noopener"&gt;https://mirror.safe-con[.]dk/vlc/vlc/3.0.18/win64/vlc-3.0.18-win64.exe&lt;/A&gt; it blocks it according to the rule (208 in screenshot). If I then try again it accepts it and skips the rule and accepts it (rule 239 in screenshot):&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sc1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20626i98CC1C11596E5E8A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sc1.png" alt="sc1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;At the moment the rule looks as follows:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sc2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20627iBDDD76257D9DCAF9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sc2.png" alt="sc2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 09:59:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/179059#M32820</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2023-04-25T09:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness not working properly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/179185#M32840</link>
      <description>&lt;P&gt;You can see in the services column that the browser is using QUIC protocol for the communication in some cases rather than HTTPS.&lt;/P&gt;
&lt;P&gt;The Gateway cannot inspect QUIC traffic in current versions and it is recommended to block it (or disable it in the browser) to force the use of HTTPS instead which in turn should allow Content Awareness to apply.&lt;/P&gt;
&lt;P&gt;Refer also:&amp;nbsp;&lt;SPAN&gt;sk108202 /&amp;nbsp;sk111754 /&amp;nbsp;sk112249&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 01:11:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-not-working-properly/m-p/179185#M32840</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-26T01:11:09Z</dc:date>
    </item>
  </channel>
</rss>

