<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to indicate new URL to Check Point in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187929#M34650</link>
    <description>&lt;P&gt;URL categorization is valid according so that's why I was asking for guidance. Yeah, as a workaround we've created a threat prevention exception and raised a ticket.&lt;BR /&gt;&lt;BR /&gt;Those are not great articles but at least something what I could share to a customer:&lt;/P&gt;&lt;P&gt;- &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPImCAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPImCAO&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- &lt;A href="https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Newly-Observed-Domain-Webfilter-category/ta-p/250697" target="_blank"&gt;https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Newly-Observed-Domain-Webfilter-category/ta-p/250697&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jul 2023 06:12:42 GMT</pubDate>
    <dc:creator>zsszlama</dc:creator>
    <dc:date>2023-07-28T06:12:42Z</dc:date>
    <item>
      <title>How to indicate new URL to Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187799#M34625</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Lately we have encountered that when our customer creates a new a URL that is blocked by gateway due to Protection Type: DNS Reputation. As a workaround we create an exception for it.&lt;/P&gt;&lt;P&gt;My question is how we can indicate this to Check Point modify the reputation of the new URL to safe? I'm aware of &lt;A href="https://urlcat.checkpoint.com/urlcat/main.htm" target="_blank"&gt;https://urlcat.checkpoint.com/urlcat/main.htm&lt;/A&gt; but it's for categorization and in most cases the category of the URLs are valid, so it's not a solution.&lt;/P&gt;&lt;P&gt;An SK about a new URL's life would be also useful what we could show to our customers.&lt;/P&gt;&lt;P&gt;Could you please these questions?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Zsolt&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 07:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187799#M34625</guid>
      <dc:creator>zsszlama</dc:creator>
      <dc:date>2023-07-27T07:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to indicate new URL to Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187800#M34626</link>
      <description>&lt;P&gt;As part of the process, DNS reputation checks how long a domain/URL exists. To avoid false positives, an exception is the best way, since you know in advance what that domain / URL would look like.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 07:31:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187800#M34626</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-07-27T07:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to indicate new URL to Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187803#M34627</link>
      <description>&lt;P&gt;URL reputation is estimated by several services / sites, and CP is also using that information sources. You will have to contact each of these that report the bad reputation.&lt;/P&gt;
&lt;P&gt;But it can be the AV / AB blade that is reporting a certain URL as containing malware (look into log details) - in this case, TAC can help after opening a CP SR#.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 07:47:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187803#M34627</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-07-27T07:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to indicate new URL to Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187808#M34630</link>
      <description>&lt;P&gt;I thought that lifetime is the key indicator. Are you aware of any time limit for that even an SK what we could show to our customer?&lt;BR /&gt;(I don't want to advertise other vendors but I found such documents at the other big 2)&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 08:28:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187808#M34630</guid>
      <dc:creator>zsszlama</dc:creator>
      <dc:date>2023-07-27T08:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to indicate new URL to Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187858#M34639</link>
      <description>&lt;P&gt;URL Categorization (for Access Control) and Threat Prevention are handled differently.&lt;BR /&gt;You have the correct URL for reporting the correct category.&lt;BR /&gt;For false positives with respect to Threat Prevention, those need to be done through TAC: &lt;A href="https://help.checkpoint.com&amp;nbsp;" target="_blank"&gt;https://help.checkpoint.com&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;As for how the other “big two” handle this, you’re welcome to provide links to the relevant information since I’m not entirely clear what the actual question is here.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 12:51:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187858#M34639</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-27T12:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to indicate new URL to Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187929#M34650</link>
      <description>&lt;P&gt;URL categorization is valid according so that's why I was asking for guidance. Yeah, as a workaround we've created a threat prevention exception and raised a ticket.&lt;BR /&gt;&lt;BR /&gt;Those are not great articles but at least something what I could share to a customer:&lt;/P&gt;&lt;P&gt;- &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPImCAO" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PPImCAO&lt;/A&gt;&lt;/P&gt;&lt;P&gt;- &lt;A href="https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Newly-Observed-Domain-Webfilter-category/ta-p/250697" target="_blank"&gt;https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Newly-Observed-Domain-Webfilter-category/ta-p/250697&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 06:12:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187929#M34650</guid>
      <dc:creator>zsszlama</dc:creator>
      <dc:date>2023-07-28T06:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to indicate new URL to Check Point</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187984#M34652</link>
      <description>&lt;P&gt;I'm guessing the question is how we handle things we flag as "DNS Reputation."&lt;BR /&gt;Unfortunately, I haven't seen any documentation on this.&lt;BR /&gt;I do know that feedback is a part of the process, though.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 17:33:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-indicate-new-URL-to-Check-Point/m-p/187984#M34652</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-28T17:33:14Z</dc:date>
    </item>
  </channel>
</rss>

