<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can not block TikTok in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/191280#M35310</link>
    <description>&lt;P&gt;upon further investigation, we found out this is an issue and open a support case; it's blocking on some gateways but in one specific network and the gateway the traffic going out, it is not blocked.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Aug 2023 19:58:07 GMT</pubDate>
    <dc:creator>Cyber_Serge</dc:creator>
    <dc:date>2023-08-31T19:58:07Z</dc:date>
    <item>
      <title>Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137254#M20770</link>
      <description>&lt;P&gt;Hi everyone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm having some problems blocking tiktok. Already block the app and domains with an Access Control Policy, in a way it worked but I still can see like 50% of the videos on the app. Is there something else that I can do?&lt;/P&gt;&lt;P&gt;Logs show that FW is blocking some traffic but the app uses different domains and cdn's to reach tiktok.&amp;nbsp;Is there something else that I can do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 17:18:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137254#M20770</guid>
      <dc:creator>Caez__</dc:creator>
      <dc:date>2021-12-27T17:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137263#M20771</link>
      <description>&lt;P&gt;What I do and ALWAYS works is add custom app with *domain*&lt;/P&gt;
&lt;P&gt;So, in your case just add custom site as *tiktok* and block it. Sometimes I found I may need to add any existing applications if they exist , but thats not often.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 18:07:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137263#M20771</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-27T18:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137270#M20774</link>
      <description>&lt;P&gt;This is the rule that I have created for this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="tiktok.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14711iCFA022F19AC322AA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tiktok.png" alt="tiktok.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I add on the tiktok custom site the app domains that I found here: &lt;A href="https://www.netify.ai/resources/applications/tiktok" target="_blank"&gt;https://www.netify.ai/resources/applications/tiktok&lt;/A&gt; . Is this what works for you? This is the config that blocks around half of the videos from the app for me.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 19:27:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137270#M20774</guid>
      <dc:creator>Caez__</dc:creator>
      <dc:date>2021-12-27T19:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137271#M20775</link>
      <description>&lt;P&gt;I attached how I would create custom site...not sure if you did it the same.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 19:31:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137271#M20775</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-27T19:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137272#M20776</link>
      <description>&lt;P&gt;Yes, config is the same, you can find it attached.&lt;/P&gt;&lt;P&gt;Still, some videos are passing&amp;nbsp;&lt;/P&gt;&lt;P&gt;You think there's something else that I can do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 20:03:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137272#M20776</guid>
      <dc:creator>Caez__</dc:creator>
      <dc:date>2021-12-27T20:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137273#M20777</link>
      <description>&lt;P&gt;In that case, you may need to examine the logs carefully and see why that happens. Do you have https inspection enabled or not?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 20:04:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137273#M20777</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-27T20:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137281#M20778</link>
      <description>&lt;P&gt;I don't have https inspection. What I see on the logs is that the App &amp;amp; URL Policy for TikTok (7) is actually blocking traffic, but the App &amp;amp; URL Cleanup rule (16) is matching some traffic and letting it pass, I think this would explain why I can see some videos but I don't know how to fix it. Cleanup rule is configured to let pass all traffic.&lt;/P&gt;&lt;P&gt;Here you can find attached some evidence.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 21:36:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137281#M20778</guid>
      <dc:creator>Caez__</dc:creator>
      <dc:date>2021-12-27T21:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137283#M20779</link>
      <description>&lt;P&gt;In some cases, you may need to add the IP addresses to block as well.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 00:32:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137283#M20779</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-28T00:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137297#M20783</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Cleanup rule is usually configured to drop all traffic not matched by other rules - that is how it got the name 8)&lt;/img&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 10:48:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137297#M20783</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-12-28T10:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137309#M20784</link>
      <description>&lt;P&gt;True that my friend :-). But, in all seriousness, it is recommended by CP to allow all at the bottom of ordered url and app control layer.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 12:42:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137309#M20784</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-28T12:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137313#M20785</link>
      <description>&lt;P&gt;That's how we have configured the url and app layer, so the traffic pass the rule that blocks tiktok (even when other traffic to the same IP addres is being blocked for that policy like I mentioned before) and goes all the way down to cleanup rule that allows all. This happens with a lot of IP addresess of tiktok, not just the one from the capture "Permit and block to same IP" that I attached before. Would you recommend to trace and block all those IP addresess?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 14:54:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137313#M20785</guid>
      <dc:creator>Caez__</dc:creator>
      <dc:date>2021-12-28T14:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137314#M20786</link>
      <description>&lt;P&gt;Yes, I would. Sadly, I had to do same for customers in some cases. Even TAC suggested the same. You can open support case to see if they suggest anything else though.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 14:58:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137314#M20786</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-28T14:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137327#M20790</link>
      <description>&lt;P&gt;I know that - but i would call it PassAll rule...&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 21:18:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137327#M20790</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-12-28T21:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137361#M20792</link>
      <description>&lt;P&gt;I will tell you what I find works the best, in my opinion...now, this might not be what most customers would do, but works well from what I experienced. Instead of say, creating another url and app control ordered layer, I always end up creating section towards the top of built in access layer with url and app control rules you need. The downside to it could be the fact that you have to enable those blades in this ordered layer, so acceleration might not work as well, but otherwise, I honestly had not seen any major issues with it.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 13:37:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/137361#M20792</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-29T13:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/175202#M31936</link>
      <description>&lt;P&gt;That's what I've always done, and agreed Checkpoint recommends that as well, so your application rules really should be block specific's and then allow everything else (as a generic rule of thumb).&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 09:54:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/175202#M31936</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2023-03-17T09:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/175205#M31937</link>
      <description>&lt;P&gt;Just a quick note - Checkpoint have added tiktok as an application&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tiktok.png" style="width: 458px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20135i7AAA990F67E38C99/image-size/large?v=v2&amp;amp;px=999" role="button" title="tiktok.png" alt="tiktok.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 09:59:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/175205#M31937</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2023-03-17T09:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/190912#M35243</link>
      <description>&lt;P&gt;I tried this method but this requires https inspection to work 100%. We see lot of traffic identified as TikTok and blocked, but the website still works and video still plays; Surely you'd think the easy solution is to enable https inspection, but that's not possible because we are talking about a wifi network. Users cannot be forced to download and install certificate for https inspection to work (especially on the mobile devices).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are able to block correctly using Harmony Mobile following the sk; but that's only managed devices. Devices not managed/guest devices is the concern here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interested in hearing some other ideas or suggestions. Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 14:04:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/190912#M35243</guid>
      <dc:creator>Cyber_Serge</dc:creator>
      <dc:date>2023-08-29T14:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can not block TikTok</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/191280#M35310</link>
      <description>&lt;P&gt;upon further investigation, we found out this is an issue and open a support case; it's blocking on some gateways but in one specific network and the gateway the traffic going out, it is not blocked.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 19:58:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-not-block-TikTok/m-p/191280#M35310</guid>
      <dc:creator>Cyber_Serge</dc:creator>
      <dc:date>2023-08-31T19:58:07Z</dc:date>
    </item>
  </channel>
</rss>

