<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic blocked by TP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197591#M36908</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Your recommendation is to make an exception policy in the TP section?&lt;/P&gt;
&lt;P&gt;Or is it to make a Bypass in the HTTPS Inspection section?&lt;/P&gt;
&lt;P&gt;Could you give me an example, please?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Thu, 09 Nov 2023 13:01:51 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-11-09T13:01:51Z</dc:date>
    <item>
      <title>Traffic blocked by TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197492#M36892</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I currently have HTTPS Inspection || AntiBot || Antivirus enabled, on my ClusterXL HA.&lt;/P&gt;
&lt;P&gt;The problem is that my local network cannot reach a URL that is on the Internet.&lt;/P&gt;
&lt;P&gt;What I see in the logs is that the traffic to the URL is "activating" the AntiBot blade.&lt;/P&gt;
&lt;P&gt;In the Cluster object in the SmartConsole, the Antibot&amp;amp;Antivirus section is set to "Detect Only" mode, but there is a rule in TP where the associated profile is the "Optimized" profile.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TP3.png" style="width: 871px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23128i699328257998F32A/image-size/large?v=v2&amp;amp;px=999" role="button" title="TP3.png" alt="TP3.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TP2.png" style="width: 918px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23129i668A1C2162E374A6/image-size/large?v=v2&amp;amp;px=999" role="button" title="TP2.png" alt="TP2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TP1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23130iB2C2C368E2EC14A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="TP1.png" alt="TP1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So, can the Cluster block the traffic ignoring the "Detect Only", and take more "priority" to the rule defined in the TP?&lt;/P&gt;
&lt;P&gt;I share a log where you can see better the traffic that I expose.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 19:14:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197492#M36892</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-08T19:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic blocked by TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197516#M36896</link>
      <description>&lt;P&gt;That attached log shows 'detect' action and a bunch of bytes tx and rx.&amp;nbsp; Maybe the site is not compatible/getting broken by HTTPS inspection and it is not the threat policy directly dropping it?&amp;nbsp; Could try to make a lower level exception/bypass of the threat policy, based on destination IP, to see if the site works solely with HTTPS inspection enabled.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 22:08:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197516#M36896</guid>
      <dc:creator>Lloyd_Braun</dc:creator>
      <dc:date>2023-11-08T22:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic blocked by TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197591#M36908</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Your recommendation is to make an exception policy in the TP section?&lt;/P&gt;
&lt;P&gt;Or is it to make a Bypass in the HTTPS Inspection section?&lt;/P&gt;
&lt;P&gt;Could you give me an example, please?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 13:01:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197591#M36908</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-09T13:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic blocked by TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197597#M36911</link>
      <description>&lt;P&gt;I was thinking a TP exception based on destination IP address, then if it is still broken, it would appear to be HTTPS inspection causing the issue.&amp;nbsp; You could also do HTTPS inspection bypass based on destination IP- I would assume that would fix it, but that also would blind the TP blade so you wouldn't know 100% if it was TP or HTTPSi that was breaking it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 13:53:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197597#M36911</guid>
      <dc:creator>Lloyd_Braun</dc:creator>
      <dc:date>2023-11-09T13:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic blocked by TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197598#M36912</link>
      <description>&lt;P&gt;I have the impression, that it is the blade of the Antibot.&lt;/P&gt;
&lt;P&gt;I am not sure.&lt;/P&gt;
&lt;P&gt;The Cluster object, in the "Antibot/Antivirus" section is set to DETECT ONLY, but other than that, we have an explicit rule in the TP section, and I'm not sure, if the CLUSTER, omits its global setting in the object and gives more importance to what is "explicitly" defined by rules.&lt;/P&gt;
&lt;P&gt;The explicit TP rule has an OPTIMIZED profile, and that profile, as I see, has several "PREVENT" enabled.&lt;/P&gt;
&lt;P&gt;Maybe this could be the root-cause of the problem.&lt;/P&gt;
&lt;P&gt;I am not sure about this behavior.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 13:59:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197598#M36912</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-09T13:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic blocked by TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197599#M36913</link>
      <description>&lt;P&gt;In your policy, detect is set for low confidence protections only. Why do you think that Anti-Bot is on detect only fully? Does not seem to be the case, if looking on the screenshot above. The log shows "High" confidence level, and it is set to Prevent&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 14:09:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197599#M36913</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-11-09T14:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic blocked by TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197601#M36914</link>
      <description>&lt;P&gt;I would say making an exception is your best bet.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 14:36:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-blocked-by-TP/m-p/197601#M36914</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-09T14:36:11Z</dc:date>
    </item>
  </channel>
</rss>

