<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practice when blocking URL in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/201054#M37779</link>
    <description>&lt;P&gt;Thats because on Fortinet, those things are not "separated" if you will, like they are on CP side. If its centrally managed, is MA blade enabled? Either way, maybe check with TAC whats the best way to do this.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 19 Dec 2023 13:09:32 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-12-19T13:09:32Z</dc:date>
    <item>
      <title>Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134712#M20227</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I would like some comments from the most experienced users about the best practice when blocking URL.&lt;/P&gt;&lt;P&gt;What I am trying to do is to block specific URL.&lt;/P&gt;&lt;P&gt;These URL may be part from 2 categories:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Phishing sites (not yet categorized by CheckPoint)&lt;/LI&gt;&lt;LI&gt;Normal web sites&lt;/LI&gt;&lt;/OL&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;What I have done as far:&lt;/P&gt;&lt;P&gt;Rule: Source-Any, Destination : Network Group Which includes destination objects (Domain, Host etc) , Action:Drop&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="urlblck.jpg" style="width: 915px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14345iE5280A9E2BC0EEDC/image-size/large?v=v2&amp;amp;px=999" role="button" title="urlblck.jpg" alt="urlblck.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The network group contains Domain objects (For example if I want to block &lt;A href="http://blockme.com/jgsgjs/fjsh/" target="_blank" rel="noopener"&gt;http://blockme.com/jgsgjs/fjsh/&lt;/A&gt;&amp;nbsp;I create a domain object &lt;EM&gt;.blockme.com&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;In this way I block all the domain which sometimes is not good.&lt;/P&gt;&lt;P&gt;For example when I want to block the phishing URL: &lt;A href="https://firebasestorage.googleapis.com/v0/b/kasyropnz.appspot.com/o/faswusamino.html" target="_blank" rel="noopener"&gt;https://firebasestorage.googleapis.com/v0/b/kasyropnz.appspot.com/o/faswusamino.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I have to block all the domain .&lt;A href="https://firebasestorage.googleapis.com/v0/b/kasyropnz.appspot.com/o/faswusamino.html" target="_blank" rel="noopener"&gt;firebasestorage.googleapis.com&lt;/A&gt;&amp;nbsp;which is not acceptable.&lt;/P&gt;&lt;P&gt;Any suggestions about the best practice?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 10:04:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134712#M20227</guid>
      <dc:creator>civoulkidis</dc:creator>
      <dc:date>2021-11-23T10:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134739#M20235</link>
      <description>&lt;P&gt;I will tell you what I always do and it works 100% of the time...I know Im not nearly as experienced as most folks here, but take it for what its worth : -). Ok, so just to give you a simple example, say you wish to block anything facebook and youtube, I would do exact same rule like you have, but in the destination, for url group, I put in custom links and say *facebook* and *youtube*, thats it. I included a screenshot for your reference.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 23 Nov 2021 14:46:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134739#M20235</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-23T14:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134850#M20273</link>
      <description>&lt;P&gt;*facebook* means that any url that contains the word facebook is matched?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 18:08:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134850#M20273</guid>
      <dc:creator>civoulkidis</dc:creator>
      <dc:date>2021-11-24T18:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134851#M20274</link>
      <description>&lt;P&gt;yes sir!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 18:10:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134851#M20274</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-24T18:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134874#M20288</link>
      <description>&lt;P&gt;Is there any guide about Regular Expressions?&lt;/P&gt;&lt;P&gt;For example I want to match and block the url &lt;A href="https://10120-0000-00010.pages.dev" target="_blank"&gt;https://10120-0000-00010.pages.dev&lt;/A&gt; which contains malicious.&lt;/P&gt;&lt;P&gt;This Reg Exp is not working.&amp;nbsp; &amp;nbsp; &amp;nbsp;/10120-0000-00010.pages.dev/&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is working but I have a warning for performance (sk165094)&lt;/P&gt;&lt;P&gt;*10120-0000-00010.pages.dev*&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 08:05:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134874#M20288</guid>
      <dc:creator>civoulkidis</dc:creator>
      <dc:date>2021-11-25T08:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134891#M20294</link>
      <description>&lt;P&gt;Look at&amp;nbsp;sk106623&lt;/P&gt;&lt;P&gt;Basically for your example the RegEx would be&amp;nbsp;&lt;SPAN&gt;\/10120-0000-0010\.pages\.com and for including subdomains additionally&amp;nbsp;\.10120-0000-0010\.pages\.com&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 10:24:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134891#M20294</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-11-25T10:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134896#M20297</link>
      <description>&lt;P&gt;&lt;STRONG&gt;10120-0000-00010\.pages\.dev&lt;/STRONG&gt;&amp;nbsp; worked for me and blocked the specific url&lt;/P&gt;&lt;P&gt;Note that I did not use &lt;STRONG&gt;/....../&lt;/STRONG&gt; at the beginning and at the end.&lt;/P&gt;&lt;P&gt;I have also checked "&lt;STRONG&gt;URLs are defined as Regular Expression&lt;/STRONG&gt;".&amp;nbsp;Is that correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 11:03:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134896#M20297</guid>
      <dc:creator>civoulkidis</dc:creator>
      <dc:date>2021-11-25T11:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134897#M20298</link>
      <description>&lt;P&gt;Yes, this is correct. Please note that without the /\ at the beginning you will also block abc&lt;SPAN&gt;10120-0000-0010.pages.com. Check that with a RegEx Tester like regex101.com.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 11:07:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134897#M20298</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-11-25T11:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134911#M20305</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11764"&gt;@Marcel_Gramalla&lt;/a&gt;&amp;nbsp;is correct. Personally, sk that pops up when you make those changes, you can follow it, but to make it simplified, if I need to block a full fqdn, I just do it without TLD (top level domains, such as .com, .org, .edu, .me...as I stated in my first response. It never fails and thats why I keep using that approach.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 14:05:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/134911#M20305</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-11-25T14:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/200870#M37736</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;Like this can I also block youtube for mobile devices?&lt;/P&gt;&lt;P&gt;I have SMB 1530 device and version is R81.10. I have blocked youtube for all users.&lt;/P&gt;&lt;P&gt;LIKE this src:lan subnet dst: any service/application:YoutubeApplication action:block&lt;/P&gt;&lt;P&gt;this rule can block youtube on desktop and laptop but not on android mobile device.&lt;/P&gt;&lt;P&gt;Do you know the solution of this?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2023 11:12:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/200870#M37736</guid>
      <dc:creator>007_mjn</dc:creator>
      <dc:date>2023-12-18T11:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/200884#M37741</link>
      <description>&lt;P&gt;I literally never work on these devices, but if I ever need anything, I either spin demo point lab from user center or log in using below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://demo700.checkpoint.com/" target="_blank"&gt;https://demo700.checkpoint.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;User: test_1234567890&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Password: %%7JvZp!!k%%&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Now, based on what I can see, appears option for mobile clients is under vpn, blade control and it appears to be enabled by default, but as far as how you control it, if its locally managed, most likely by regular rules, but if central, probably via mobile access blade. You may want to confirm this with TAC.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2023 13:05:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/200884#M37741</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-18T13:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/201001#M37764</link>
      <description>&lt;P&gt;Thanks for your quick support.&lt;/P&gt;&lt;P&gt;It's a centrally managed device and MAB portal is not available for SMB device. As far as I know MAB is used for secure remote access for android/IOS clients. I have worked on fortinet firewall and it block youtube for all devices.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 05:08:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/201001#M37764</guid>
      <dc:creator>007_mjn</dc:creator>
      <dc:date>2023-12-19T05:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/201002#M37765</link>
      <description>&lt;P&gt;I think application control blade have to block applications on all devices but it didn't block youtube application on mobile device.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 05:21:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/201002#M37765</guid>
      <dc:creator>007_mjn</dc:creator>
      <dc:date>2023-12-19T05:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/201054#M37779</link>
      <description>&lt;P&gt;Thats because on Fortinet, those things are not "separated" if you will, like they are on CP side. If its centrally managed, is MA blade enabled? Either way, maybe check with TAC whats the best way to do this.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 13:09:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/201054#M37779</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-19T13:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/201155#M37806</link>
      <description>&lt;P&gt;MAB is only required to terminate the Capsule Workspace client.&lt;BR /&gt;Check Point Mobile clients for Android/iOS can terminate on an SMB gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 01:28:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/201155#M37806</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-20T01:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practice when blocking URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/201168#M37808</link>
      <description>&lt;P&gt;ok, I know MAB is only used for capsule workspace.&lt;/P&gt;&lt;P&gt;for mobile devices I will raise a TAC case.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 09:04:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practice-when-blocking-URL/m-p/201168#M37808</guid>
      <dc:creator>007_mjn</dc:creator>
      <dc:date>2023-12-20T09:04:03Z</dc:date>
    </item>
  </channel>
</rss>

