<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Usercheck acting weird in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201875#M37991</link>
    <description>&lt;P&gt;What is the purpose of Userchek then, if Chrome (which is the most used browser) will block it?&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jan 2024 15:23:03 GMT</pubDate>
    <dc:creator>Moudar</dc:creator>
    <dc:date>2024-01-01T15:23:03Z</dc:date>
    <item>
      <title>Usercheck acting weird</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201873#M37989</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;On my lab I am trying to use usercheck alongside with HTTPS inspection:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23849i0E902EA6AD4FFEEC/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Rule 11.2&lt;/P&gt;&lt;P&gt;When trying to connect to Cnn.com a notification comes up and everything is fine and work as expected.&lt;/P&gt;&lt;P&gt;When try to connect to Youtube or facebook i get "this site can't be reached"&lt;/P&gt;&lt;P&gt;when checking the logs i see that youtube and facebook are rejected for a reason that i don't know:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23850i4F959BEBBC0DF062/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I don't know why rule 11.2 is rejecting youtube and facebook when the action is inform and cnn is working!&lt;/P&gt;&lt;P&gt;this is how HTTPS inspection is configured:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23851iB4CFE0FB6242CB4B/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.PNG" alt="4.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2024 14:47:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201873#M37989</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-01-01T14:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck acting weird</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201874#M37990</link>
      <description>&lt;P&gt;Your browser (probably Chrome) has pinned HTTPS certificates for popular sites such as facebook and definitely youtube which is a google-owed site.&amp;nbsp; In these cases the browser itself will block the display of the UserCheck as a man-in-the-middle attack, which it most certainly is.&amp;nbsp; Try a few different browsers.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2024 15:10:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201874#M37990</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-01-01T15:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck acting weird</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201875#M37991</link>
      <description>&lt;P&gt;What is the purpose of Userchek then, if Chrome (which is the most used browser) will block it?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2024 15:23:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201875#M37991</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-01-01T15:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck acting weird</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201877#M37993</link>
      <description>&lt;P&gt;Chrome will only block UserChecks for sites whose certificates are pinned in the browser, which will always include google-owned sites (youtube, google.com, etc) and key major sites like fakebook.&amp;nbsp; Chrome is sensing what it perceives to be a man in the middle attack and blocking it, and there is no way to disable this that I know of.&lt;/P&gt;
&lt;P&gt;The purpose of UserChecks is attempting to notify the user that their connection was blocked (it is not a connectivity/DNS problem), and provide a reference number they can use when trying to find the specific block event in the logs.&amp;nbsp; However there are a variety of technical situations where a UserCheck cannot be sent to the user, or it is sent but the user cannot see it.&amp;nbsp; You have run into one of those situations.&amp;nbsp; Another example: any blocks/drops by the IPS blade will never send a UserCheck as IPS does not support that feature at all.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2024 21:57:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201877#M37993</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-01-01T21:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck acting weird</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201878#M37994</link>
      <description>&lt;P&gt;Make sure user check is enabled for all interfaces under gateway object properties (portal -&amp;gt; user check) and test. if same issue, try maybe resetting Chroms browser and see if same happens.&lt;/P&gt;
&lt;P&gt;Happy New Year.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2024 22:33:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201878#M37994</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-01T22:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck acting weird</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201889#M37997</link>
      <description>&lt;P&gt;The issue in your policy is that Facebook and YouTube is not HTTPS inspected but bypassed as shown in your screenshot. This is because you use the "HTTPS services - bypass" object where Facebook is included (and bypassed). You can find all domains etc. in this SK&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk163595" target="_blank"&gt;HTTPS Inspection bypass list object (checkpoint.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;And if your gateway doesn't inspect the traffic it can't display the UserCheck page and simply rejects the connection which is to be expected.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 10:19:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201889#M37997</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2024-01-02T10:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: Usercheck acting weird</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201920#M38001</link>
      <description>&lt;P&gt;Thats an excellent point, did not see that from the screenshots the first time.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2024 13:52:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Usercheck-acting-weird/m-p/201920#M38001</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-02T13:52:57Z</dc:date>
    </item>
  </channel>
</rss>

