<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DLP blade is not working as expected in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214769#M41012</link>
    <description>&lt;P&gt;&lt;BR /&gt;Hi everyone,&lt;BR /&gt;&lt;BR /&gt;I'm setting up DLP Blade for POC at the customer (OpenServer - R81.20) but seems like it's not working correctly.&lt;BR /&gt;Here is the Policy:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fdf.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25789iCC63667B1C7921D1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="fdf.png" alt="fdf.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;So when the client behind the gateway tries to upload files:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Some sites working get log and alert email: Gmail, LinkedIn, Onedrive,...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25790iC8E7EB073A3BEFA3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="log.png" alt="log.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Some sites are not working (no DLP log, just normal traffic log): Google Drive, Facebook, Telegram,...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lognot.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25792iE1D8DB42700802AE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lognot.png" alt="lognot.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Other Blade I set the default configuration so I don't think it's a conflict.&lt;BR /&gt;Have I configured something wrong?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Please help me..&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you so much.&lt;/P&gt;</description>
    <pubDate>Sun, 19 May 2024 11:17:00 GMT</pubDate>
    <dc:creator>Phillip-83</dc:creator>
    <dc:date>2024-05-19T11:17:00Z</dc:date>
    <item>
      <title>DLP blade is not working as expected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214769#M41012</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hi everyone,&lt;BR /&gt;&lt;BR /&gt;I'm setting up DLP Blade for POC at the customer (OpenServer - R81.20) but seems like it's not working correctly.&lt;BR /&gt;Here is the Policy:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fdf.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25789iCC63667B1C7921D1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="fdf.png" alt="fdf.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;So when the client behind the gateway tries to upload files:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Some sites working get log and alert email: Gmail, LinkedIn, Onedrive,...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25790iC8E7EB073A3BEFA3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="log.png" alt="log.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Some sites are not working (no DLP log, just normal traffic log): Google Drive, Facebook, Telegram,...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lognot.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25792iE1D8DB42700802AE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lognot.png" alt="lognot.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Other Blade I set the default configuration so I don't think it's a conflict.&lt;BR /&gt;Have I configured something wrong?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Please help me..&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you so much.&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2024 11:17:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214769#M41012</guid>
      <dc:creator>Phillip-83</dc:creator>
      <dc:date>2024-05-19T11:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: DLP blade is not working as expected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214771#M41013</link>
      <description>&lt;P&gt;Are you doing HTTPS inspection on this traffic?&lt;/P&gt;
&lt;P&gt;The logs shows UDP 443 that is encryped.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/HTTPS-Inspection.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/HTTPS-Inspection.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2024 14:43:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214771#M41013</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-05-19T14:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: DLP blade is not working as expected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214773#M41014</link>
      <description>&lt;P&gt;Are you blocking QUIC traffic in your environment?&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2024 15:18:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214773#M41014</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-05-19T15:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: DLP blade is not working as expected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214786#M41021</link>
      <description>&lt;P&gt;As Chris said, QUIC can definitely be the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 01:13:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214786#M41021</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-20T01:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: DLP blade is not working as expected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214799#M41023</link>
      <description>&lt;P&gt;Https inspection already done:&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="httpsip.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25801i5CA85A7AE0397CFD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="httpsip.png" alt="httpsip.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I did install cert on client, in GG Drive website, that show https inspection cert:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cert.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25802i94D26117CD51F82C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cert.png" alt="cert.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 06:35:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214799#M41023</guid>
      <dc:creator>Phillip-83</dc:creator>
      <dc:date>2024-05-20T06:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: DLP blade is not working as expected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214802#M41024</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="quicblock.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25803iD64E2DE0696892B0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="quicblock.png" alt="quicblock.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'm testing with allow *any all, and block only quic UDP-443 in FW Layer, but DLP on GG Drive, Facebook,... still not working:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drive test.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25804iFDD2D7E7A94E8EBD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="drive test.png" alt="drive test.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 06:41:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214802#M41024</guid>
      <dc:creator>Phillip-83</dc:creator>
      <dc:date>2024-05-20T06:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: DLP blade is not working as expected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214803#M41025</link>
      <description>&lt;P&gt;Does zdebug show anything for the IP site resolves to?&lt;/P&gt;
&lt;P&gt;fw ctz zdebug + drop | grep x.x.x.x&lt;/P&gt;
&lt;P&gt;Just put the ip address after grep&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 06:44:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214803#M41025</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-20T06:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: DLP blade is not working as expected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214806#M41026</link>
      <description>&lt;P&gt;When i'm trying upload to drive:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="drip.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25805i93F20483181A7A31/image-size/medium?v=v2&amp;amp;px=400" role="button" title="drip.png" alt="drip.png" /&gt;&lt;/span&gt;&lt;FONT&gt; &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;run command I saw it's not dropping anything:&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cli.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25806i03D8521EEE199EE4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cli.png" alt="cli.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 07:12:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214806#M41026</guid>
      <dc:creator>Phillip-83</dc:creator>
      <dc:date>2024-05-20T07:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: DLP blade is not working as expected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214808#M41028</link>
      <description>&lt;P&gt;Hi the_rock, do we support to do the DLP Policy for native applications such as Google Driver, Telegram, Dropbox...?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 07:17:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214808#M41028</guid>
      <dc:creator>Binhn</dc:creator>
      <dc:date>2024-05-20T07:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: DLP blade is not working as expected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214809#M41029</link>
      <description>&lt;P&gt;You may want to ask internally as well, but Im pretty sure you do support it.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 07:23:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214809#M41029</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-20T07:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: DLP blade is not working as expected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214831#M41036</link>
      <description>&lt;P&gt;That is good! UDP 443 cannot be inspected and would be best to block. As others already posted. I can see you have done this now.&lt;/P&gt;
&lt;P&gt;Further info about this is listed here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk111754" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk111754&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Could it maybe be a character / language issue? If I see your screenshots &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_DataLossPrevention_AdminGuide/Content/Topics-DLPG/Regular-Expressions-and-Character-Sets.htm?TocPath=Regular%20Expressions%20and%20Character%20Sets%7CSupported%20Character%20Sets%7C_____0#Character_Types" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_DataLossPrevention_AdminGuide/Content/Topics-DLPG/Regular-Expressions-and-Character-Sets.htm?TocPath=Regular%20Expressions%20and%20Character%20Sets%7CSupported%20Character%20Sets%7C_____0#Character_Types&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 12:09:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DLP-blade-is-not-working-as-expected/m-p/214831#M41036</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-05-20T12:09:21Z</dc:date>
    </item>
  </channel>
</rss>

