<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225390#M43365</link>
    <description>&lt;P&gt;correct. The log in the screenshot is application layer&lt;/P&gt;</description>
    <pubDate>Mon, 02 Sep 2024 22:18:05 GMT</pubDate>
    <dc:creator>Emil_T</dc:creator>
    <dc:date>2024-09-02T22:18:05Z</dc:date>
    <item>
      <title>Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225382#M43359</link>
      <description>&lt;P&gt;I have proxy configured in gateway's object (HA) Under Topology &amp;gt; Proxy &amp;gt; Use custom proxy.&lt;/P&gt;&lt;P&gt;I can see in traffic logs that most of the traffic coming form gateway indeed goes to the proxy.&lt;/P&gt;&lt;P&gt;But some traffic is still going directly.&amp;nbsp;I see logs to&amp;nbsp;&lt;SPAN&gt;dl3.checkpoint.com and to updates.checkpoint.com.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Why is this happening?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Screenshot 2024-09-02 173926.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27474iCD91CAC21DD25AD1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-09-02 173926.png" alt="Screenshot 2024-09-02 173926.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-09-02 175530.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27475iFF78495355572BFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-09-02 175530.png" alt="Screenshot 2024-09-02 175530.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 21:55:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225382#M43359</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2024-09-02T21:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225383#M43360</link>
      <description>&lt;P&gt;Are you able to send screenshot of the rule?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 21:52:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225383#M43360</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-02T21:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225385#M43361</link>
      <description>&lt;P&gt;Updated in the original post&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 21:56:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225385#M43361</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2024-09-02T21:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225386#M43362</link>
      <description>&lt;P&gt;Screenshot of the RULE, not the log.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 21:57:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225386#M43362</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-02T21:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225387#M43363</link>
      <description>&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 22:16:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225387#M43363</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2024-09-02T22:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225389#M43364</link>
      <description>&lt;P&gt;Sorry, see it now, not sure why I could not before &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Just wondering, is that layer with fw and urlf/appc enabled?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 22:07:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225389#M43364</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-02T22:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225390#M43365</link>
      <description>&lt;P&gt;correct. The log in the screenshot is application layer&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 22:18:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225390#M43365</guid>
      <dc:creator>Emil_T</dc:creator>
      <dc:date>2024-09-02T22:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225391#M43366</link>
      <description>&lt;P&gt;Not sure, maybe its by default, TAC can confirm.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 22:23:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225391#M43366</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-02T22:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225480#M43388</link>
      <description>&lt;P&gt;Possibly a bug.&lt;BR /&gt;Suggest involving TAC: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 13:52:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/225480#M43388</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-03T13:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/271257#M103453</link>
      <description>&lt;P&gt;HMMMM Very Interesting. We have an MDS R81.20 and it's the MDS IP Address that seems to be bypassing the proxy every night at 2:30 AM as seen on the adjacent internet facing FW.&lt;/P&gt;&lt;P&gt;Diagram = &amp;lt;MDS&amp;gt; &amp;lt;CP Proxy FW&amp;gt; &amp;lt;Internet FW&amp;gt; &amp;lt;ISP&amp;gt;&lt;/P&gt;&lt;P&gt;Let me dig into the outbound IP's a little more but logs show it's cloudfront.net and I read somewhere that was CP Web Services hosted in AWS&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scrubbed-log-021726.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33383iD58A6D92F827D2A8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="scrubbed-log-021726.png" alt="scrubbed-log-021726.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update#2 the three IP's the MDS is accessing are&lt;/P&gt;&lt;P&gt;DST -&lt;/P&gt;&lt;P&gt;3.167.152.116 - AWS&lt;/P&gt;&lt;P&gt;52.85.12.125 - AWS&lt;/P&gt;&lt;P&gt;13.225.143.28 - AWS&lt;/P&gt;&lt;P&gt;How do we find out what those IP's are used for (ie URLF Updates, etc)&lt;/P&gt;&lt;P&gt;Update #3&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Found this one - 3.167.152.116 - AWS = updates.checkpoint.com&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 20:10:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/271257#M103453</guid>
      <dc:creator>D_Riddleberger</dc:creator>
      <dc:date>2026-02-18T20:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/271307#M103471</link>
      <description>&lt;P&gt;Hey Dan,&lt;/P&gt;
&lt;P&gt;What do you get when running below?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@CP-GW:0]# nslookup updates.checkpoint.com&lt;BR /&gt;Server: 8.8.8.8&lt;BR /&gt;Address: 8.8.8.8#53&lt;/P&gt;
&lt;P&gt;Non-authoritative answer:&lt;BR /&gt;updates.checkpoint.com canonical name = updates.g04.checkpoint.com.&lt;BR /&gt;updates.g04.checkpoint.com canonical name = d3dzd94mv2pmza.cloudfront.net.&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 18.245.104.59&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 18.245.104.81&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 18.245.104.64&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 18.245.104.80&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 2600:9000:26c2:9c00:19:dc2f:a580:93a1&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 2600:9000:26c2:ba00:19:dc2f:a580:93a1&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 2600:9000:26c2:fe00:19:dc2f:a580:93a1&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 2600:9000:26c2:3c00:19:dc2f:a580:93a1&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 2600:9000:26c2:f800:19:dc2f:a580:93a1&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 2600:9000:26c2:d000:19:dc2f:a580:93a1&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 2600:9000:26c2:2400:19:dc2f:a580:93a1&lt;BR /&gt;Name: d3dzd94mv2pmza.cloudfront.net&lt;BR /&gt;Address: 2600:9000:26c2:8a00:19:dc2f:a580:93a1&lt;/P&gt;
&lt;P&gt;[Expert@CP-GW:0]#&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 12:56:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/271307#M103471</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-19T12:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway IPS, AV, AB, Contract updating directly while proxy configured</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/271478#M103505</link>
      <description>&lt;P&gt;Ok a couple of updates. This environment 'which is highly sensitive' is totally locked down from a Security Policy to L2 and L3 Switches which drops everything from Ping, Traceroute, Tcptraceroute, etc so no 'joy' trying to use those tools for some basic T/S of the network/route paths.&lt;/P&gt;&lt;P&gt;Next, everything that leaves the MDS is either CP 'Well known ports' for GW Policy/Log Mgmt or 80/443 for CP Web Services which 80/443 should be going directly to the proxy and only the proxy. This was verified by using the curl_cli with --proxy_ip:8080 qualifier tests and hcp -r "Connectivity to UC" tests. Those two sets of tests were both successful and go out the proxy as intended.&lt;/P&gt;&lt;P&gt;I also found this sk -&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk83520" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk83520&lt;/A&gt; - That lists all Sites used by CP for Web Service(s)/Update&lt;/P&gt;&lt;P&gt;Also confirmed that not only this MDS but also multiple other gateways that need access to the Web for CP updates, all use this same CP Proxy FW and none are having any issues.&lt;/P&gt;&lt;P&gt;Just to be clear all CP Web Services and Updates are working as expected, it's just this MDS seems to want to contact CP every night at 2:40 AM and for an unknown reason, bypasses the proxy and the MDS outbound connections are then dropped on the Egress FW because it's the MDS Source IP and not the intended Proxy Source IP. Otherwise the destination traffic is legit. It's not like the MDS has a some sort of malware trying to establish an outbound connection to 'phone home'. It's trying to reach these three destinations for CP Web Services hosted in AWS&lt;/P&gt;&lt;P&gt;3.167.152.116 - AWS&lt;/P&gt;&lt;P&gt;52.85.12.125 - AWS&lt;/P&gt;&lt;P&gt;13.225.143.28 - AWS&lt;/P&gt;&lt;P&gt;This, as when the MDS traffic reaches the Egress FW it 'should' have 'already assumed' the IP address of the Proxy....&lt;/P&gt;</description>
      <pubDate>Fri, 20 Feb 2026 14:41:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-IPS-AV-AB-Contract-updating-directly-while-proxy/m-p/271478#M103505</guid>
      <dc:creator>D_Riddleberger</dc:creator>
      <dc:date>2026-02-20T14:41:35Z</dc:date>
    </item>
  </channel>
</rss>

