<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Content awareness problem in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243351#M47273</link>
    <description>&lt;P&gt;Any chance this traffic has been fact_accel'ed?&amp;nbsp; That will keep Content Awareness from working on it even though it is called for in the policy.&amp;nbsp; Next I would establish what path this problematic traffic is being handled in, please post the filtered output of &lt;STRONG&gt;fwaccel conns&lt;/STRONG&gt; showing just the flags for the live connection in question that should be getting scanned by Content Awareness.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 09 Mar 2025 14:59:19 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2025-03-09T14:59:19Z</dc:date>
    <item>
      <title>Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/242723#M47167</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Wondering if anyone may have some experience with this blade, more specifically, getting files to be blocked when its enabled &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;So, essentially, we got this working few years ago, but customer decided back then not to use the blade and they would like to do it at this point. Issue is literally the same like the post I had back in the day.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Content-awareness-issue/m-p/156026/emcs_t/S2h8ZW1haWx8YW5zd2VyX2FjY2VwdGVkX2FzX3NvbHV0aW9ufEw3R1IzTk1VQks5SjN8MTU2MDI2fEFDQ0VQVEVEX1NPTFVUSU9OU3xoSw#M26668" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Content-awareness-issue/m-p/156026/emcs_t/S2h8ZW1haWx8YW5zd2VyX2FjY2VwdGVkX2FzX3NvbHV0aW9ufEw3R1IzTk1VQks5SjN8MTU2MDI2fEFDQ0VQVEVEX1NPTFVUSU9OU3xoSw#M26668&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;R81.20 jumbo 98&lt;/P&gt;
&lt;P&gt;We did exact same steps esc. engineer gave us and no luck, we dont even see any logs for the blade at all when exe files is downloaded.&lt;/P&gt;
&lt;P&gt;Before doing any debugs from below, wondering if anyone may have any other ideas/suggestions. I will also open TAC case to see what they say.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk119715" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk119715&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks as always and happy weekend &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 19:54:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/242723#M47167</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T19:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/242724#M47168</link>
      <description>&lt;P&gt;To add to this, when I created rule from the screenshot for content awareness exe block, it turns out that actually causes my windows update in the lab PC to fail...as soon as I disabled it, no issues.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 20:21:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/242724#M47168</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T20:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/242730#M47171</link>
      <description>&lt;P&gt;Another test I tried was add rule in content awar. layer to allow access to windows updates sites, so update now works and funny enough, after I pushed policy, exe got blocked once and then never after that, even after I rebooted.&lt;/P&gt;
&lt;P&gt;Anyway, lets see what TAC says in remote Tuesday, March 4th.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 22:50:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/242730#M47171</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T22:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/242987#M47211</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Quick update, will have remote with TAC shortly, lets see if there is any progress and will update once done.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 19:51:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/242987#M47211</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T19:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/242998#M47212</link>
      <description>&lt;P&gt;We had call with TAC, but still unable to fix this in the lab. Guy said would reavh out to senior folks and let us know the next steps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 21:40:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/242998#M47212</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T21:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243113#M47221</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Just a quick update. We had remote with TAC and still no progress. They asked us to change some AV settings in TP profile, but no luck. We also ended up disabling bypass rule in ssl inspection policy and that did not work either.&lt;/P&gt;
&lt;P&gt;Im really confused at this point what else to do. If anyone has any idea, please be free to chime in.&lt;/P&gt;
&lt;P&gt;Tx&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 17:54:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243113#M47221</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-05T17:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243293#M47262</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;
&lt;P&gt;Just something else I wanted to share, if anyone has an idea if maybe rule I have is wrong? I tried with default services, different applications, no joy no matter what I try, it NEVER hits the rule.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 18:58:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243293#M47262</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-07T18:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243297#M47263</link>
      <description>&lt;P&gt;Latest update. After doing the quick debug, I see below messages, which to me makes no logical sense, since blade is 100% enabled.&lt;/P&gt;
&lt;P&gt;Maybe you smart guys&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;can give some suggestions? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*************************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;@;95092703.42; 7Mar2025 15:19:28.163024;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.43; 7Mar2025 15:19:28.163025;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.44; 7Mar2025 15:19:28.163027;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.45; 7Mar2025 15:19:28.163029;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.46; 7Mar2025 15:19:28.163033;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_category_sort_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.47; 7Mar2025 15:19:28.163035;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.48; 7Mar2025 15:19:28.163036;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.49; 7Mar2025 15:19:28.163038;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.50; 7Mar2025 15:19:28.163040;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.51; 7Mar2025 15:19:28.163043;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_category_sort_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.52; 7Mar2025 15:19:28.163046;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.53; 7Mar2025 15:19:28.163049;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.54; 7Mar2025 15:19:28.163052;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;@;95092703.55; 7Mar2025 15:19:28.163055;[kern];[tid_2];[fw4_0];1:{engine} dlpd&lt;BR /&gt;a_stats_get_table_rows_number_callback: Content Awreness not enabled;&lt;BR /&gt;[Expert@CP-FW-01:0]# enabled_blades&lt;BR /&gt;fw vpn urlf appi identityServer SSL_INSPECT content_awareness qos mon&lt;BR /&gt;[Expert@CP-FW-01:0]# cphaprob roles&lt;/P&gt;
&lt;P&gt;ID Role&lt;/P&gt;
&lt;P&gt;1 (local) Master&lt;BR /&gt;2 Non-Master&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]#&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 20:25:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243297#M47263</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-07T20:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243351#M47273</link>
      <description>&lt;P&gt;Any chance this traffic has been fact_accel'ed?&amp;nbsp; That will keep Content Awareness from working on it even though it is called for in the policy.&amp;nbsp; Next I would establish what path this problematic traffic is being handled in, please post the filtered output of &lt;STRONG&gt;fwaccel conns&lt;/STRONG&gt; showing just the flags for the live connection in question that should be getting scanned by Content Awareness.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Mar 2025 14:59:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243351#M47273</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-03-09T14:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243352#M47274</link>
      <description>&lt;P&gt;First thing I did was disable sxl, but had not tried that after installing newest jumbo, will test tomorrow.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 09 Mar 2025 20:56:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243352#M47274</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-09T20:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243366#M47276</link>
      <description>&lt;P&gt;Same problem even when sxl is off. See output from command you gave.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;dst ip is 142.251.40.142&lt;/P&gt;
&lt;P&gt;[Expert@CP-FW-01:0]# fwaccel conns&lt;BR /&gt;Source SPort Destination DPort PR Flags TCP state C2S i/f S2C i/f Inst Policy ID (FW/UP) CPU Host Pkts Host Bytes Last Seen Duration TTL/Timeout&lt;BR /&gt;--------------- ----- --------------- ----- -- --------------------- ---------------- ------- ------- ---- --------------------- --- ----------- ----------- ---------- ---------- -----------&lt;BR /&gt;142.251.163.188 5228 172.16.10.246 10404 6 ..NA..S....L......... Established 1/1 1/1 4 3987324519/1741399108 0 13.99K 1000.10KB 42s 81h33m12s 3558/3600&lt;BR /&gt;9.9.9.9 53 172.16.10.246 18916 17 ..NA..S....L......... No State 1/1 1/1 4 3987324519/1741399108 0 2 214B 4s 4s 36/40&lt;BR /&gt;172.16.10.177 57119 142.251.163.188 5228 6 ..NA..S.............. Established 1/1 1/1 4 3987324519/1741399108 0 13.99K 1000.10KB 42s 81h33m12s 3558/3600&lt;BR /&gt;107.167.110.211 443 172.16.10.177 53509 6 ..NA..S....L......... Established 1/1 1/1 3 3987324519/1741399108 0 56 9.82KB 5s 27m25s 3595/3600&lt;BR /&gt;149.112.121.10 443 172.16.10.246 10412 6 ..NA..S....L......... Established 1/1 1/1 4 3987324519/1741399108 0 18.63K 2.14MB 26s 55h51m14s 3574/3600&lt;BR /&gt;107.167.110.211 443 172.16.10.246 10403 6 ..NA..S....L......... Established 1/1 1/1 3 3987324519/1741399108 0 56 9.82KB 5s 27m25s 3595/3600&lt;BR /&gt;172.16.10.177 61257 9.9.9.9 53 17 ..NA..S.............. No State 1/1 1/1 5 3987324519/1741399108 0 2 255B 4s 4s 36/40&lt;BR /&gt;107.167.110.216 443 172.16.10.246 10400 6 ..NA..S....L......... Established 1/1 1/1 0 3987324519/1741399108 0 81 40.20KB 21s 27m42s 3579/3600&lt;BR /&gt;107.167.96.30 443 172.16.10.246 10400 6 ..NA..S....L......... Established 1/1 1/1 5 3987324519/1741399108 0 30 8.14KB 34s 6m55s 3566/3600&lt;BR /&gt;9.9.9.9 53 172.16.10.246 25933 17 ..NA..S....L......... No State 1/1 1/1 5 3987324519/1741399108 0 2 255B 4s 4s 36/40&lt;BR /&gt;9.9.9.9 53 172.16.10.177 61257 17 ..NA..S....L......... No State 1/1 1/1 5 3987324519/1741399108 0 2 255B 4s 4s 36/40&lt;BR /&gt;142.251.167.188 5228 172.16.10.177 58626 6 ..NA..S....L......... Established 1/1 1/1 4 3987324519/1741399108 0 9.96K 755.14KB 21s 57h27m28s 3579/3600&lt;BR /&gt;172.16.10.177 57101 107.167.96.30 443 6 ..NA..S.............. Established 1/1 1/1 5 3987324519/1741399108 0 30 8.14KB 34s 6m55s 3566/3600&lt;BR /&gt;107.167.110.216 443 172.16.10.177 53456 6 ..NA..S....L......... Established 1/1 1/1 0 3987324519/1741399108 0 81 40.20KB 21s 27m42s 3579/3600&lt;BR /&gt;149.112.121.10 443 172.16.10.177 59207 6 ..NA..S....L......... Established 1/1 1/1 4 3987324519/1741399108 0 18.63K 2.14MB 26s 55h51m14s 3574/3600&lt;BR /&gt;142.251.163.188 5228 172.16.10.177 57119 6 ..NA..S....L......... Established 1/1 1/1 4 3987324519/1741399108 0 13.99K 1000.10KB 42s 81h33m12s 3558/3600&lt;BR /&gt;172.16.10.177 59095 31.209.137.47 61613 6 ..NA..S.............. Established 1/1 1/1 5 3987324519/1741399108 0 5.58K 386.79KB 0s 7h42m26s 3600/3600&lt;BR /&gt;172.16.10.177 58626 142.251.167.188 5228 6 ..NA..S.............. Established 1/1 1/1 4 3987324519/1741399108 0 9.96K 755.14KB 21s 57h27m28s 3579/3600&lt;BR /&gt;107.167.96.30 443 172.16.10.177 57101 6 ..NA..S....L......... Established 1/1 1/1 5 3987324519/1741399108 0 30 8.14KB 34s 6m55s 3566/3600&lt;BR /&gt;31.209.137.47 61613 172.16.10.246 10400 6 ..NA..S....L......... Established 1/1 1/1 5 3987324519/1741399108 0 5.58K 386.79KB 0s 7h42m26s 3600/3600&lt;BR /&gt;31.209.137.47 61613 172.16.10.177 59095 6 ..NA..S....L......... Established 1/1 1/1 5 3987324519/1741399108 0 5.58K 386.79KB 0s 7h42m26s 3600/3600&lt;BR /&gt;172.16.10.177 63193 9.9.9.9 53 17 ..NA..S.............. No State 1/1 1/1 4 3987324519/1741399108 0 2 214B 4s 4s 36/40&lt;BR /&gt;172.16.10.177 53456 107.167.110.216 443 6 ..NA..S.............. Established 1/1 1/1 0 3987324519/1741399108 0 81 40.20KB 21s 27m42s 3579/3600&lt;BR /&gt;172.16.10.177 59207 149.112.121.10 443 6 ..NA..S.............. Established 1/1 1/1 4 3987324519/1741399108 0 18.63K 2.14MB 26s 55h51m14s 3574/3600&lt;BR /&gt;9.9.9.9 53 172.16.10.177 63193 17 ..NA..S....L......... No State 1/1 1/1 4 3987324519/1741399108 0 2 214B 4s 4s 36/40&lt;BR /&gt;172.16.10.177 53509 107.167.110.211 443 6 ..NA..S.............. Established 1/1 1/1 3 3987324519/1741399108 0 56 9.82KB 5s 27m25s 3595/3600&lt;BR /&gt;142.251.167.188 5228 172.16.10.246 10400 6 ..NA..S....L......... Established 1/1 1/1 4 3987324519/1741399108 0 9.96K 755.14KB 21s 57h27m28s 3579/3600&lt;/P&gt;
&lt;P&gt;Idx Interface&lt;BR /&gt;--- ---------&lt;BR /&gt;0 lo&lt;BR /&gt;1 eth0&lt;BR /&gt;2 eth1&lt;BR /&gt;3 eth2&lt;BR /&gt;4 eth3&lt;/P&gt;
&lt;P&gt;Total number of connections: 9&lt;BR /&gt;Total number of links: 18&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 01:39:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243366#M47276</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-10T01:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243368#M47277</link>
      <description>&lt;P&gt;What do you see in the allow logs for the connections you are trying to block? It would help to enabled Extended Logging on the rule the connection is being accepted on so we can see more detail.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You're blocking QUIC traffic while testing this, yes?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 03:15:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243368#M47277</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-03-10T03:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243371#M47279</link>
      <description>&lt;P&gt;The connections involving&amp;nbsp;&lt;SPAN&gt;142.251.40.142 are not shown at all in that output, so those connections are slowpath.&amp;nbsp; Content Awareness should be able to be enforced in that path and not just the Medium Path.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 16:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243371#M47279</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-03-10T16:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243373#M47280</link>
      <description>&lt;P&gt;Also looks like you can't match applications and Content Awareness types simultaneously in the same first ordered layer (or in the top/parent inline layer), see here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk180116" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk180116: Rule with Application Control and Content Awareness is not matched&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 04:34:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243373#M47280</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-03-10T04:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243420#M47288</link>
      <description>&lt;P&gt;We tried layer with only content awareness on, same result.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 11:50:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243420#M47288</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-10T11:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243421#M47289</link>
      <description>&lt;P&gt;Hey Emma,&lt;/P&gt;
&lt;P&gt;Yes, quic is blocked. We do have extended logging enabled, but it gives us exact same log info. When ssl bypass rule is active, shows its bypassed, but when we disable it, content awareness block rule never gets hit. I asked TAC if they can replicate this in their lab, because I feel like customer and I tried literally everything we can think of &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 11:53:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243421#M47289</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-10T11:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243424#M47291</link>
      <description>&lt;P&gt;Two more things:&lt;/P&gt;
&lt;P&gt;1) Verify default settings are configured on the Blade properties for Content Awareness, then try setting "fail-close" and see what happens, perhaps the blade is having some kind of problem and just letting it through, fail-close will block everything subject to Content Awareness if this is the case:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="contentawarenessprops.png" style="width: 942px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29873iAB45675B9D41E21C/image-size/large?v=v2&amp;amp;px=999" role="button" title="contentawarenessprops.png" alt="contentawarenessprops.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2) Try setting an explicit override for the file type you are trying to detect via the dlpda_file_family_mapping_override.C file, maybe that will give it the kick it needs to work properly:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk114954" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk114954: How to configure actions for a specific file type in R80.10 Content Awareness blade&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 12:31:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243424#M47291</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-03-10T12:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243425#M47292</link>
      <description>&lt;P&gt;Yup, tried both last week, same problem.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 12:25:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243425#M47292</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-10T12:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243426#M47293</link>
      <description>&lt;P&gt;Strange, sounds like Content Awareness isn't working at all.&amp;nbsp; Checking that the Unified Policy was generated correctly will be needed, then a kernel debug on the gateway to figure out what is going on.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 12:52:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243426#M47293</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-03-10T12:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: Content awareness problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243432#M47295</link>
      <description>&lt;P&gt;Yep, that sounds right. Funny enough, when I ran debug Friday, it was full of messages that content awareness blade is not enabled. I think at this point, lets wait for TAC to provide next steps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks Tim!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 13:17:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-awareness-problem/m-p/243432#M47295</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-10T13:17:14Z</dc:date>
    </item>
  </channel>
</rss>

