<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Auditing File Uploads (with view to block using Application Rule) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-File-Uploads-with-view-to-block-using-Application-Rule/m-p/253778#M49700</link>
    <description>&lt;P&gt;Gateway version - R81.20 T99; SMS management - R82, including Log Server and Smart Event.&lt;/P&gt;&lt;P&gt;We have an audit finding that would like us to "research ways to enhance controls preventing data uploads to unauthorized websites." There's a great Tag called "File Uploads" that we can use in a Block rule, but I want to be able to audit which sites are currently being used in our organization that would fit into the File Uploads category. I want to research which business approved sites would be blocked using this category, so we can create specific accepts above the block rule. We currently block most File Storage and Sharing sites across the organization.&lt;/P&gt;&lt;P&gt;I've tried searching the logs for category:"File Upload", tags:"File Upload" and cannot find any logs in our log server that match those categories. I thought I could add an Accept Rule for that tag/category in the App Control rulebase, but that may allow users to upload to file storage sites we do not want them to access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jul 2025 12:43:53 GMT</pubDate>
    <dc:creator>Eric_Knopp</dc:creator>
    <dc:date>2025-07-23T12:43:53Z</dc:date>
    <item>
      <title>Auditing File Uploads (with view to block using Application Rule)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-File-Uploads-with-view-to-block-using-Application-Rule/m-p/253778#M49700</link>
      <description>&lt;P&gt;Gateway version - R81.20 T99; SMS management - R82, including Log Server and Smart Event.&lt;/P&gt;&lt;P&gt;We have an audit finding that would like us to "research ways to enhance controls preventing data uploads to unauthorized websites." There's a great Tag called "File Uploads" that we can use in a Block rule, but I want to be able to audit which sites are currently being used in our organization that would fit into the File Uploads category. I want to research which business approved sites would be blocked using this category, so we can create specific accepts above the block rule. We currently block most File Storage and Sharing sites across the organization.&lt;/P&gt;&lt;P&gt;I've tried searching the logs for category:"File Upload", tags:"File Upload" and cannot find any logs in our log server that match those categories. I thought I could add an Accept Rule for that tag/category in the App Control rulebase, but that may allow users to upload to file storage sites we do not want them to access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 12:43:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-File-Uploads-with-view-to-block-using-Application-Rule/m-p/253778#M49700</guid>
      <dc:creator>Eric_Knopp</dc:creator>
      <dc:date>2025-07-23T12:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing File Uploads (with view to block using Application Rule)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-File-Uploads-with-view-to-block-using-Application-Rule/m-p/253784#M49701</link>
      <description>&lt;P&gt;Very interesting question. Let me play around with this in my lab and see how far I get.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 13:18:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-File-Uploads-with-view-to-block-using-Application-Rule/m-p/253784#M49701</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-23T13:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing File Uploads (with view to block using Application Rule)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-File-Uploads-with-view-to-block-using-Application-Rule/m-p/253794#M49731</link>
      <description>&lt;P&gt;You can see what apps we include as part of File Upload on &lt;A href="https://appwiki.checkpoint.com/appwikisdb/public.htm" target="_self"&gt;AppWiki&lt;/A&gt;&amp;nbsp;by simply searching for the tag "File Upload" of which there appear to be 250.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 14:23:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Auditing-File-Uploads-with-view-to-block-using-Application-Rule/m-p/253794#M49731</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-23T14:23:11Z</dc:date>
    </item>
  </channel>
</rss>

