<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exceptional Blockages in TP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254191#M49814</link>
    <description>&lt;P&gt;Custom Application/Site Objects require either App Control &lt;STRONG&gt;or&lt;/STRONG&gt; URL Filtering to be usable in the Access Policy.&lt;BR /&gt;They can also be used in Threat Emulation without activating either of these blades.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jul 2025 12:44:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-07-29T12:44:49Z</dc:date>
    <item>
      <title>Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253978#M49766</link>
      <description>&lt;P&gt;Hi, Mates&lt;/P&gt;
&lt;P&gt;I have an MDS environment in combination with VSX.&lt;/P&gt;
&lt;P&gt;In some of my VSX Clusters, I have some VS that have AV/AB/IPS enabled.&lt;/P&gt;
&lt;P&gt;I have the need to create a point block on some of the VS, for example for the Malware “Malware.TC.8502EJGJ”. The problem is that it does not allow me to do it when I am standing in the “Security Policies -&amp;gt; My Policy Package -&amp;gt; Threat Prevention -&amp;gt; Exceptions” section.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TP1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31053i837D6B246A68BAE6/image-size/large?v=v2&amp;amp;px=999" role="button" title="TP1.jpg" alt="TP1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This configuration can only be done by the Global Domain of the MDS?&lt;/P&gt;
&lt;P&gt;Can't it be done uniquely in the CMA I need?&lt;/P&gt;
&lt;P&gt;I have traffic that is only being “Detected” when the TP profile I have, indicates that it should be “Prevented” but still, the traffic is going through, and I need to block it somehow.&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 20:13:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253978#M49766</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-07-25T20:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253983#M49767</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Is that option not present when you are logged into CMA's smart console?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 23:09:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253983#M49767</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-25T23:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253985#M49768</link>
      <description>&lt;P&gt;You should be able to create a specific rule in the Threat Prevention policy on the CMA that will basically do the same thing.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 23:46:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253985#M49768</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-25T23:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253986#M49769</link>
      <description>&lt;P&gt;Hey.&lt;BR /&gt;&lt;BR /&gt;The option appears when you connect to the CMA, but you cannot configure anything.&lt;/P&gt;
&lt;P&gt;The only way, is that you enter the MDS Global Domain, and from there it allows you to create what you need, but then, it only works in MDS environments with VSX?&lt;/P&gt;
&lt;P&gt;Can't you just configure this, being “stopped” in the CMA you need?&lt;/P&gt;
&lt;P&gt;Not all my CMAs need to have “Global Exceptions” configuration.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 23:46:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253986#M49769</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-07-25T23:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253987#M49770</link>
      <description>&lt;P&gt;I see, thats the screenshot you posted. Hm...what if you add new exceptions "package" on the top and not use global one? See if that lets you add a new rule.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jul 2025 00:42:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253987#M49770</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-26T00:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253988#M49771</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Can I create a rule in Threat Prevention Policy, for a specific malware? For example for "Malware.TC.8502EJGJ" for a single segment of my internal network?&lt;BR /&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jul 2025 00:01:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/253988#M49771</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-07-26T00:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254080#M49787</link>
      <description>&lt;P&gt;Generally, yes, though not sure on the generic ThreatCloud protections (which this is).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 11:40:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254080#M49787</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-28T11:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254099#M49796</link>
      <description>&lt;P&gt;What is the best alternative in scenarios where you need to block multiple domains discovered that have a bad reputation (malicious)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it to use the URLF Blade for these cases? Maybe create a ‘Custom/Applications Site’?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our AV/AB profile is ‘ignoring’ the blocking of domains that it should be blocking according to our profile (Traffic is being tagged as ‘Detect’)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We want a safe way to generate the blocking of these domains&lt;/P&gt;
&lt;P&gt;This can be done only as URLF? Because I don't see the option in AV/AB to block based on Malware type.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 14:06:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254099#M49796</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-07-28T14:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254103#M49797</link>
      <description>&lt;P&gt;From your screenshot it looks like you are trying to configure the wrong 'Global Exceptions' policy.&lt;/P&gt;&lt;P&gt;The one with a 'G' in the icon are read-only and handled from the Global Policy.&lt;/P&gt;&lt;P&gt;Try to click on 'Global Exceptions' (without G in icon) and then try to 'Add exceptions'&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 14:36:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254103#M49797</guid>
      <dc:creator>ClausOCD</dc:creator>
      <dc:date>2025-07-28T14:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254113#M49800</link>
      <description>&lt;P&gt;From the screenshot, it looks like you are trying to configure the 'Global Exceptions' handled by the Global Policy (G in icon). Thats only possible from the Global Policy.&lt;/P&gt;&lt;P&gt;Try to click on 'Global Exceptions' (without G in icon) and then 'Add Exception'&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 15:28:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254113#M49800</guid>
      <dc:creator>ClausOCD</dc:creator>
      <dc:date>2025-07-28T15:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254136#M49804</link>
      <description>&lt;P&gt;You can create a Custom Application/Site object with the relevant domains.&lt;BR /&gt;This object can be used in the Threat Prevention policy in addition to the Access Policy.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 19:11:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254136#M49804</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-28T19:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254142#M49808</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;The ‘Custom/Applications Site’ can be used without activating the URLF blade?&lt;/P&gt;
&lt;P&gt;If I put it in an explicit rule in the TP layer, the GW is able to do the filtering if I only have active blades like AV/AB?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 22:53:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254142#M49808</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-07-28T22:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254191#M49814</link>
      <description>&lt;P&gt;Custom Application/Site Objects require either App Control &lt;STRONG&gt;or&lt;/STRONG&gt; URL Filtering to be usable in the Access Policy.&lt;BR /&gt;They can also be used in Threat Emulation without activating either of these blades.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 12:44:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254191#M49814</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-29T12:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: Exceptional Blockages in TP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254200#M49815</link>
      <description>&lt;P&gt;That sounds very logical, for sure.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 13:17:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Exceptional-Blockages-in-TP/m-p/254200#M49815</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-29T13:17:44Z</dc:date>
    </item>
  </channel>
</rss>

