<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: geo policy on website behind haproxy using sni in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257244#M50410</link>
    <description>&lt;P&gt;Hey Dan,&lt;/P&gt;
&lt;P&gt;Can you send screenshot?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Sun, 14 Sep 2025 21:40:53 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-09-14T21:40:53Z</dc:date>
    <item>
      <title>geo policy on website behind haproxy using sni</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257168#M50385</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;We want to set up geo protection for certain websites.&amp;nbsp; However, there many sites behind one IP using SNI behind one IP address on haproxy.&amp;nbsp; &amp;nbsp; Is this possible to protect one or two URLs (name) with a geo policy?&amp;nbsp; &amp;nbsp;I know SNI is supported with https inspection.&amp;nbsp; &amp;nbsp;Or would every project hosted behind that one IP have to be on the policy?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2025 13:02:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257168#M50385</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-09-12T13:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: geo policy on website behind haproxy using sni</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257194#M50389</link>
      <description>&lt;P&gt;I assume this is possible since:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You can use a geography as a source in a rule&lt;/LI&gt;
&lt;LI&gt;You can use a Custom Application/Site as a destination (which can be as above) in a rule&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;SNI doesn't require HTTPS Inspection, FYI.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2025 21:22:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257194#M50389</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-12T21:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: geo policy on website behind haproxy using sni</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257219#M50403</link>
      <description>&lt;P&gt;Just use geo objects as @&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; said.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 14 Sep 2025 01:44:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257219#M50403</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-14T01:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: geo policy on website behind haproxy using sni</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257240#M50409</link>
      <description>&lt;P&gt;rule #12 using a geography as source (blocking Russia for example) and a custom application as destination&amp;nbsp;&lt;/P&gt;
&lt;P&gt;rule #13 allows the IP.&amp;nbsp; &amp;nbsp;Sources from Russia wouldn't make it to rule #13 they would be blocked on #12.&lt;/P&gt;
&lt;P&gt;Sounds good.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Sep 2025 19:02:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257240#M50409</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-09-14T19:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: geo policy on website behind haproxy using sni</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257244#M50410</link>
      <description>&lt;P&gt;Hey Dan,&lt;/P&gt;
&lt;P&gt;Can you send screenshot?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 14 Sep 2025 21:40:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257244#M50410</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-14T21:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: geo policy on website behind haproxy using sni</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257590#M50470</link>
      <description>&lt;P&gt;Thanks, the application/site object works great in the access policy.&amp;nbsp; &amp;nbsp;Now, moving on to the threat prevention exception policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;La Question du jour:&amp;nbsp; Can a custom application/site object exist in the threat prevention Exceptions policy sort of acting as a destination site?&amp;nbsp; &amp;nbsp;I was focused adding a site object to the protected scope column (can't do it), but there is also the protections/site/file/blade column that I've only been using to add protection exceptions.&amp;nbsp; &amp;nbsp; IOW, when making an exception for an IP (and that IP can represent 100 sites)&amp;nbsp; &amp;nbsp;We just need an IPS exception for 1 of the 100 sites.&amp;nbsp; &amp;nbsp;Currently, the protected scope doesn't support application/site objects.&amp;nbsp; &amp;nbsp;However, I can and did simply add the site object to the column with the list of IPS protections the exception is for.&amp;nbsp; &amp;nbsp;IOW, I have 10 IPS protections and a site all in the same column.&amp;nbsp; &amp;nbsp;I mean the column does say it's for Protections/site/file/blade.&amp;nbsp; &amp;nbsp;It just seems very unusual to have that mix of protections and a specific destination (site object/URLs) in the same column.&amp;nbsp; Thinking... that might just work.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 11:14:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257590#M50470</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-09-18T11:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: geo policy on website behind haproxy using sni</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257595#M50471</link>
      <description>&lt;P&gt;Yea, probably best idea Dan.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 11:00:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257595#M50471</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-18T11:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: geo policy on website behind haproxy using sni</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257676#M50483</link>
      <description>&lt;P&gt;Let us know one way or the other.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 23:06:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/geo-policy-on-website-behind-haproxy-using-sni/m-p/257676#M50483</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-18T23:06:04Z</dc:date>
    </item>
  </channel>
</rss>

