<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS - Block HTTP Non Compliant in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Block-HTTP-Non-Compliant/m-p/218498#M54158</link>
    <description>&lt;P&gt;Hi Mates,&lt;/P&gt;
&lt;P&gt;how can I check why this Debian APT download is blocked via IPS?&lt;/P&gt;
&lt;P&gt;I only have this with two clients. Others have no issue.&lt;/P&gt;
&lt;DIV id="tinyMceEditorD_W_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26403i42D32F8E4E6E45C8/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;BR /&gt;David&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2024 14:56:34 GMT</pubDate>
    <dc:creator>D_W</dc:creator>
    <dc:date>2024-06-24T14:56:34Z</dc:date>
    <item>
      <title>IPS - Block HTTP Non Compliant</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Block-HTTP-Non-Compliant/m-p/218498#M54158</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;
&lt;P&gt;how can I check why this Debian APT download is blocked via IPS?&lt;/P&gt;
&lt;P&gt;I only have this with two clients. Others have no issue.&lt;/P&gt;
&lt;DIV id="tinyMceEditorD_W_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26403i42D32F8E4E6E45C8/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;BR /&gt;David&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 14:56:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Block-HTTP-Non-Compliant/m-p/218498#M54158</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2024-06-24T14:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - Block HTTP Non Compliant</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Block-HTTP-Non-Compliant/m-p/218521#M54159</link>
      <description>&lt;P&gt;Probably it's best to investigate with TAC&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 16:42:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Block-HTTP-Non-Compliant/m-p/218521#M54159</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-06-24T16:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - Block HTTP Non Compliant</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Block-HTTP-Non-Compliant/m-p/218523#M54160</link>
      <description>&lt;P&gt;Hey David,&lt;/P&gt;
&lt;P&gt;Couple of questions:&lt;/P&gt;
&lt;P&gt;1) What IPS profile is used in TP policy?&lt;/P&gt;
&lt;P&gt;2) Considering this is critical, I assume thats why its blocked...have you tried adding an IPS exception if you know its 100% legit?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 16:49:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Block-HTTP-Non-Compliant/m-p/218523#M54160</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-24T16:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - Block HTTP Non Compliant</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Block-HTTP-Non-Compliant/m-p/218596#M54161</link>
      <description>&lt;P&gt;1) Custom Policy&lt;/P&gt;
&lt;P&gt;2) when I let them proxy the traffic via our squid proxy then the IPS is allowing this traffic. Also other Linux Servers downloading these packages have no issue. Only two specific Linux Systems that run this apt-get command via Docker Container have this issue.&lt;BR /&gt;&lt;BR /&gt;I will&amp;nbsp; go ahead with the TAC &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 09:53:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Block-HTTP-Non-Compliant/m-p/218596#M54161</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2024-06-25T09:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - Block HTTP Non Compliant</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Block-HTTP-Non-Compliant/m-p/218710#M54162</link>
      <description>&lt;P&gt;Indeed this will be a TAC case. Reason I think why it works via proxy is because then the proxy will set up the connection and will download the packages.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best is to make a packet capture on the gateway and if possible on client. The packet capture in the logs is sometimes not enough for TAC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try without but i think it makes life more easy for the TAC engineer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are lucky it is HTTP, if it is HTTPS we needed to share a decrypted packet capture for TAC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 21:25:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPS-Block-HTTP-Non-Compliant/m-p/218710#M54162</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-06-25T21:25:07Z</dc:date>
    </item>
  </channel>
</rss>

