<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS inspection not block URL in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/HTTPS-inspection-not-block-URL/m-p/121014#M56074</link>
    <description>&lt;P&gt;Thank you for reply. Here is my setting picture (I use R80.10, HOTFIX_R80_10_JUMBO_HF Take: 203):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appctl.png" style="width: 985px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12135iB0DA7A572DC42B83/image-size/large?v=v2&amp;amp;px=999" role="button" title="appctl.png" alt="appctl.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is HTTPS validation setting:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="https inspect.png" style="width: 884px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12136iE1EFEC92C4B88C06/image-size/large?v=v2&amp;amp;px=999" role="button" title="https inspect.png" alt="https inspect.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On picture about HTTPS inspection setting, Do you mean that I need to check "Untrusted server certificate" box?&lt;/P&gt;</description>
    <pubDate>Sat, 12 Jun 2021 07:41:07 GMT</pubDate>
    <dc:creator>minhhaivietnam</dc:creator>
    <dc:date>2021-06-12T07:41:07Z</dc:date>
    <item>
      <title>HTTPS inspection not block URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/HTTPS-inspection-not-block-URL/m-p/121007#M56072</link>
      <description>&lt;P&gt;Hello experts,&lt;/P&gt;&lt;P&gt;I have firewall CP running HTTPS inspection to control internet access of users.&lt;/P&gt;&lt;P&gt;I have 2 layer: NETWORK and APP&amp;amp;URL.&lt;/P&gt;&lt;P&gt;In layer Network, I allow any any.&lt;/P&gt;&lt;P&gt;In layer APP&amp;amp;URL, I manually allow URL1, URL2,...and cleanup rule is block all others.&lt;/P&gt;&lt;P&gt;My problem is:&lt;/P&gt;&lt;P&gt;Some PCs sometime call to this URL "&lt;STRONG&gt;events.data.microsoft.com&lt;/STRONG&gt;", and I do not allow this url. But log on firewall still show that it &lt;STRONG&gt;allow&lt;/STRONG&gt; this URL . I don't know why. Here is some pictures. Please help to explain! Tks you&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="inspection.png" style="width: 857px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12133iD295721D5819C412/image-size/large?v=v2&amp;amp;px=999" role="button" title="inspection.png" alt="inspection.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log url.png" style="width: 744px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12134iAAA32D01FFCAB442/image-size/large?v=v2&amp;amp;px=999" role="button" title="log url.png" alt="log url.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jun 2021 03:34:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/HTTPS-inspection-not-block-URL/m-p/121007#M56072</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2021-06-12T03:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection not block URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/HTTPS-inspection-not-block-URL/m-p/121008#M56073</link>
      <description>&lt;P&gt;What version/JHF level?&lt;BR /&gt;It would also be useful see what precise rule is allowing this connection, which will be shown in the log card.&lt;BR /&gt;Might need a screenshot of the rule and relevant services.&lt;BR /&gt;I’m also surprised this is not being blocked because of the untrusted CA key; did you disable that check?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jun 2021 06:24:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/HTTPS-inspection-not-block-URL/m-p/121008#M56073</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-12T06:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection not block URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/HTTPS-inspection-not-block-URL/m-p/121014#M56074</link>
      <description>&lt;P&gt;Thank you for reply. Here is my setting picture (I use R80.10, HOTFIX_R80_10_JUMBO_HF Take: 203):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="appctl.png" style="width: 985px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12135iB0DA7A572DC42B83/image-size/large?v=v2&amp;amp;px=999" role="button" title="appctl.png" alt="appctl.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is HTTPS validation setting:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="https inspect.png" style="width: 884px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12136iE1EFEC92C4B88C06/image-size/large?v=v2&amp;amp;px=999" role="button" title="https inspect.png" alt="https inspect.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On picture about HTTPS inspection setting, Do you mean that I need to check "Untrusted server certificate" box?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jun 2021 07:41:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/HTTPS-inspection-not-block-URL/m-p/121014#M56074</guid>
      <dc:creator>minhhaivietnam</dc:creator>
      <dc:date>2021-06-12T07:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS inspection not block URL</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/HTTPS-inspection-not-block-URL/m-p/121029#M56075</link>
      <description>&lt;P&gt;I suspect the issue is related to SNI detection, which is not supported in R80.10.&lt;BR /&gt;That means your app control rule will match based on CN instead, which may be being allowed by your existing rules.&lt;BR /&gt;I highly recommend upgrading to a later release&amp;nbsp;as shown here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk173633" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk173633&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Yes, that’s the setting I’m referring to.&lt;BR /&gt;If you check that (and push policy), the gateway will not allow connections to sites for which it cannot validate the certificate chain for (similar to what a browser does).&lt;BR /&gt;However, that could also block your legitimate traffic as well.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jun 2021 15:59:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/HTTPS-inspection-not-block-URL/m-p/121029#M56075</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-12T15:59:35Z</dc:date>
    </item>
  </channel>
</rss>

