<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow File Download from certain URLs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57191#M57603</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please share an example.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2019 05:38:56 GMT</pubDate>
    <dc:creator>Omer_Shliva</dc:creator>
    <dc:date>2019-07-02T05:38:56Z</dc:date>
    <item>
      <title>Allow File Download from certain URLs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57114#M57602</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;we have R80.20 and normally we don't allow to download filetypes like "exe", "zip" etc.. Therefore we created a Threat Prevention policy with the action "prevent (defined in a profile)". Now we want do define some URls (as exceptions) where a file download is accpeted and allowed.&lt;/P&gt;&lt;P&gt;Does anybody know, how I can do this?&lt;/P&gt;&lt;P&gt;Thanks for any infos.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 11:48:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57114#M57602</guid>
      <dc:creator>hw</dc:creator>
      <dc:date>2019-07-01T11:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Allow File Download from certain URLs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57191#M57603</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please share an example.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 05:38:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57191#M57603</guid>
      <dc:creator>Omer_Shliva</dc:creator>
      <dc:date>2019-07-02T05:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: Allow File Download from certain URLs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57213#M57604</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;for example I want to download the file "KeePass" (and later also files from other URLs) from the URL&amp;nbsp;&lt;A href="https://www.heise.de/download/product/keepass-15712" target="_blank"&gt;https://www.heise.de/download/product/keepass-15712&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Therefore I need an exception for the domain "*.heise.de", because normaly we deny to download filetypes as exe, zip....&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already tried to define an exception rule under the threat prevention rule (which blocks to download certain filetypes), however this doesn't work.&lt;/P&gt;&lt;P&gt;How can I implement this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 07:36:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57213#M57604</guid>
      <dc:creator>hw</dc:creator>
      <dc:date>2019-07-02T07:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Allow File Download from certain URLs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57384#M57605</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create a custom application in order to allow those certain URLs. Please refer to &amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103051&amp;amp;partition=General&amp;amp;product=Application" target="_blank"&gt;sk103051&lt;/A&gt; for download and guide.&lt;/P&gt;
&lt;P&gt;Then, you can create an application for “.heise.de/download” with HTTP scenario:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 682px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1802iA653D23CCF279172/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;After that, import the application into Smart Console and use it in a rule in the access policy on “allow”:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.jpg" style="width: 955px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1803iFB60540FA57B7292/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.jpg" alt="2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 18:41:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57384#M57605</guid>
      <dc:creator>Omer_Shliva</dc:creator>
      <dc:date>2019-07-03T18:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Allow File Download from certain URLs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57394#M57606</link>
      <description>That only helps from an Access Control perspective.&lt;BR /&gt;Since he's blacklisting exes in general in Threat Prevention, he probably needs to create specific indicators that are set to "Detect" or "Inactive".&lt;BR /&gt;This means creating an indicator file that contains the necessary domains you want to allow and importing it.&lt;BR /&gt;See: &lt;A href="https://sc1.checkpoint.com/documents/R80.20/SmartConsole_OLH/EN/-_ktjOvSNsVDDJA210OA3g2.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.20/SmartConsole_OLH/EN/-_ktjOvSNsVDDJA210OA3g2.htm&lt;/A&gt;</description>
      <pubDate>Wed, 03 Jul 2019 20:37:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57394#M57606</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-03T20:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Allow File Download from certain URLs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57418#M57607</link>
      <description>&lt;P&gt;Thanks for your answers. I will try it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I described I also tried an exception under the Threat prevention. It seems that it works only with a Regex expression for the domain heise.de and not with a wildcard definition.&lt;/P&gt;&lt;P&gt;So the Regex:&lt;STRONG&gt;&amp;nbsp;.*\.heise\.de.*&amp;nbsp;&lt;/STRONG&gt;allows the download from the domain heise.de however the wildcard &lt;STRONG&gt;*.heise.de&lt;/STRONG&gt; or &lt;STRONG&gt;*.heise.de*&lt;/STRONG&gt; doesn't work. Is the syntax for the wildcard false? I don't understand why it doesn't work with a wildcard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 06:18:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57418#M57607</guid>
      <dc:creator>hw</dc:creator>
      <dc:date>2019-07-04T06:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Allow File Download from certain URLs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57437#M57608</link>
      <description>&lt;P&gt;Thank you for the infos. I will try it.&lt;/P&gt;&lt;P&gt;As I described in my last post, I tried to accept the download with an exception rule under the threat prevention rule (rule which blocks all exe downloads). Now it seems, that the rule works, but only if I write the URL as a Regex expression and not as a wildcard.&lt;/P&gt;&lt;P&gt;So the regex works:&amp;nbsp;&lt;STRONG&gt;.*\.heise\.de.*&amp;nbsp;&lt;/STRONG&gt;but not the wildcard &lt;STRONG&gt;*.heise.de&lt;/STRONG&gt; or &lt;STRONG&gt;*.heise.de*&lt;/STRONG&gt;. Is the syntax of the wildcard false? Is this also a correct way if i define a Threat prevention exception?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 09:50:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Allow-File-Download-from-certain-URLs/m-p/57437#M57608</guid>
      <dc:creator>hw</dc:creator>
      <dc:date>2019-07-04T09:50:28Z</dc:date>
    </item>
  </channel>
</rss>

