<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall as Proxy and Error Pages in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11112#M58652</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the firewall an explicit proxy in this case?&lt;/P&gt;&lt;P&gt;Because if so, we may not be able to redirect the traffic to a UserCheck page.&lt;/P&gt;&lt;P&gt;See:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110013" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110013"&gt;How to configure Check Point Security Gateway as HTTP/HTTPS Proxy&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise, a diagram of how the proxies are configured (related to users and Internet) would be helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Jul 2018 19:16:35 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-07-20T19:16:35Z</dc:date>
    <item>
      <title>Firewall as Proxy and Error Pages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11111#M58651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We&amp;nbsp;have a R80.10 cluster which has Firewall, IPS, Anti-Virus and Anti-Bot Blades in place and it is being used as a parent proxy. When the IPS/AV detect a virus signature (in this case the test Eicar virus) it drops the connection to the child proxy, however if the Anti-bot detects an issue which is classed as reputation it is redirected to the UserCheck error pages. How do we set up the firewall to redirect all the "proxying" requests to UserCheck when there is a Threat Prevention issue ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2018 10:39:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11111#M58651</guid>
      <dc:creator>Neil_Plastow</dc:creator>
      <dc:date>2018-07-20T10:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall as Proxy and Error Pages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11112#M58652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the firewall an explicit proxy in this case?&lt;/P&gt;&lt;P&gt;Because if so, we may not be able to redirect the traffic to a UserCheck page.&lt;/P&gt;&lt;P&gt;See:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110013" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110013"&gt;How to configure Check Point Security Gateway as HTTP/HTTPS Proxy&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise, a diagram of how the proxies are configured (related to users and Internet) would be helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2018 19:16:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11112#M58652</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-20T19:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall as Proxy and Error Pages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11113#M58653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it is being used as&amp;nbsp;an explicit proxy.&lt;/P&gt;&lt;P&gt;The browsers are setup to use a proxy on the internal network which is configured to use the firewall as a parent proxy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2018 09:29:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11113#M58653</guid>
      <dc:creator>Neil_Plastow</dc:creator>
      <dc:date>2018-07-23T09:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall as Proxy and Error Pages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11114#M58654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;How are the clients configured to use your other proxy? By IP/host or through a proxy.pac somewhere?&lt;/SPAN&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2018 14:27:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11114#M58654</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-23T14:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall as Proxy and Error Pages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11115#M58655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not 100% as we don't manage the internal proxy but believe it is using a proxy.pac file.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:08:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11115#M58655</guid>
      <dc:creator>Neil_Plastow</dc:creator>
      <dc:date>2018-07-23T15:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall as Proxy and Error Pages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11116#M58656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I suspect is happening is that AV/IPS cannot see there's something to block until well after the connection is established (almost over in the case of AV).&lt;/P&gt;&lt;P&gt;As we are past the point of being able to inject any sort of redirect at that point,&amp;nbsp;it's not possible for us to inject a&amp;nbsp;UserCheck page.&lt;/P&gt;&lt;P&gt;As a result, we just drop the connection, which I assume the client proxy then picks up as an issue and displays its own page.&lt;/P&gt;&lt;P&gt;With an Anti-bot reputation, we can check that before a real connection is established and thus display a UserCheck page to the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The comment I was going to make about proxy.pac file is to make sure that connections redirected to the gateway itself are not sent through a proxy, which may already be happening.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:28:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11116#M58656</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-23T15:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall as Proxy and Error Pages</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11117#M58657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for looking at this and answering the question, appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2018 15:45:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-as-Proxy-and-Error-Pages/m-p/11117#M58657</guid>
      <dc:creator>Neil_Plastow</dc:creator>
      <dc:date>2018-07-23T15:45:44Z</dc:date>
    </item>
  </channel>
</rss>

