<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: antibot usercheck redirect in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/antibot-usercheck-redirect/m-p/6399#M59331</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know,&amp;nbsp;the only information you can pass is the Incident ID, and only if that option is specified in the UserCheck interaction.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Incident ID can be looked up in the logs as described here (but not with an API call at the moment):&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101236" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101236"&gt;Searching for Incident ID when using UserCheck&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may want to customize the UserCheck portal a bit more instead of writing your own, refer to&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk83700" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk83700"&gt;How to customize and localize the UserCheck portal&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Sep 2017 09:06:28 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2017-09-22T09:06:28Z</dc:date>
    <item>
      <title>antibot usercheck redirect</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/antibot-usercheck-redirect/m-p/6398#M59330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been doing some testing with the usercheck feature with antibot.&amp;nbsp; I have antibot enabled and setup with just a few test IPs for the scope and that is working well.&amp;nbsp; We would like to present the users with a block page if a device attempts to go to a known bot controlled site.&amp;nbsp; I tested some with using the usercheck on the firewall and also using the redirect feature.&amp;nbsp; We would prefer to use the redirect feature if possible.&amp;nbsp; My web programming team is assisting with getting the site setup for the redirect and we would like to include the URL and Activity on the page that is presented.&amp;nbsp; These options are available when using the usercheck on the firewall.&amp;nbsp; The web programming team has asked if we could find out what the http parameters are for the URL and Activity.&amp;nbsp; When testing with the usercheck on the firewall these do not appear to be included in the url.&amp;nbsp; Is it possible to pass these parameters when redirecting?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Sep 2017 18:29:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/antibot-usercheck-redirect/m-p/6398#M59330</guid>
      <dc:creator>Ed_Eades</dc:creator>
      <dc:date>2017-09-19T18:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: antibot usercheck redirect</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/antibot-usercheck-redirect/m-p/6399#M59331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know,&amp;nbsp;the only information you can pass is the Incident ID, and only if that option is specified in the UserCheck interaction.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Incident ID can be looked up in the logs as described here (but not with an API call at the moment):&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101236" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101236"&gt;Searching for Incident ID when using UserCheck&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may want to customize the UserCheck portal a bit more instead of writing your own, refer to&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk83700" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk83700"&gt;How to customize and localize the UserCheck portal&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2017 09:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/antibot-usercheck-redirect/m-p/6399#M59331</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-22T09:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: antibot usercheck redirect</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/antibot-usercheck-redirect/m-p/6400#M59332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response and I had looked at the customize SK.&amp;nbsp; We may not end up having to customize a usercheck page.&amp;nbsp; We currently have a Cisco Web Security Appliance (WSA) in place for url filtering and it provides anti-malware protection as well.&amp;nbsp; Would there be any differences with the CheckPoint Antibot and Antivirus blades compared to the Cisco WSA Anti-Malware protection?&amp;nbsp; Would the CheckPoint blades offer any extra protection in addition to what the Cisco Web Security Appliance is offering?&amp;nbsp; If the CheckPoint antibot and antivirus blades offer extra protections it may be worth having both active.&amp;nbsp; I have done some testing and when I have Antibot set to not display usercheck our Cisco Web Security Appliance user page will display and it is logged in the CheckPoint as well.&amp;nbsp; I am trying to determine if it is worthwhile to have the CheckPoint antibot and antivirus blades active as well.&amp;nbsp; The Cisco WSA will only protect against 80 and 443 traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Sep 2017 01:49:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/antibot-usercheck-redirect/m-p/6400#M59332</guid>
      <dc:creator>Ed_Eades</dc:creator>
      <dc:date>2017-09-23T01:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: antibot usercheck redirect</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/antibot-usercheck-redirect/m-p/6401#M59333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One benefit to using the Check Point solution in general is that we are not limited to port 80/443.&lt;/P&gt;&lt;P&gt;Anti-Bot will pick up outgoing command and control traffic and will work on any port.&lt;/P&gt;&lt;P&gt;We can also do other inspections with IPS, Threat Emulation (for zero-day malware) and the like.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Sep 2017 06:13:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/antibot-usercheck-redirect/m-p/6401#M59333</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-23T06:13:09Z</dc:date>
    </item>
  </channel>
</rss>

