<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Categorization in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163544#M70308</link>
    <description>&lt;P&gt;How so? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Nov 2022 12:32:49 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-11-29T12:32:49Z</dc:date>
    <item>
      <title>URL Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163466#M70302</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Two questions:&lt;/P&gt;&lt;P&gt;1. Is URL Categorization based on SNI or "Application Name" (CN name ?) when the gateway is deciding on witch category destination falls in to?&lt;/P&gt;&lt;P&gt;2. Does the categorization not being done when destination has a untrusted certificate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anders Larsson&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 08:50:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163466#M70302</guid>
      <dc:creator>andersplarsson</dc:creator>
      <dc:date>2022-11-29T08:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163531#M70303</link>
      <description>&lt;P&gt;In earlier release (pre-R80.30) only CN was used, now verified SNI is used when available.&lt;BR /&gt;Part of the verification process is checking the cert provided by the remote server matches the SNI requested by the client.&lt;BR /&gt;HTTPS Inspection actually requires the certificate be signed by a valid CA, not sure this is required merely for categorization.&lt;BR /&gt;When this fails for HTTPS Inspection, there are definitely log messages.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 11:23:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163531#M70303</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-29T11:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163540#M70304</link>
      <description>&lt;P&gt;I am pretty sure what phoneboy said is also done by any other major vendors that do https inspection, but thats the gist of it really.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 11:58:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163540#M70304</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-29T11:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163541#M70305</link>
      <description>&lt;P&gt;Thanks for the reply!&lt;/P&gt;&lt;P&gt;If HTTPS Inspection is not being used only URL-categorization, is there any change of how this is categorized for R81.10?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 12:16:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163541#M70305</guid>
      <dc:creator>andersplarsson</dc:creator>
      <dc:date>2022-11-29T12:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163542#M70306</link>
      <description>&lt;P&gt;That is not exactly true, I am afraid. I think you misunderstood what PH conveyed &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 12:26:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163542#M70306</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-29T12:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163543#M70307</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;mentioned, with R80.40 and up, we are using a patented SNI validation. As part of it, we request a site certificate and make sure it is valid and corresponds to the rest of web request data: SNI and URL.&lt;BR /&gt;&lt;BR /&gt;The URL categorization is part of this process, and it is done via HTTPS even if you did not enable HTTPSi on your security GW.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 12:28:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163543#M70307</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-29T12:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163544#M70308</link>
      <description>&lt;P&gt;How so? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 12:32:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163544#M70308</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-29T12:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163545#M70309</link>
      <description>&lt;P&gt;The main differentiator from the rest of the competitors is SNI validation. Instead of taking it for granted, we actually pull the server certificate and compare its details with the SNI data.&lt;/P&gt;
&lt;P&gt;This is, or at least was, unique for Check Point when R80.40 was out, and we filed a patent application for it.&lt;/P&gt;
&lt;P&gt;Hope this makes sense.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 12:39:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163545#M70309</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-29T12:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163547#M70310</link>
      <description>&lt;P&gt;A kk, I see what you mean, makes sense. Though, Im pretty positive that Fortinet and PAN do it nowdays as well.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 12:45:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163547#M70310</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-29T12:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163564#M70311</link>
      <description>&lt;P&gt;So if the certificate is not trusted there is no categorization?&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Anders&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 14:27:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163564#M70311</guid>
      <dc:creator>andersplarsson</dc:creator>
      <dc:date>2022-11-29T14:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: URL Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163567#M70312</link>
      <description>&lt;P&gt;Actually, the change was introduced in R80.30 and backported to R80.20 JHF.&lt;BR /&gt;I believe SNI Verification requires HTTPS Inspection to be enabled in R80.20 and R80.30, but it is not required in R80.40 and above.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 14:35:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Categorization/m-p/163567#M70312</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-29T14:35:38Z</dc:date>
    </item>
  </channel>
</rss>

