<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Content Awareness, things that do not work in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-things-that-do-not-work/m-p/139460#M73227</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11764"&gt;@Marcel_Gramalla&lt;/a&gt; I am referring specifically to the browser-based behavior. In all the years I've worked with Check Point, not once have I seen the UserCheck Client being deployed in the organizations strictly for Content Awareness. Check Point DLP is also not that widely implemented. I have considered including UserCheck Client stipulation in the statement, but have decided against it. From administrators point of view, when working on rules, it is not listed as prerequisite, creating false sense of the expected behavior vs. best-effort possibility.&lt;/P&gt;
&lt;P&gt;Considering that there may be clients other than Windows, we are talking about Captive Portal and AD membership in order to ensure user interaction.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jan 2022 20:19:33 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2022-01-25T20:19:33Z</dc:date>
    <item>
      <title>Content Awareness, things that do not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-things-that-do-not-work/m-p/139442#M73225</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;With either Content Awareness or CA + Applications &amp;amp; URLF enabled, rule 9.1 below is ignored by non-HTTP/HTTPS/Proxies/SMTP/FTP traffic, such as CIFS. User is not aware of this rules’ non-compliance:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Figure_1_rule_non-compliance_awareness.png" style="width: 720px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15081i9790EFE7908AE91D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Figure_1_rule_non-compliance_awareness.png" alt="Figure_1_rule_non-compliance_awareness.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;With Content Awareness and Applications &amp;amp; URLF enabled, in rule 10.3, ‘Ask’ UserCheck is not triggered, but the transfer of the file is blocked and the log reports ‘Redirect’:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Figure_2_UserCheck_not_triggered.png" style="width: 720px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15082iEA0E10B38ACCEF87/image-size/large?v=v2&amp;amp;px=999" role="button" title="Figure_2_UserCheck_not_triggered.png" alt="Figure_2_UserCheck_not_triggered.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Figure_3_Upload_stopped.png" style="width: 342px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15083i48B37AB5F5183247/image-size/large?v=v2&amp;amp;px=999" role="button" title="Figure_3_Upload_stopped.png" alt="Figure_3_Upload_stopped.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Figure_4_Redirect_log.png" style="width: 621px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15084iB75733E80E7C08D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Figure_4_Redirect_log.png" alt="Figure_4_Redirect_log.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;I have no trouble pasting the list of SSNs into the Google Docs file completely ignoring 10.4 below:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Figure_5_Content_Awareness_Rules.png" style="width: 720px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15085iA40F7E240FDE2FC4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Figure_5_Content_Awareness_Rules.png" alt="Figure_5_Content_Awareness_Rules.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Figure_6_SSN_pattern_and_coccurances_number.png" style="width: 365px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15086i6FA1794BF3769518/image-size/large?v=v2&amp;amp;px=999" role="button" title="Figure_6_SSN_pattern_and_coccurances_number.png" alt="Figure_6_SSN_pattern_and_coccurances_number.png" /&gt;&lt;/span&gt;
&lt;P&gt;The content is from dlptest.com that is routinely used to test the DLP systems was used to test Content Awareness.&lt;/P&gt;
&lt;P&gt;The attempt to upload sample-data.csv was prevented and the Data Type correctly identified: &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Figure_7_SSN_in_CSV_upload_Stopped.png" style="width: 363px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15087i75474440E42DD1D5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Figure_7_SSN_in_CSV_upload_Stopped.png" alt="Figure_7_SSN_in_CSV_upload_Stopped.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Figure_8_SSN_in_CSV_Upload_Log.png" style="width: 720px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15088i0690FEF5F9826985/image-size/large?v=v2&amp;amp;px=999" role="button" title="Figure_8_SSN_in_CSV_Upload_Log.png" alt="Figure_8_SSN_in_CSV_Upload_Log.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;…but copy/paste of same file’s content in Google Docs was not.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Figure_9_data_from_same_CSV_paste_allowed.png" style="width: 720px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15089i6238A27C52C6DFB0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Figure_9_data_from_same_CSV_paste_allowed.png" alt="Figure_9_data_from_same_CSV_paste_allowed.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;My conclusions, at the moment, are:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Do not use Content Awareness in rules or layers without either explicit services (HTTP/HTTPS, proxies, SMTP, FTP) or applications in the parent rule&lt;/LI&gt;
&lt;LI&gt;Do not use UserCheck with Content Awareness due to unreliability, (although User Guides are explicitly showing UserCheck in Content Awareness rules)&lt;/LI&gt;
&lt;LI&gt;When Content Awareness is used, either limit it to file types, or use with the caveat that it is easily circumvented&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If someone can point out any errors in my observations or conclusions, I’d be grateful.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 25 Jan 2022 16:30:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-things-that-do-not-work/m-p/139442#M73225</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-01-25T16:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness, things that do not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-things-that-do-not-work/m-p/139455#M73226</link>
      <description>&lt;P&gt;Regarding your second point - do you use the UserCheck Client or only the browser based variant? The redirect log normally says that the message cannot be displayed via browser but only in the UserCheck Client. Some predefined types can display the browser page just fine but most of them (and custom ones) seem to only display the error via the Client. I had a TAC case about that and that was basically the conclusion. The Client itself works perfectly on all systems but they also show up if something gets blocked in the background (auto-updaters for example) so the users may get distracted by this as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 19:27:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-things-that-do-not-work/m-p/139455#M73226</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2022-01-25T19:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness, things that do not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-things-that-do-not-work/m-p/139460#M73227</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11764"&gt;@Marcel_Gramalla&lt;/a&gt; I am referring specifically to the browser-based behavior. In all the years I've worked with Check Point, not once have I seen the UserCheck Client being deployed in the organizations strictly for Content Awareness. Check Point DLP is also not that widely implemented. I have considered including UserCheck Client stipulation in the statement, but have decided against it. From administrators point of view, when working on rules, it is not listed as prerequisite, creating false sense of the expected behavior vs. best-effort possibility.&lt;/P&gt;
&lt;P&gt;Considering that there may be clients other than Windows, we are talking about Captive Portal and AD membership in order to ensure user interaction.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 20:19:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-things-that-do-not-work/m-p/139460#M73227</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-01-25T20:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness, things that do not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-things-that-do-not-work/m-p/139464#M73228</link>
      <description>&lt;P&gt;Yeah, I was also disappointed about the fact that we would need the Client for such basic things but I also don't know how other manufacturers handle this situation. We are coming from a proxy solution which doesn't have the problem but it's a complete different story for this task. Also the archive scanner for Content Awareness and Anti-Virus isn't great and probably disabled by default because of that and we have different issues with it. And this seems to be a pretty old and bad(?) technique/code as TAC and R&amp;amp;D really struggle with this (case open for over 3months now)&lt;/P&gt;
&lt;P&gt;I hope Check Point will build something new that works better for those usecases with less limitations (file size and file count limit just to name a few)&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 20:30:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-things-that-do-not-work/m-p/139464#M73228</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2022-01-25T20:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Content Awareness, things that do not work</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-things-that-do-not-work/m-p/139467#M73229</link>
      <description>&lt;P&gt;Thats an excellent and VERY informative post, thanks for that&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 20:33:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Content-Awareness-things-that-do-not-work/m-p/139467#M73229</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-01-25T20:33:50Z</dc:date>
    </item>
  </channel>
</rss>

