<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application Anonymizer Exception in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Application-Anonymizer-Exception/m-p/72824#M82002</link>
    <description>&lt;P&gt;Category Override only works for URL, so I don't see a way to not have OpenVPN dropped at the Block Anonymiser Rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you block categories then rules that allows Apps/URLs that would be blocked need to be placed above where they are blocked.&lt;/P&gt;&lt;P&gt;Don't see a way around that, when customers want to generally block file sharing and storage then rules where they want OneDrive or DropBox get placed above that block rule for the category.&lt;/P&gt;&lt;P&gt;Don't really see the issue with the structure, otherwise would be creating lots of exceptions constantly to allow specific apps within a category that don't want general access too.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jan 2020 09:53:47 GMT</pubDate>
    <dc:creator>mdjmcnally</dc:creator>
    <dc:date>2020-01-21T09:53:47Z</dc:date>
    <item>
      <title>Application Anonymizer Exception</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Application-Anonymizer-Exception/m-p/72805#M82001</link>
      <description>&lt;P&gt;I have combined my Firewall and Applications and URL Filtering Policy now into a single layer and have a question about if I can add an exception to an Anonymizer category/OpenVPN?&lt;/P&gt;&lt;P&gt;I have created default recommended categories to block near the top of my rule base as attached.&lt;/P&gt;&lt;P&gt;I have a rule a few lines further down that requires OpenVPN which at the moment is being blocked due to the rules at the higher level.&lt;/P&gt;&lt;P&gt;I don't really want to move my rules above my recommended block rules, so was seeing if you are able to add an exception for the OpenVPN application to be allowed for a specific source and destination if possible?&lt;/P&gt;&lt;P&gt;This means I can leave all my rules in place and the exception would only allow this specific traffic from working.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 08:44:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Application-Anonymizer-Exception/m-p/72805#M82001</guid>
      <dc:creator>NeilDavey</dc:creator>
      <dc:date>2020-01-21T08:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Application Anonymizer Exception</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Application-Anonymizer-Exception/m-p/72824#M82002</link>
      <description>&lt;P&gt;Category Override only works for URL, so I don't see a way to not have OpenVPN dropped at the Block Anonymiser Rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you block categories then rules that allows Apps/URLs that would be blocked need to be placed above where they are blocked.&lt;/P&gt;&lt;P&gt;Don't see a way around that, when customers want to generally block file sharing and storage then rules where they want OneDrive or DropBox get placed above that block rule for the category.&lt;/P&gt;&lt;P&gt;Don't really see the issue with the structure, otherwise would be creating lots of exceptions constantly to allow specific apps within a category that don't want general access too.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 09:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Application-Anonymizer-Exception/m-p/72824#M82002</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2020-01-21T09:53:47Z</dc:date>
    </item>
  </channel>
</rss>

