<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic URL Filtering – Categorization in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization/m-p/34643#M91910</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a new question about URL Filtering. I am testing the Application Control und URL Filtering Blades in order to replace our Proxy, but I have a problem with Categorization. The test is done with a R80.10 security Gateway configured as HTTP/HTTPS Proxy with a restrictive configuration: Each Department has access to a group of categories, and all other categories are blocked.&lt;/P&gt;&lt;P&gt;I experience the following behavior:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When a user opens a new Web Site it becomes immediately the category “Web Browsing”. This Category is not allowed in our Policy and the firewall drops the connection.&lt;/LI&gt;&lt;LI&gt;The second time that we open the same website the site is correctly categorized and traffic accepted oder droped according to the policy.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This behavior is also described in SK105642 “Allowed site is blocked on first attempt, then allowed on second attempt”, but the solution doesn’t work for me.&lt;/P&gt;&lt;P&gt;The advanced configuration of Application Control &amp;amp; URL Filtering is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Fail Mode – Block all requests (fail-close)&lt;/LI&gt;&lt;LI&gt;Web browsing – “enable web browsing logging and policy enforcement” – Disabled&lt;/LI&gt;&lt;LI&gt;Checkpoint online web service&lt;UL&gt;&lt;LI&gt;Block requests when web service is unavailable&lt;/LI&gt;&lt;LI&gt;Website Categorization mode: Hold – requests are blocked until categorization is complete&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;For torubleshooting purposes I have temporary disabled https inspection and I experience the same problem.&lt;/P&gt;&lt;P&gt;Has anyone experienced a similar problem?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Oct 2018 13:48:43 GMT</pubDate>
    <dc:creator>Alejandro_Lansa</dc:creator>
    <dc:date>2018-10-11T13:48:43Z</dc:date>
    <item>
      <title>URL Filtering – Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization/m-p/34643#M91910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a new question about URL Filtering. I am testing the Application Control und URL Filtering Blades in order to replace our Proxy, but I have a problem with Categorization. The test is done with a R80.10 security Gateway configured as HTTP/HTTPS Proxy with a restrictive configuration: Each Department has access to a group of categories, and all other categories are blocked.&lt;/P&gt;&lt;P&gt;I experience the following behavior:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When a user opens a new Web Site it becomes immediately the category “Web Browsing”. This Category is not allowed in our Policy and the firewall drops the connection.&lt;/LI&gt;&lt;LI&gt;The second time that we open the same website the site is correctly categorized and traffic accepted oder droped according to the policy.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This behavior is also described in SK105642 “Allowed site is blocked on first attempt, then allowed on second attempt”, but the solution doesn’t work for me.&lt;/P&gt;&lt;P&gt;The advanced configuration of Application Control &amp;amp; URL Filtering is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Fail Mode – Block all requests (fail-close)&lt;/LI&gt;&lt;LI&gt;Web browsing – “enable web browsing logging and policy enforcement” – Disabled&lt;/LI&gt;&lt;LI&gt;Checkpoint online web service&lt;UL&gt;&lt;LI&gt;Block requests when web service is unavailable&lt;/LI&gt;&lt;LI&gt;Website Categorization mode: Hold – requests are blocked until categorization is complete&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;For torubleshooting purposes I have temporary disabled https inspection and I experience the same problem.&lt;/P&gt;&lt;P&gt;Has anyone experienced a similar problem?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2018 13:48:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization/m-p/34643#M91910</guid>
      <dc:creator>Alejandro_Lansa</dc:creator>
      <dc:date>2018-10-11T13:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering – Categorization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization/m-p/34644#M91911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The SK does a fairly good job describing the issue.&lt;/P&gt;&lt;P&gt;The solution described clearly doesn’t work in R80.10.&lt;/P&gt;&lt;P&gt;Maybe instead of entirely blocking Web Browsing you “limit” it to a ridiculously low bandwidth.&lt;/P&gt;&lt;P&gt;This will allow the traffic to continue until it is classified appropriately.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2018 15:54:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization/m-p/34644#M91911</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-12T15:54:04Z</dc:date>
    </item>
  </channel>
</rss>

