<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Filtering Categorization issues r80.30 without https inspection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83873#M9331</link>
    <description>&lt;P&gt;i enabled https inspection with any any bypass.&lt;/P&gt;&lt;P&gt;It seems to be better, but i still have cases where is being droped and not matching the rule it should, with logs like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is case as test is a rule any any with Financial Services as category, and this website is in that category based on checkpoint tool to check.&lt;/P&gt;&lt;P&gt;@;888290;[vs_2];[tid_4];[fw4_4];fw_log_drop_ex: Packet proto=6 194.79.41.46:443 -&amp;gt; 10.160.35.190:61925 dropped by fwpslglue_chain Reason: PSL Reject: TLS_PARSER;&lt;BR /&gt;@;888290;[vs_2];[tid_4];[fw4_4];fw_log_drop_ex: Packet proto=6 194.79.41.46:443 -&amp;gt; 10.160.35.190:61925 dropped by fwpslglue_chain Reason: PSL Reject: TLS_PARSER;&lt;BR /&gt;@;888290;[vs_2];[tid_4];[fw4_4];fw_log_drop_ex: Packet proto=6 194.79.41.46:443 -&amp;gt; 10.160.35.190:61925 dropped by fwpslglue_chain Reason: PSL Reject: TLS_PARSER;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it's the in the other direction..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;site is nbs.rs if you want to check certificat.&lt;/P&gt;</description>
    <pubDate>Fri, 01 May 2020 22:40:15 GMT</pubDate>
    <dc:creator>Khalid_Aftas</dc:creator>
    <dc:date>2020-05-01T22:40:15Z</dc:date>
    <item>
      <title>URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83852#M9329</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In the past we never succeded to make URL filtering/Appcontrol work as advertised in 77.30 &amp;amp; 80.10, now that we upgraded our vsx to r80.30 we decided to give it a shot.&lt;/P&gt;&lt;P&gt;In our policy we tested everything we could, simple rules with categories, rules with custom application &amp;amp; list of urls, and we are still having matching issues (blocked categories allowed, allowed categories blocked etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In R80.30, URL filtering should be using SNI to check the urls, as CN is not reliable as certificats can be shared and not related to the actual websites categories, but that seems not work either,.&lt;/P&gt;&lt;P&gt;Even following the famous white paper that was written for 80.10 that suggested to add those command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;fw ctl set int urlf_use_sni_for_categorization 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;fw ctl set int urlf_block_unauthorized_sni 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Of course our configuration is following the documentation, and HTTPS website categorization options is checked.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;in Some cases they are even some silent drops (which i think is a separate) issue&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;@;6279018;[vs_2];[tid_11];[fw4_11];fw_log_drop_ex: Packet proto=6 2.17.5.196:443 -&amp;gt; 10.160.35.190:50092 dropped by fwmultik_process_f2p_cookie_inner Reason: PSL Drop: TLS_PARSER&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;There is some SK about this error for a special hotfix&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;TAC support case 7h tshoot couldn't find anything (not even this hotfix.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Any toughts ?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Kr,&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Khalid&lt;/DIV&gt;</description>
      <pubDate>Fri, 01 May 2020 18:34:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83852#M9329</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-05-01T18:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83856#M9330</link>
      <description>SNI verification (and inspecting based on SNI) requires HTTPS Inspection to be enabled in R80.30.&lt;BR /&gt;Enable HTTPS Inspection with a simple "Any Any Bypass" rule and try again.</description>
      <pubDate>Fri, 01 May 2020 19:06:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83856#M9330</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-01T19:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83873#M9331</link>
      <description>&lt;P&gt;i enabled https inspection with any any bypass.&lt;/P&gt;&lt;P&gt;It seems to be better, but i still have cases where is being droped and not matching the rule it should, with logs like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is case as test is a rule any any with Financial Services as category, and this website is in that category based on checkpoint tool to check.&lt;/P&gt;&lt;P&gt;@;888290;[vs_2];[tid_4];[fw4_4];fw_log_drop_ex: Packet proto=6 194.79.41.46:443 -&amp;gt; 10.160.35.190:61925 dropped by fwpslglue_chain Reason: PSL Reject: TLS_PARSER;&lt;BR /&gt;@;888290;[vs_2];[tid_4];[fw4_4];fw_log_drop_ex: Packet proto=6 194.79.41.46:443 -&amp;gt; 10.160.35.190:61925 dropped by fwpslglue_chain Reason: PSL Reject: TLS_PARSER;&lt;BR /&gt;@;888290;[vs_2];[tid_4];[fw4_4];fw_log_drop_ex: Packet proto=6 194.79.41.46:443 -&amp;gt; 10.160.35.190:61925 dropped by fwpslglue_chain Reason: PSL Reject: TLS_PARSER;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it's the in the other direction..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;site is nbs.rs if you want to check certificat.&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 22:40:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83873#M9331</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-05-01T22:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83877#M9332</link>
      <description>Looks similar to: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164815" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164815&lt;/A&gt;&lt;BR /&gt;I would get the TAC involved here.</description>
      <pubDate>Fri, 01 May 2020 22:51:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83877#M9332</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-01T22:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83878#M9333</link>
      <description>Yeah that is what we found, and we were in a session with TAC (india) they did not find that hotfix...</description>
      <pubDate>Fri, 01 May 2020 22:53:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83878#M9333</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-05-01T22:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83917#M9334</link>
      <description>TAC can request a portfix if required.&lt;BR /&gt;That said it may not be the exact same issue, so additional debugging may be required.</description>
      <pubDate>Sun, 03 May 2020 05:06:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/83917#M9334</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-03T05:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/84119#M9335</link>
      <description>&lt;P&gt;The issue was that Trusted CAs was not up to date, r&amp;amp;d was able to pinpoint it with the debugs.&lt;/P&gt;&lt;P&gt;Thx a lot for the help &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Enabling https inspection with any any bypass and updating Trusted CAs must be added in the documentation, that would avoid trouble like this for other clients &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 17:53:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/84119#M9335</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-05-04T17:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/87357#M9336</link>
      <description>&lt;P&gt;Is there a way to verify that checkpoint is using sni versus just checking the CN in the certificate. Also how do you update the trusted CA?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 00:35:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/87357#M9336</guid>
      <dc:creator>Michael_Thompso</dc:creator>
      <dc:date>2020-06-05T00:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/87401#M9337</link>
      <description>Depending on your version, as of r80.30 SNI check are per default, but you NEED https inspection to be enabled, even without using it.&lt;BR /&gt;&lt;BR /&gt;To update Trusted CA list, is under smartconsole, https inspection console, you have a big tab Trusted CA list, and a check box to look up for update, check it save, close, go back at it again and it should find new one, update and push policy&lt;BR /&gt;</description>
      <pubDate>Fri, 05 Jun 2020 07:57:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/87401#M9337</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-06-05T07:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/87425#M9338</link>
      <description>&lt;P&gt;Thanks .. do you still need "Categorize HTTPS websites" checked?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 12:50:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/87425#M9338</guid>
      <dc:creator>Michael_Thompso</dc:creator>
      <dc:date>2020-06-05T12:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/87426#M9339</link>
      <description>&lt;P&gt;yes it's a requirement.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 12:51:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/87426#M9339</guid>
      <dc:creator>Khalid_Aftas</dc:creator>
      <dc:date>2020-06-05T12:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/87526#M9340</link>
      <description>Note that the requirement to have HTTPS Inspection enabled for SNI support applies to R80.30 only, it is not required for R80.40 and later releases.&lt;BR /&gt;In this case, you can just set an "Any any bypass" rule as the HTTPS Inspection rulebase.&lt;BR /&gt;It does require "Categorize HTTPS Websites" to be checked as well, regardless of the release.&lt;BR /&gt;</description>
      <pubDate>Mon, 08 Jun 2020 02:30:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/87526#M9340</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-08T02:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/103432#M9341</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have similar problem with URL Filtering. After read this article&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164815" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164815&lt;/A&gt;&amp;nbsp;, I upgrade cluster to 80.40 software, and 83 jumbo. The problem is still exist. Do you have some idea what's is wrong?&lt;/P&gt;&lt;P&gt;We do not use SSL insepction. The certificate list is ok.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 13:41:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/103432#M9341</guid>
      <dc:creator>TomaszSZ</dc:creator>
      <dc:date>2020-11-26T13:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: URL Filtering Categorization issues r80.30 without https inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/103445#M9342</link>
      <description>&lt;P&gt;Please elaborate on your "similar problem"&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 14:17:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/URL-Filtering-Categorization-issues-r80-30-without-https/m-p/103445#M9342</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-11-26T14:17:03Z</dc:date>
    </item>
  </channel>
</rss>

