<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custon rules aplication control ? in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264146#M11076</link>
    <description>&lt;P&gt;Can you please clarify what you define as being a "custom rule" and more specifically if this is being tested with / without HTTPS inspection and with what gateway version &amp;amp; JHF etc?&lt;/P&gt;
&lt;P&gt;/Edit: Noted this is an Endpoint query.&lt;/P&gt;</description>
    <pubDate>Wed, 03 Dec 2025 01:06:26 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2025-12-03T01:06:26Z</dc:date>
    <item>
      <title>Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264143#M11075</link>
      <description>&lt;P&gt;Has anyone tested the custom rules in the application control? Honestly, I've tested everything and the custom rules don't work; only the rules defined in "app rules" work.&amp;nbsp;For example: I want to create a rule that blocks all versions of Firefox.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 14:23:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264143#M11075</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2025-12-02T14:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264146#M11076</link>
      <description>&lt;P&gt;Can you please clarify what you define as being a "custom rule" and more specifically if this is being tested with / without HTTPS inspection and with what gateway version &amp;amp; JHF etc?&lt;/P&gt;
&lt;P&gt;/Edit: Noted this is an Endpoint query.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 01:06:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264146#M11076</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-12-03T01:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264154#M11078</link>
      <description>&lt;P&gt;Hey brother,&lt;/P&gt;
&lt;P&gt;Mind sending a screenshot as an example of what you tested?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 15:33:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264154#M11078</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-02T15:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264159#M11079</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These custom rules don't work; only the app rules work. See the images below.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Version89.05.5018.png" style="width: 378px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32275i6B82B3F64AB0C23A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Version89.05.5018.png" alt="Version89.05.5018.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="app_rules.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32277iEEB62528242B75DC/image-size/large?v=v2&amp;amp;px=999" role="button" title="app_rules.png" alt="app_rules.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-12-02_12-44.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32276i3C91BFB0C4B530FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-12-02_12-44.png" alt="2025-12-02_12-44.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 15:50:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264159#M11079</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2025-12-02T15:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264174#M11080</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT:&lt;/P&gt;
&lt;P&gt;My reply&amp;nbsp; below is about the Check Point Security Gateway capabilities and not Harmony Endpoint App Control capabilities.&lt;/P&gt;
&lt;P&gt;I wonder if AppScan could help here.&lt;/P&gt;
&lt;P&gt;-------------------------&lt;/P&gt;
&lt;P&gt;Works for me&lt;/P&gt;
&lt;P&gt;R82&lt;/P&gt;
&lt;P&gt;No https inspection&lt;/P&gt;
&lt;P&gt;New connection - first time Firefox is used - no caching&lt;/P&gt;
&lt;P&gt;Firefox browser is blocked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="No-Firefox-rule.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32278i38B68F4EE1EAEFA6/image-size/large?v=v2&amp;amp;px=999" role="button" title="No-Firefox-rule.png" alt="No-Firefox-rule.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="No-Firefox-log.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32279i494563796126BB5F/image-size/large?v=v2&amp;amp;px=999" role="button" title="No-Firefox-log.png" alt="No-Firefox-log.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 17:30:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264174#M11080</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-12-02T17:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264175#M11081</link>
      <description>&lt;P&gt;I actually tried same in my lab Don and it also blocked incognito window, so definitely works. But, I have a feeling&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/87055"&gt;@lluner&lt;/a&gt;&amp;nbsp;was referring to endpoint policy, just my impression based on what was posted.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 17:21:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264175#M11081</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-02T17:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264176#M11082</link>
      <description>&lt;P&gt;Ah, ooops. I didn't spot that it in the Endpoint forum.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for that.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 17:24:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264176#M11082</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-12-02T17:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264177#M11083</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue is that the blocking occurs at the harmony endpoint, not at the gateway checkpoint.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 17:26:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264177#M11083</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2025-12-02T17:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264178#M11084</link>
      <description>&lt;P&gt;Thats what I figured based on your screenshots. Did you open TAC case yet?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 17:28:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264178#M11084</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-02T17:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264179#M11085</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm first trying to see if anyone can configure these settings and provide an example.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 17:40:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264179#M11085</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2025-12-02T17:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264180#M11086</link>
      <description>&lt;P&gt;Let me ask one of my colleagues, have a call with him in few mins, he is very good with endpoint. Will update you after.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 17:41:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264180#M11086</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-02T17:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264182#M11087</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18248"&gt;@Don_Paterson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've already tried using AppScan, and it works. The problem is that you need to create a custom rule for multiple versions of Adobe, Firefox, or 7-Zip. Using AppScan becomes impractical.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 17:48:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264182#M11087</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2025-12-02T17:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264185#M11088</link>
      <description>&lt;P&gt;This is what my colleague showed me, not sure if you tried it or not.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32280i4D8A6E8A9AA3E91D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32281i700358D1D0FF4336/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 18:13:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264185#M11088</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-02T18:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264193#M11089</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've tried everything to block Adobe and other applications, but nothing works.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-12-02_16-24.png" style="width: 771px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32282iBE2CBB1D1F9E4901/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-12-02_16-24.png" alt="2025-12-02_16-24.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-12-02_16-23_1.png" style="width: 760px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32283iCB91582AF520BD86/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-12-02_16-23_1.png" alt="2025-12-02_16-23_1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-12-02_16-23.png" style="width: 781px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32285iBB40491A41009414/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-12-02_16-23.png" alt="2025-12-02_16-23.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 19:25:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264193#M11089</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2025-12-02T19:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264196#M11091</link>
      <description>&lt;P&gt;So regardless of which application you try, same result?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 20:25:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264196#M11091</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-02T20:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264254#M11100</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, I've tried everything. I tried following the manual exactly, but it doesn't work. It only works when I use AppScan, import the file, and then block it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Application-Control-configuring-the-policy.html?Highlight=application%20control" target="_blank"&gt;Configuring Application Permissions in the Application Control Policy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It only works by uploading the AppScan XML file. The "custom rules" option doesn't work at all.&lt;/P&gt;
&lt;P&gt;Below are the application control logs using the AppScan XML file.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-12-03_08-12.png" style="width: 948px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32291iAD0539C53156CB22/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-12-03_08-12.png" alt="2025-12-03_08-12.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 11:12:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264254#M11100</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2025-12-03T11:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264259#M11101</link>
      <description>&lt;P&gt;I would definitely open TAC case and reference this post.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 11:56:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264259#M11101</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-03T11:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264261#M11103</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's what I'm going to do; I've already opened a ticket with a partner. I'll keep you updated here.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 11:59:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264261#M11103</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2025-12-03T11:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264262#M11104</link>
      <description>&lt;P&gt;I will check with my colleague again, but I can tell by the things you post and try about harmony endpoint, that you are very FAMILIAR with it, so I trust all you did. Please keep us posted.&lt;/P&gt;
&lt;P&gt;Excellent work, as always.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 12:01:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264262#M11104</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-03T12:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: Custon rules aplication control ?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264266#M11105</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We usually block apps using the field&amp;nbsp; Issued To, and that blocks all versiones of the app. You can check on a couple diferent versions of firefox to check if the cert matchs just to double check. In some tests, we saw that the "Application Name" field is actually the name of the process running on windows, so for adobe i think you can use "Acrobat.exe" on your rule. Attaching an example to block opera. HTH.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2025 12:31:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Custon-rules-aplication-control/m-p/264266#M11105</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2025-12-03T12:31:21Z</dc:date>
    </item>
  </channel>
</rss>

