<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint Security white list domains for Sandblast agent for browsers Phishing check in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-white-list-domains-for-Sandblast-agent-for/m-p/83499#M3138</link>
    <description>&lt;P&gt;I found the answer. I was typing the domain name wrong.&lt;/P&gt;&lt;P&gt;answer was in this post:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Endpoint-Security-Products/Zero-Phishing-Exceptions/td-p/49595" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Endpoint-Security-Products/Zero-Phishing-Exceptions/td-p/49595&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Talya towards the bottom pointed out:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When defining a domain for exclusion\protection, you should only consider the domain portion of the URL (shown in bold):&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.checkpoint.com:8080/path/to/page" target="_blank" rel="nofollow noopener noreferrer"&gt;https://&lt;STRONG&gt;www.checkpoint.com&lt;/STRONG&gt;:8080/path/to/page&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;A domain will be classified as excluded\protected, if any entry in the exclusion list is a suffix of it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;For example, if the exclusion list contains the entry&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;EM&gt;.checkpoint.com&lt;/EM&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;then&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://www.checkpoint.com/" target="_blank" rel="nofollow noopener noreferrer"&gt;www.checkpoint.com&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;will be excluded.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;that was under "inspect all domains and files"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the Zero phishing "protected sites" is for data-mining the credentials to not allow to be used elsewhere.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope that helps.&lt;/P&gt;&lt;P&gt;Seth&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 15:18:15 GMT</pubDate>
    <dc:creator>Seth</dc:creator>
    <dc:date>2020-04-28T15:18:15Z</dc:date>
    <item>
      <title>Endpoint Security white list domains for Sandblast agent for browsers Phishing check</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-white-list-domains-for-Sandblast-agent-for/m-p/82675#M3137</link>
      <description>&lt;P&gt;first time poster, long time(1 year) listener.&lt;/P&gt;&lt;P&gt;I am trying to white list internal(not going through a gateway) homemade websites. When a user with E82.30.0530 (or any version) endpoint client tries to click on the username/password field they get blocked by the "SandBlast Agent for Browsers": Beware! Deceptive site blocked.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="endpoint2.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5716iA8440485BFEF5DCA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="endpoint2.jpg" alt="endpoint2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The error then goes on to explain itself and gives a link "if this is incorrect,&amp;nbsp;&lt;U&gt;send a report&lt;/U&gt;" (is that internal? can't find it)&lt;/P&gt;&lt;P&gt;I have added the site to the white-list in 2 places in the&amp;nbsp; SmartEndpoint management console. properties calls this area "Exclusions" under "inspect all domains and files" and "Protected Domains" under "Zero Phishing Settings.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="endpoint.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5715iD3300F136E3A9B26/image-size/large?v=v2&amp;amp;px=999" role="button" title="endpoint.jpg" alt="endpoint.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am i doing wrong? Where do i white-list sites for the browser agent to not check for Phishing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seth in St. Louis&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 20:25:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-white-list-domains-for-Sandblast-agent-for/m-p/82675#M3137</guid>
      <dc:creator>Seth</dc:creator>
      <dc:date>2020-04-21T20:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security white list domains for Sandblast agent for browsers Phishing check</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-white-list-domains-for-Sandblast-agent-for/m-p/83499#M3138</link>
      <description>&lt;P&gt;I found the answer. I was typing the domain name wrong.&lt;/P&gt;&lt;P&gt;answer was in this post:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Endpoint-Security-Products/Zero-Phishing-Exceptions/td-p/49595" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Endpoint-Security-Products/Zero-Phishing-Exceptions/td-p/49595&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Talya towards the bottom pointed out:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When defining a domain for exclusion\protection, you should only consider the domain portion of the URL (shown in bold):&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.checkpoint.com:8080/path/to/page" target="_blank" rel="nofollow noopener noreferrer"&gt;https://&lt;STRONG&gt;www.checkpoint.com&lt;/STRONG&gt;:8080/path/to/page&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;A domain will be classified as excluded\protected, if any entry in the exclusion list is a suffix of it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;For example, if the exclusion list contains the entry&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;EM&gt;.checkpoint.com&lt;/EM&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;then&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://www.checkpoint.com/" target="_blank" rel="nofollow noopener noreferrer"&gt;www.checkpoint.com&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;will be excluded.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;that was under "inspect all domains and files"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the Zero phishing "protected sites" is for data-mining the credentials to not allow to be used elsewhere.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope that helps.&lt;/P&gt;&lt;P&gt;Seth&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 15:18:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-Security-white-list-domains-for-Sandblast-agent-for/m-p/83499#M3138</guid>
      <dc:creator>Seth</dc:creator>
      <dc:date>2020-04-28T15:18:15Z</dc:date>
    </item>
  </channel>
</rss>

