<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to update malware definitions from LAN in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139901#M5070</link>
    <description>&lt;P&gt;I'm seeing urls that are not listed in sk116590 yes, but I have to assume they should be https as they are using certificates.&lt;/P&gt;&lt;P&gt;dc1.ksn.kaspersky-labs.com&lt;/P&gt;&lt;P&gt;da.kaspersky.com&lt;/P&gt;&lt;P&gt;It sort of suggests that the sk may be out of date,.&lt;/P&gt;&lt;P&gt;I am seeing the same issue with the E85.40 as well the latest E86.20 clients.&lt;/P&gt;&lt;P&gt;I've attached the 2 log entries below&lt;/P&gt;</description>
    <pubDate>Sat, 29 Jan 2022 14:57:44 GMT</pubDate>
    <dc:creator>StevePearson</dc:creator>
    <dc:date>2022-01-29T14:57:44Z</dc:date>
    <item>
      <title>Unable to update malware definitions from LAN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139847#M5064</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm starting to roll out new laptop endpoints from the Infinity Portal. The problem is, while they update correctly when at home on broadband, they do not update whilst in the office behind the corporate firewall.&lt;/P&gt;&lt;P&gt;The firewall is a clustered pair of 5800's running R80.20.&lt;/P&gt;&lt;P&gt;The logs report "untrusted certificate detected" and refers to Kaspersy url's&lt;/P&gt;&lt;P&gt;I've tried whitelisting these url's in the https &amp;nbsp;inspection policy but that doesn't help, but if I whitelist everything for a test machine, so it effectively doesn't do any inspection, then it works correctly, so it's definitely related to https inspection.&lt;/P&gt;&lt;P&gt;I was wondering if anyone else has come across this issue, or has any suggestions how to resolve this?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 18:07:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139847#M5064</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2022-01-28T18:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to update malware definitions from LAN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139890#M5065</link>
      <description>&lt;P&gt;Correct me if I'm wrong, but arn't the kav8.zonealarm.com links running over http?&lt;BR /&gt;If you're forcing traffic over HTTPS, that would explain the lack of a valid certificate.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jan 2022 09:18:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139890#M5065</guid>
      <dc:creator>Swiftyyyy</dc:creator>
      <dc:date>2022-01-29T09:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to update malware definitions from LAN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139893#M5066</link>
      <description>&lt;P&gt;Are you seeing non-HTTP URLs different to those in&amp;nbsp;&lt;SPAN&gt;sk116590?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;One alternative is the Supernode approach, refer: sk171703&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jan 2022 11:24:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139893#M5066</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-01-29T11:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to update malware definitions from LAN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139898#M5068</link>
      <description>&lt;P&gt;the links its having problems with are dc1.ksn.kaspersky-labs.com, and da.kaspersky.com&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jan 2022 14:59:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139898#M5068</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2022-01-29T14:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to update malware definitions from LAN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139901#M5070</link>
      <description>&lt;P&gt;I'm seeing urls that are not listed in sk116590 yes, but I have to assume they should be https as they are using certificates.&lt;/P&gt;&lt;P&gt;dc1.ksn.kaspersky-labs.com&lt;/P&gt;&lt;P&gt;da.kaspersky.com&lt;/P&gt;&lt;P&gt;It sort of suggests that the sk may be out of date,.&lt;/P&gt;&lt;P&gt;I am seeing the same issue with the E85.40 as well the latest E86.20 clients.&lt;/P&gt;&lt;P&gt;I've attached the 2 log entries below&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jan 2022 14:57:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139901#M5070</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2022-01-29T14:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to update malware definitions from LAN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139903#M5071</link>
      <description>&lt;P&gt;What precise JHF version?&lt;BR /&gt;Seems to me you would benefit from updating to a later release where SNI support would help you create the necessary exclusions.&lt;BR /&gt;Plenty of other reasons to upgrade from R80.20 as well,&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jan 2022 15:51:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139903#M5071</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-01-29T15:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to update malware definitions from LAN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139905#M5072</link>
      <description>&lt;P&gt;The gateway is running Take 202 (205 planned for this coming week!)&lt;/P&gt;&lt;P&gt;We've white listed the urls but it makes no difference, do you think that this could be due to SNI?&lt;/P&gt;&lt;P&gt;There are plans in motion to upgrade, the target was R80.40, but wheels move so slowly we'll go with the recommended version once we get the go ahead to do it (R81.10 now I believe)&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jan 2022 16:41:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Unable-to-update-malware-definitions-from-LAN/m-p/139905#M5072</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2022-01-29T16:41:11Z</dc:date>
    </item>
  </channel>
</rss>

