<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint blocked by Firewall in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169972#M6536</link>
    <description>&lt;P&gt;I will look into that but why would this affect only 1 user?&lt;/P&gt;</description>
    <pubDate>Wed, 01 Feb 2023 18:19:18 GMT</pubDate>
    <dc:creator>Tony_Graham</dc:creator>
    <dc:date>2023-02-01T18:19:18Z</dc:date>
    <item>
      <title>Endpoint blocked by Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169962#M6533</link>
      <description>&lt;P&gt;Any ideas why CP Endpoint would be blocked by the CP Firewall from contacting the update server?&lt;/P&gt;
&lt;P&gt;I have 1 system in my environment that is getting stuffed.&lt;/P&gt;
&lt;P&gt;The service port is 443, the destination is 209.87.211.157.&lt;/P&gt;
&lt;P&gt;Whois reports this is ZoneAlarm.&lt;/P&gt;
&lt;P&gt;Sometimes it bangs on range 66.110.49.114-116 which is Kaspersky.&lt;/P&gt;
&lt;P&gt;Other times I see 3.5.8.156 which is AWS (no telling which service).&lt;/P&gt;
&lt;P&gt;There is no SSL inspection going on and 443 outbound is allowed for the user&lt;/P&gt;
&lt;P&gt;so it's a definite oddity.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 17:45:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169962#M6533</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2023-02-01T17:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint blocked by Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169969#M6534</link>
      <description>&lt;P&gt;Make sure you’re allowing connectivity per:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116590&amp;amp;partition=Basic&amp;amp;product=Harmony" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116590&amp;amp;partition=Basic&amp;amp;product=Harmony&lt;/A&gt;&lt;BR /&gt;The “Check Point Services” Updatable Object includes the stuff listed here.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 18:11:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169969#M6534</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-01T18:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint blocked by Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169971#M6535</link>
      <description>&lt;P&gt;Had to actually verify that sk once with customer what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;gave, so definitely good starting point.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 18:18:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169971#M6535</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-01T18:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint blocked by Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169972#M6536</link>
      <description>&lt;P&gt;I will look into that but why would this affect only 1 user?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 18:19:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169972#M6536</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2023-02-01T18:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint blocked by Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169973#M6537</link>
      <description>&lt;P&gt;If its only one user, then does not really sound like its fw issue, but just my logical assumption. Do you have any relevant logs from the dashboard you can attach?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 18:31:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169973#M6537</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-01T18:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint blocked by Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169974#M6538</link>
      <description>&lt;P&gt;I kind of digested all the relevant details in the first post. That's all that's available to me in dashboard.&lt;/P&gt;
&lt;P&gt;Although it looks like it's a bunch of 'First packet isn't SYN'. Again it only occurs with this one user.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 18:37:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169974#M6538</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2023-02-01T18:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint blocked by Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169978#M6539</link>
      <description>&lt;P&gt;That message needs some captures, for sure. Do fw monitor and tcpdump to see path it takes.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 18:55:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169978#M6539</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-01T18:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint blocked by Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169979#M6540</link>
      <description>&lt;P&gt;I am starting to suspect it has something to do with VMware and its NAT connection.&lt;/P&gt;
&lt;P&gt;I am going to switch that machine over to Bridged tonight and monitor it some more.&lt;/P&gt;
&lt;P&gt;**UPDATE** The problem was with VMware. I deleted the virtual adapter and re-added it, switched to Bridged mode and the problem has gone away. As a note VMware Workstation virtual network adapters do not always upgrade correctly when there is a version change or if you ported it around. You can often find 'cruft' in the vmx files from past versions. My process is to remove the current adapter in VMware. Shut down Workstation, find the .vmx file of the VM you have issues with. Make a copy of it, then I go into the original and search on 'eth', and blast all the entries that match on 'eth' except the one related to the PCI slot number and the MAC address. Save the file, relaunch VMware Workstation, add in a new adapter for the VM and then boot it. You have to take care of any IP things inside of the VM but it will sort out any crazy Ethernet weirdness.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 21:32:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Endpoint-blocked-by-Firewall/m-p/169979#M6540</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2023-02-02T21:32:31Z</dc:date>
    </item>
  </channel>
</rss>

