<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Application and URL Filtering Drops in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/87196#M17501</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I see the below drops on Application filtering, the type says "Session" and the destination is an IP so not sure how to troubleshoot this.&lt;/P&gt;&lt;P&gt;Please help to fix this. Thanks in advance.&lt;/P&gt;&lt;P&gt;Time: 2020-06-03T12:23:47Z&lt;BR /&gt;Interface Direction: inbound&lt;BR /&gt;Interface Name: eth1&lt;BR /&gt;Connection Direction: Outgoing&lt;BR /&gt;Id: ac1qwe3af-1f3a-0000-asdc-00000001&lt;BR /&gt;Id Generated By Indexer:false&lt;BR /&gt;First: false&lt;BR /&gt;Sequencenum: 22&lt;BR /&gt;Hll Key: 56821192462850914&lt;BR /&gt;Duration: 300&lt;BR /&gt;Last Update Time: 2020-06-03T12:23:47Z&lt;BR /&gt;Update Count: 2&lt;BR /&gt;Connections: 1&lt;BR /&gt;Aggregated Log Count: 1&lt;BR /&gt;Creation Time: 2020-06-03T12:23:47Z&lt;BR /&gt;Source: 10.10.x.x&lt;BR /&gt;Destination: 1.2.1.3&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Service ID: https&lt;BR /&gt;Source Zone: Internal&lt;BR /&gt;Destination Zone: External&lt;BR /&gt;Last Update Time: 2020-06-03T12:28:47Z&lt;BR /&gt;Action: Drop&lt;BR /&gt;Type: Session&lt;BR /&gt;Policy Name: Standard&lt;BR /&gt;Policy Management: ABCD_Mgmt_Server&lt;BR /&gt;Db Tag: {13405065-D333-3540-964B-2FA7A027B7CB}&lt;BR /&gt;Policy Date: 2020-06-03T12:22:01Z&lt;BR /&gt;Blade: Firewall&lt;BR /&gt;Origin: ABCDEFFW01&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 1234&lt;BR /&gt;Domain: ABCD_Mgmt_Server&lt;BR /&gt;Access Rule Name: Deny Any&lt;BR /&gt;Access Rule Number: 18&lt;BR /&gt;Policy Rule UID: 8989898-090909-998&lt;BR /&gt;Layer Name: Application&lt;BR /&gt;Interface: eth1&lt;BR /&gt;Description: https Traffic Dropped from 10.10.x.x to 1.2.1.3&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jun 2020 15:27:13 GMT</pubDate>
    <dc:creator>Sanjay_S</dc:creator>
    <dc:date>2020-06-03T15:27:13Z</dc:date>
    <item>
      <title>Application and URL Filtering Drops</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/87196#M17501</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I see the below drops on Application filtering, the type says "Session" and the destination is an IP so not sure how to troubleshoot this.&lt;/P&gt;&lt;P&gt;Please help to fix this. Thanks in advance.&lt;/P&gt;&lt;P&gt;Time: 2020-06-03T12:23:47Z&lt;BR /&gt;Interface Direction: inbound&lt;BR /&gt;Interface Name: eth1&lt;BR /&gt;Connection Direction: Outgoing&lt;BR /&gt;Id: ac1qwe3af-1f3a-0000-asdc-00000001&lt;BR /&gt;Id Generated By Indexer:false&lt;BR /&gt;First: false&lt;BR /&gt;Sequencenum: 22&lt;BR /&gt;Hll Key: 56821192462850914&lt;BR /&gt;Duration: 300&lt;BR /&gt;Last Update Time: 2020-06-03T12:23:47Z&lt;BR /&gt;Update Count: 2&lt;BR /&gt;Connections: 1&lt;BR /&gt;Aggregated Log Count: 1&lt;BR /&gt;Creation Time: 2020-06-03T12:23:47Z&lt;BR /&gt;Source: 10.10.x.x&lt;BR /&gt;Destination: 1.2.1.3&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Service ID: https&lt;BR /&gt;Source Zone: Internal&lt;BR /&gt;Destination Zone: External&lt;BR /&gt;Last Update Time: 2020-06-03T12:28:47Z&lt;BR /&gt;Action: Drop&lt;BR /&gt;Type: Session&lt;BR /&gt;Policy Name: Standard&lt;BR /&gt;Policy Management: ABCD_Mgmt_Server&lt;BR /&gt;Db Tag: {13405065-D333-3540-964B-2FA7A027B7CB}&lt;BR /&gt;Policy Date: 2020-06-03T12:22:01Z&lt;BR /&gt;Blade: Firewall&lt;BR /&gt;Origin: ABCDEFFW01&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 1234&lt;BR /&gt;Domain: ABCD_Mgmt_Server&lt;BR /&gt;Access Rule Name: Deny Any&lt;BR /&gt;Access Rule Number: 18&lt;BR /&gt;Policy Rule UID: 8989898-090909-998&lt;BR /&gt;Layer Name: Application&lt;BR /&gt;Interface: eth1&lt;BR /&gt;Description: https Traffic Dropped from 10.10.x.x to 1.2.1.3&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 15:27:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/87196#M17501</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2020-06-03T15:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: Application and URL Filtering Drops</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/87218#M17507</link>
      <description>&lt;P&gt;Have you looked through all the tabs (circled below) on the log card?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tabs.png" style="width: 798px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6344iDD9F5F7DDC7C25D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="tabs.png" alt="tabs.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 21:42:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/87218#M17507</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-06-03T21:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Application and URL Filtering Drops</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/87271#M17525</link>
      <description>Hi Timothy,&lt;BR /&gt;I dont see the Session Tab at all in the log.</description>
      <pubDate>Thu, 04 Jun 2020 09:07:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/87271#M17525</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2020-06-04T09:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Application and URL Filtering Drops</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/87445#M17599</link>
      <description>Hi Timothy,&lt;BR /&gt;After enabling the detailed logging i can see the Session TAB. But i don see much difference between Details and Session TAB. Not seeing more information on this. Any help is much appreciated.&lt;BR /&gt;&lt;BR /&gt;Time: 2020-06-05T16:25:13Z&lt;BR /&gt;Interface Direction: inbound&lt;BR /&gt;Interface Name: eth1&lt;BR /&gt;Connection Direction: Outgoing&lt;BR /&gt;Id: ac1103af-1f3a-0000-5eda-71e900000002&lt;BR /&gt;Id Generated By Indexer:false&lt;BR /&gt;First: false&lt;BR /&gt;Sequencenum: 14&lt;BR /&gt;Hll Key: 9772743427617257963&lt;BR /&gt;Duration: 300&lt;BR /&gt;Last Update Time: 2020-06-05T16:29:46Z&lt;BR /&gt;Update Count: 3&lt;BR /&gt;Connections: 5&lt;BR /&gt;Aggregated Log Count: 7&lt;BR /&gt;Creation Time: 2020-06-05T16:25:13Z&lt;BR /&gt;Source: 10.0.0.1&lt;BR /&gt;Destination: 3.1.2.11&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Protocol: HTTPS&lt;BR /&gt;Sig Id: 4&lt;BR /&gt;Service ID: https&lt;BR /&gt;Source Zone: Internal&lt;BR /&gt;Destination Zone: External&lt;BR /&gt;Packets: 10&lt;BR /&gt;Total Bytes: 867&lt;BR /&gt;Client Inbound Packets: 6&lt;BR /&gt;Client Outbound Packets:4&lt;BR /&gt;Server Inbound Packets: 4&lt;BR /&gt;Server Outbound Packets:6&lt;BR /&gt;Client Inbound Bytes: 683&lt;BR /&gt;Client Outbound Bytes: 184&lt;BR /&gt;Server Inbound Bytes: 184&lt;BR /&gt;Server Outbound Bytes: 683&lt;BR /&gt;Last Update Time: 2020-06-05T16:30:13Z&lt;BR /&gt;Action: Drop&lt;BR /&gt;Type: Session&lt;BR /&gt;Policy Name: Standard&lt;BR /&gt;Policy Management: ABCD_Mgmt_Server&lt;BR /&gt;Db Tag: {0F6DB4CC-76A3-5142-80FB-580A72810BF9}&lt;BR /&gt;Policy Date: 2020-06-05T16:23:22Z&lt;BR /&gt;Blade: Firewall&lt;BR /&gt;Origin: ABCDEFFW01&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Sent Bytes: 683&lt;BR /&gt;Received Bytes: 184&lt;BR /&gt;Logid: 352&lt;BR /&gt;Domain: ABCD_Mgmt_Server&lt;BR /&gt;Access Rule Name: Deny Any&lt;BR /&gt;Access Rule Number: 18&lt;BR /&gt;Policy Rule UID: 86b4d9db-0f48-44f2-9168-4fb85f74a617&lt;BR /&gt;Layer Name: Application&lt;BR /&gt;Interface: eth1&lt;BR /&gt;Description: https Traffic Dropped from 10.0.0.1 to 3.1.2.11</description>
      <pubDate>Fri, 05 Jun 2020 17:02:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/87445#M17599</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2020-06-05T17:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Application and URL Filtering Drops</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/87446#M17600</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18584"&gt;@Sanjay_S&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your shown connection is dropped by rule number 18.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Access Rule Name: Deny Any&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Access Rule Number: 18&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Policy Rule UID: 86b4d9db-0f48-44f2-9168-4fb85f74a617&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Layer Name: Application&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You should check this rule, the name indicates the the rule drops all.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 17:13:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/87446#M17600</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-06-05T17:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: Application and URL Filtering Drops</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/88272#M17733</link>
      <description>Thanks for the reply.&lt;BR /&gt;As per the customer a particular server needs access only to particular URL and nothing else and hence created a rule at the bottom to block everything except the URLs he want to access and that is the Rule 18.</description>
      <pubDate>Thu, 11 Jun 2020 16:34:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/88272#M17733</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2020-06-11T16:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: Application and URL Filtering Drops</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/88279#M17736</link>
      <description>&lt;P&gt;Your log shows blocking from firewall blade not applicationcontrol/urlfilter.&lt;/P&gt;
&lt;P&gt;please show your rulebase, maybee something wrong configured.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 17:38:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-and-URL-Filtering-Drops/m-p/88279#M17736</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-06-11T17:38:45Z</dc:date>
    </item>
  </channel>
</rss>

