<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic to domain excepted is still blocked in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/163888#M27382</link>
    <description>&lt;P&gt;Hello friends,&lt;/P&gt;&lt;P&gt;Nice to greet you all.&lt;/P&gt;&lt;P&gt;I need your help. I have the following problem. I need to access the website "usage.projectcalico.org" I have enabled it by regex and by fqdn, and the log also shows the domain *r.cloudfront.net, which I have also enabled by wildcard regex "*r.cloudfront .net" .... but the lock remains. It can be seen in the "SNI" column that contains the domain that I want to enable. Also, I have enabled a bypass rule in SSL inspection, but the blocking persists. Has anyone else had this problem and know how to fix it? I attach the evidence image.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Dec 2022 15:24:08 GMT</pubDate>
    <dc:creator>Pvalderrama</dc:creator>
    <dc:date>2022-12-01T15:24:08Z</dc:date>
    <item>
      <title>Traffic to domain excepted is still blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/163888#M27382</link>
      <description>&lt;P&gt;Hello friends,&lt;/P&gt;&lt;P&gt;Nice to greet you all.&lt;/P&gt;&lt;P&gt;I need your help. I have the following problem. I need to access the website "usage.projectcalico.org" I have enabled it by regex and by fqdn, and the log also shows the domain *r.cloudfront.net, which I have also enabled by wildcard regex "*r.cloudfront .net" .... but the lock remains. It can be seen in the "SNI" column that contains the domain that I want to enable. Also, I have enabled a bypass rule in SSL inspection, but the blocking persists. Has anyone else had this problem and know how to fix it? I attach the evidence image.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 15:24:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/163888#M27382</guid>
      <dc:creator>Pvalderrama</dc:creator>
      <dc:date>2022-12-01T15:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to domain excepted is still blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/163919#M27387</link>
      <description>&lt;P&gt;Can you try by allowing custom app site and try *projectcalico* and also bypass that in https inspection policy.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 01:29:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/163919#M27387</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T01:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to domain excepted is still blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/164037#M27392</link>
      <description>&lt;P&gt;What version/JHF level are you running?&lt;BR /&gt;We only use Verified SNI if you’re on R80.40 or above.&lt;BR /&gt;In R80.30 or R80.20, you need to be on a specific JHF level AND have HTTPS Inspection enabled.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 23:40:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/164037#M27392</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-02T23:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to domain excepted is still blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/164045#M27396</link>
      <description>&lt;P&gt;Did you try creating a domain object/FQDN Object? and keeping same dns on firewall which is kept at user level?&lt;/P&gt;</description>
      <pubDate>Sat, 03 Dec 2022 05:41:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/164045#M27396</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-12-03T05:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to domain excepted is still blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/164177#M27405</link>
      <description>&lt;P&gt;Hi, friend. Thank you very much for the reply. I have version r81.10&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 14:33:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/164177#M27405</guid>
      <dc:creator>Pvalderrama</dc:creator>
      <dc:date>2022-12-05T14:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic to domain excepted is still blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/164183#M27406</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;usage.projectcalico.org is not available in firefox also without CP GW:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="tab-panel headers"&gt;
&lt;DIV class="headersPanelBox tab-panel-inner"&gt;
&lt;DIV class="toolbar"&gt;Headers:&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="netInfoHeadersTable"&gt;
&lt;DIV class="netHeadersGroup"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="netHeadersGroup"&gt;
&lt;TABLE cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Connection"&gt;Connection&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;keep-alive&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Content-Length"&gt;Content-Length&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;23&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Content-Type"&gt;Content-Type&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;application/json&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Date"&gt;Date&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;Mon, 05 Dec 2022 14:41:39 GMT&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Via"&gt;Via&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;1.1 42c9dddb4e518a9ed3248bf50565b120.cloudfront.net (CloudFront)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="X-Amz-Cf-Id"&gt;X-Amz-Cf-Id&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;zk4XqztmW584JeeKX51WBO5Umsg8Jmn1oJT4RPQUFHKWu8oY8CiG3w==&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="X-Amz-Cf-Pop"&gt;X-Amz-Cf-Pop&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;VIE50-C2&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="X-Cache"&gt;X-Cache&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;Error from cloudfront&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="x-amz-apigw-id"&gt;x-amz-apigw-id&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;crVtpFdMNjMFoYg=&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="x-amzn-ErrorType"&gt;x-amzn-ErrorType&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;ForbiddenException&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="x-amzn-RequestId"&gt;x-amzn-RequestId&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;7af7c8f5-4dde-40bd-b8e4-ad09ae2f7c11&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;DIV class="netHeadersGroup"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;TABLE cellspacing="0" cellpadding="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Accept"&gt;Accept&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Accept-Encoding"&gt;Accept-Encoding&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;gzip, deflate, br&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Accept-Language"&gt;Accept-Language&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;de,en-US;q=0.7,en;q=0.3&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Connection"&gt;Connection&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;keep-alive&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="DNT"&gt;DNT&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Host"&gt;Host&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;usage.projectcalico.org&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Sec-Fetch-Dest"&gt;Sec-Fetch-Dest&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;document&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Sec-Fetch-Mode"&gt;Sec-Fetch-Mode&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;navigate&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Sec-Fetch-Site"&gt;Sec-Fetch-Site&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;none&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Sec-Fetch-User"&gt;Sec-Fetch-User&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;?1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="Upgrade-Insecure-Requests"&gt;Upgrade-Insecure-Requests&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class="netInfoParamName"&gt;&lt;SPAN title="User-Agent"&gt;User-Agent&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD class="netInfoParamValue"&gt;Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:107.0) Gecko/20100101 Firefox/107.0&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Mon, 05 Dec 2022 14:43:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-to-domain-excepted-is-still-blocked/m-p/164183#M27406</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-12-05T14:43:44Z</dc:date>
    </item>
  </channel>
</rss>

