<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Loss of a rule hit in AppCtrl-URLFltr... in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17126#M2880</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the firewall's rad process is having problems you will see behavior like this (and slow initial page loads), can I assume you are running the latest GA Jumbo HFA for R77.30 or R80.10?&amp;nbsp; This is extensively covered in second edition of my book, does &lt;STRONG&gt;cpwd_admin list&lt;/STRONG&gt; show rad getting restarted?&amp;nbsp; For R77.30 especially there were a lot of problems with rad fixed by the jumbo HFA.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My Book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; Second Edition Coming Soon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Dec 2017 22:15:47 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2017-12-07T22:15:47Z</dc:date>
    <item>
      <title>Loss of a rule hit in AppCtrl-URLFltr...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17121#M2875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anyone have a rule that just stops getting hits in the&amp;nbsp;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;AppCtrl-URLFltr&lt;/SPAN&gt; blade?&amp;nbsp; I have hits for pornography/gambling categorization etcetera that have just stopped being blocked and are not logged as a block, obviously (domains categorized and verified) as when I test to some of these sites I have access/page loads...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyone else see a rule just "drop"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 17:28:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17121#M2875</guid>
      <dc:creator>Lloyd_Barnett</dc:creator>
      <dc:date>2017-12-07T17:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Loss of a rule hit in AppCtrl-URLFltr...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17122#M2876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have Website Categorization Mode set to "Hold" or "Background"?&amp;nbsp; How many total filtered users do you have?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My Book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; Second Edition Coming Soon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 18:10:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17122#M2876</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-12-07T18:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: Loss of a rule hit in AppCtrl-URLFltr...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17123#M2877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Categorization is set to "background" and we don't do filtered users (presuming some kind of ID awareness?) but do hope to kluge that up too someday...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did try throwing all six copies we have of your book at it, and it only knocked over the monitor...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 20:07:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17123#M2877</guid>
      <dc:creator>Lloyd_Barnett</dc:creator>
      <dc:date>2017-12-07T20:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: Loss of a rule hit in AppCtrl-URLFltr...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17124#M2878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a chance that a more generic rule got placed above&amp;nbsp;it in the AppCtrl policy that is now matching that traffic? If you look in SmartLog you should be able to see what App Control rule was matched when the traffic was allowed. Is that rule above the Drop / Block rule in question?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 21:34:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17124#M2878</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2017-12-07T21:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Loss of a rule hit in AppCtrl-URLFltr...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17125#M2879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe I have the same situation.&lt;/P&gt;&lt;P&gt;I've noticed that all categories that have only 'url filtering' blade are without applications. I don't remember if this is indeed the correct behavior. I don't think so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61273_cat.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know what that is about?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 22:01:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17125#M2879</guid>
      <dc:creator>Kurt_Lee</dc:creator>
      <dc:date>2017-12-07T22:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: Loss of a rule hit in AppCtrl-URLFltr...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17126#M2880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the firewall's rad process is having problems you will see behavior like this (and slow initial page loads), can I assume you are running the latest GA Jumbo HFA for R77.30 or R80.10?&amp;nbsp; This is extensively covered in second edition of my book, does &lt;STRONG&gt;cpwd_admin list&lt;/STRONG&gt; show rad getting restarted?&amp;nbsp; For R77.30 especially there were a lot of problems with rad fixed by the jumbo HFA.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My Book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; Second Edition Coming Soon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 22:15:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17126#M2880</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-12-07T22:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: Loss of a rule hit in AppCtrl-URLFltr...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17127#M2881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nope that's normal, that particular category is all about inappropriate content (not a specific application) which is what URL Filtering is for, not App control.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My Book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; Second Edition Coming Soon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Dec 2017 22:18:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17127#M2881</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-12-07T22:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Loss of a rule hit in AppCtrl-URLFltr...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17128#M2882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answer! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2017 00:06:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17128#M2882</guid>
      <dc:creator>Kurt_Lee</dc:creator>
      <dc:date>2017-12-08T00:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Loss of a rule hit in AppCtrl-URLFltr...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17129#M2883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RAD is running -as other rules are getting hit, just these (2) particular rules refuse to uphold the law.&amp;nbsp; I stopped and restarted RAD just for kicks and giggles, I also did by alternating "fail-open" and "fail-safe" and no changes there.&amp;nbsp; As for rules, we've removed and then added and moved but no change.&amp;nbsp; No rules catch it above -I even pushed to the top.&amp;nbsp; A couple of items missed Tim, you reminded me to have conveyed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Management R77.20&lt;/P&gt;&lt;P&gt;Gateways R77.30 JHF (take 286)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 15:17:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17129#M2883</guid>
      <dc:creator>Lloyd_Barnett</dc:creator>
      <dc:date>2017-12-12T15:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Loss of a rule hit in AppCtrl-URLFltr...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17130#M2884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Um, isn't it not supported to have the SMS be an older minor release than that gateway?&amp;nbsp; There weren't too many changes to APCL/URLF policies from R77.20 to R77.30 but that seems odd.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My Book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; Second Edition Coming Soon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 17:38:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17130#M2884</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-12-12T17:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Loss of a rule hit in AppCtrl-URLFltr...</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17131#M2885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought this changed in R77x where you can "manage up" from Manager to Gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears the issue has something to do with -and I'm gonna write this out with some skepticism, you'll just have to take it as gospel:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;(domains).checkpoint.com changed IPs at some point&lt;/LI&gt;&lt;LI&gt;our implied rule to allow access to said domains was pushed down in the order of implied rules&lt;UL&gt;&lt;LI&gt;this is due to us running traditional VPN (??? -I'm gonna have to research the "how and why" on that one)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;rejection of the site's access and intermittent updating this crippled&amp;nbsp;&lt;EM&gt;for some odd reason&lt;/EM&gt; JUST these two rules&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...I also believe there was a third gunman, does that seem to jive (I at least get the issue of not getting updates)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LDB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2018 03:17:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Loss-of-a-rule-hit-in-AppCtrl-URLFltr/m-p/17131#M2885</guid>
      <dc:creator>Lloyd_Barnett</dc:creator>
      <dc:date>2018-02-20T03:17:01Z</dc:date>
    </item>
  </channel>
</rss>

