<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not Inspected Traffic in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186484#M31144</link>
    <description>&lt;P&gt;There is built in quic application in R81.20 you can use (not sure lower versions). If not, you can do below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk111754" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk111754&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also, I attached how I have it set in my lab. Its only appc+urlf blade in that layer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21748iD4DE6D99E48DF9E6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Fri, 14 Jul 2023 17:39:45 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-07-14T17:39:45Z</dc:date>
    <item>
      <title>Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186475#M31141</link>
      <description>&lt;P&gt;Hello, everyone,&lt;/P&gt;
&lt;P&gt;We are in the process of implementing the IA+APPC&amp;amp;URLF+HTTPS Inspection... blades.&lt;/P&gt;
&lt;P&gt;So far everything seems to be going "fine".&lt;/P&gt;
&lt;P&gt;We are using the IDC for the iA blade.&lt;/P&gt;
&lt;P&gt;We are working with separate layers (1 Firewall layer, 1 APPC+URLF layer).&lt;/P&gt;
&lt;P&gt;The rules are working fine so far, but there are some "alerts".&lt;/P&gt;
&lt;P&gt;We are blocking access to "Social Networking" for a group of users.&lt;/P&gt;
&lt;P&gt;The rule is working, but there is some traffic, such as consumption of the Facebook page, which is not blocked and is allowed to pass.&lt;/P&gt;
&lt;P&gt;We are using a self-signed certificate, which is already deployed to the users by GPO.&lt;/P&gt;
&lt;P&gt;When a user consumes Facebook via web, the page does open (and this should not happen).&lt;/P&gt;
&lt;P&gt;I get the "untrusted site" message from the page, and when I check the certificate, I don't see our certificate, I see the public certificate.&lt;/P&gt;
&lt;P&gt;This behavior is happening on some pages, not all.&lt;/P&gt;
&lt;P&gt;Do you know what steps can be followed in this scenario, to get pages like Facebook blocked?&lt;/P&gt;
&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 15:14:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186475#M31141</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-14T15:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186479#M31142</link>
      <description>&lt;P&gt;Are you using Google Chrome to test or are multiple browsers affected?&lt;/P&gt;
&lt;P&gt;Is Quic traffic blocked or allowed in the environment?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 16:11:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186479#M31142</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-07-14T16:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186480#M31143</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I had not read about "QUIC Traffic", until now.&lt;/P&gt;
&lt;P&gt;Where can I validate that?&lt;/P&gt;
&lt;P&gt;We have tested in 3 browsers, Chrome, Edge, Mozilla.&lt;/P&gt;
&lt;P&gt;They are only for "certain" pages.&lt;BR /&gt;Facebook web, is one of them.&lt;BR /&gt;The rest of the pages, if it is blocking them by the rule created.&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 16:29:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186480#M31143</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-14T16:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186484#M31144</link>
      <description>&lt;P&gt;There is built in quic application in R81.20 you can use (not sure lower versions). If not, you can do below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk111754" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk111754&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also, I attached how I have it set in my lab. Its only appc+urlf blade in that layer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21748iD4DE6D99E48DF9E6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 17:39:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186484#M31144</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-14T17:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186489#M31145</link>
      <description>&lt;P&gt;Hey, bro&lt;/P&gt;
&lt;P&gt;I have version R81.10 in production.&lt;/P&gt;
&lt;P&gt;I'm going to check the SK.&lt;/P&gt;
&lt;P&gt;The weird thing is that it only happens for certain "web pages".&lt;/P&gt;
&lt;P&gt;The rest of the pages are being inspected and blocked according to our policies.&lt;/P&gt;
&lt;P&gt;We have the layers separated (as you can see in the following image)&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IM2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21750i71E4FB7CC49306EC/image-size/large?v=v2&amp;amp;px=999" role="button" title="IM2.png" alt="IM2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IM1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21749i24CC1A23DBE0A723/image-size/large?v=v2&amp;amp;px=999" role="button" title="IM1.png" alt="IM1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 17:48:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186489#M31145</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-14T17:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186503#M31146</link>
      <description>&lt;P&gt;QUIC traffic is not categorized by Check Point.&lt;BR /&gt;There needs to be an explicit rule blocking this service in the Access Policy.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 22:44:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186503#M31146</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-14T22:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186505#M31147</link>
      <description>&lt;P&gt;Hello, PhoneBoy.&lt;/P&gt;
&lt;P&gt;You would have to create an explicit rule in the Firewall layer, denying the "UDP/443" service, which I understand is what the QUIC uses, and also create an explicit rule in the APPC+URLF layer, is this correct?&lt;/P&gt;
&lt;P&gt;Or is it enough just to create the drop rule in the Firewall layer?&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 23:02:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186505#M31147</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-14T23:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186506#M31148</link>
      <description>&lt;P&gt;Fw layer is good bro. Idea is this...whatever is dropped on first layer, there is no more checks. Whatever is accepted on fw layer, it has to be accepted on all additional layers.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 23:05:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186506#M31148</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-14T23:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186507#M31149</link>
      <description>&lt;P&gt;Haaa, Ok.&lt;/P&gt;
&lt;P&gt;So, I can define an explicit rule only in the Firewall layer, something like this:&lt;/P&gt;
&lt;P&gt;Source: Any&lt;BR /&gt;Destination: Any&lt;BR /&gt;Service: QUIC (UDP/443)&lt;BR /&gt;Action: DROP&lt;/P&gt;
&lt;P&gt;With this explicit rule, it would be enough for me to block the famous "QUIC", right?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 23:10:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186507#M31149</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-14T23:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186508#M31150</link>
      <description>&lt;P&gt;Yes sir &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 23:23:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186508#M31150</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-14T23:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186509#M31151</link>
      <description>&lt;P&gt;I will test the recommendation in the work window, because it is very rare that only for certain pages, it does not apply the block filter for web pages.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jul 2023 00:17:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186509#M31151</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-15T00:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: Not Inspected Traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186511#M31152</link>
      <description>&lt;P&gt;Are you able to provide a screenshot of the log card showing that the traffic was allowed?&lt;/P&gt;
&lt;P&gt;(Please redact sensitive information).&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jul 2023 03:26:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Not-Inspected-Traffic/m-p/186511#M31152</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-07-15T03:26:21Z</dc:date>
    </item>
  </channel>
</rss>

