<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security policy inconsistently applied when using Proxy in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Security-policy-inconsistently-applied-when-using-Proxy/m-p/26443#M5376</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't see a &lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/4998-how-to-create-a-custom-application-with-custom-services"&gt;custom web application&lt;/A&gt; for the website &lt;A href="http://www.teamviewer.om"&gt;www.teamviewer.com &lt;/A&gt;in your rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Sep 2018 22:10:10 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2018-09-12T22:10:10Z</dc:date>
    <item>
      <title>Security policy inconsistently applied when using Proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Security-policy-inconsistently-applied-when-using-Proxy/m-p/26440#M5373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have an application layer which allows access to TeamViewer for members of an AD security group:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70224_team_viewer.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything works perfectly, in that users that are members of this security group can use both the TeamViewer application and navigate to &lt;A href="http://www.teamviewer.com"&gt;www.teamviewer.com&lt;/A&gt;&amp;nbsp;whilst others can't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we however then configure an explicit proxy, the application continues to work but members of this security group can no longer navigate to &lt;A href="http://www.teamviewer.com"&gt;www.teamviewer.com&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something or should I log this with TAC?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 21:06:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Security-policy-inconsistently-applied-when-using-Proxy/m-p/26440#M5373</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-12T21:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy inconsistently applied when using Proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Security-policy-inconsistently-applied-when-using-Proxy/m-p/26441#M5374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Teamviewer application will always try to find ways through your network to successfully reach the internet.&lt;/P&gt;&lt;P&gt;To identify users behind a proxy to the firewall, the proxy must be configured to add the &lt;A href="https://en.wikipedia.org/wiki/X-Forwarded-For"&gt;X-Forwarded-For (XFF)&lt;/A&gt; flag to the connections. Only then the rule can match as the user identification succeeds. Check Point can delete the XFF flag within the IA settings of your gateway object.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 21:46:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Security-policy-inconsistently-applied-when-using-Proxy/m-p/26441#M5374</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-09-12T21:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy inconsistently applied when using Proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Security-policy-inconsistently-applied-when-using-Proxy/m-p/26442#M5375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The opposite is however true, users that are members of the AD security group are NOT able to access the &lt;A href="http://www.teamviewer.com"&gt;www.teamviewer.com&lt;/A&gt;&amp;nbsp;website whilst they can use the application. Reviewing log records for the rule correctly matches against packets from the application but requests for the website are blocked on a subsequent rule which denies access using the 'Remote Administration' categorisation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Disabling the explicit proxy and sending traffic directly results in everything working as it should, users that are members of the security group can use the application and browse to the &lt;A href="http://www.teamviewer.com"&gt;www.teamviewer.com&lt;/A&gt;&amp;nbsp;website.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ie: Browsing to &lt;A href="http://www.teamviewer.com"&gt;www.teamviewer.com&lt;/A&gt;, when configuring the browser to send connections DIRECTLY to the security gateway's proxy port, does not match the 'TeamViewer' application in a policy rule whilst it does when one disables the proxy settings in the browser.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 22:02:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Security-policy-inconsistently-applied-when-using-Proxy/m-p/26442#M5375</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-12T22:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy inconsistently applied when using Proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Security-policy-inconsistently-applied-when-using-Proxy/m-p/26443#M5376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't see a &lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/4998-how-to-create-a-custom-application-with-custom-services"&gt;custom web application&lt;/A&gt; for the website &lt;A href="http://www.teamviewer.om"&gt;www.teamviewer.com &lt;/A&gt;in your rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 22:10:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Security-policy-inconsistently-applied-when-using-Proxy/m-p/26443#M5376</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-09-12T22:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy inconsistently applied when using Proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Security-policy-inconsistently-applied-when-using-Proxy/m-p/26444#M5377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not aware of a requirement to specifically list sites when using the proxy interface on a Check Point security gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I do not configure the security gateway as an explicit proxy and navigate to &lt;A href="http://www.teamviewer.com"&gt;www.teamviewer.com&lt;/A&gt;&amp;nbsp;via a web browser the site is correctly associated with the rule:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70240_teamviewer.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If all I subsequently do is point the browser directly at the Check Point security gateway's proxy interface, browsing sessions to &lt;A href="http://www.teamviewer.com"&gt;www.teamviewer.com&lt;/A&gt;&amp;nbsp;are not matched by the rule that references the TeamViewer application. Herewith the log record from the subsequent rule which blocks Remote Administration category for everyone else in the network:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70241_teamviewer2.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-3 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70242_teamviewer3.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS: We've been using Squid for 20+ years and are used to referencing a proxy on port 3128. We subsequently configured the Check Point Security Gateway to listen on this port as well. There are NO intermediary proxy servers between the browser and the security gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 07:03:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Security-policy-inconsistently-applied-when-using-Proxy/m-p/26444#M5377</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-13T07:03:09Z</dc:date>
    </item>
  </channel>
</rss>

