<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web Advertisements drop in R80.10 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27129#M5535</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Offhand I do not, but I did inquire internally with R&amp;amp;D about it and they suggested opening a task regarding the issue.&lt;/P&gt;&lt;P&gt;If you can send me the SR number privately, I'll make sure the dots are connected on the backend.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Feb 2018 16:23:59 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-02-07T16:23:59Z</dc:date>
    <item>
      <title>HTTPS drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27124#M5530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm experiencing an strange issue after Gateway upgrade to R80.10 (T56 now) on Open Server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Previously when blocking Web Advertisements category on R77.30 all work fine with one "&lt;STRONG&gt;&lt;EM&gt;Block and show usercheck&lt;/EM&gt;&lt;/STRONG&gt;" rule. After upgrade to R80.10, the same rule was applied, and since Block option does not exists on the new architecture for APC and URL Filter, the option was replaced to drop instead.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="62766" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62766_pastedImage_11.png" style="width: 620px; height: 29px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put you an example using the &lt;STRONG&gt;&lt;EM&gt;Drop&lt;/EM&gt;&lt;/STRONG&gt; option. There is a news site &lt;A href="http://www.eldeber.com.bo"&gt;www.eldeber.com.bo&lt;/A&gt; where embedded advertising exists. When I open a link of a report inside the site, the page remains loading forever in blank despite the news is already received (pressing F5 the report is showed on screen briefly). All this is because HTTPS advertising, according to the Logs, and it seems the session is still trying to establish despite the drop rule.&lt;/P&gt;&lt;P&gt;I got similar error on &lt;A href="http://www.amazon.com"&gt;www.amazon.com&lt;/A&gt;&amp;nbsp; and some other sites with embedded advertising.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a workaround, what I had to do was create an inline layer for Web Advertisements and choose &lt;EM&gt;&lt;STRONG&gt;Reject&lt;/STRONG&gt;&lt;/EM&gt; for HTTPS and HTTPS_proxy. After this, the sites with embedded advertising load normally (I did the same test with the sites mentioned above).&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="62764" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62764_pastedImage_9.png" style="width: 620px; height: 58px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: line-through;"&gt;So far, Web Advertisements is the only category who give me problems, but perahps this behavior reproduces in other categories.&lt;/SPAN&gt; This issue is reproduced on all categories where the action for HTTPS is Drop; and specially on those sites who point to external content Droped somehow by the policy. Would be great if can test this for yourself's and verify why the problem only reproduces when using drop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Feb 2018 20:57:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27124#M5530</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-02-01T20:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: Web Advertisements drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27125#M5531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What if you change the action to Reject in the top-level rule?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Feb 2018 21:11:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27125#M5531</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-01T21:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Web Advertisements drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27126#M5532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It works, but cannot show UserCheck message for HTTP traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Feb 2018 21:13:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27126#M5532</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-02-01T21:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Web Advertisements drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27127#M5533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like this is a known bug and you should open a TAC case for a potential fix to this.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://www.checkpoint.com/support-services/contact-support/" title="http://www.checkpoint.com/support-services/contact-support/"&gt;Contact Support | Check Point Software&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Feb 2018 14:14:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27127#M5533</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-05T14:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Web Advertisements drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27128#M5534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dameon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a bug ID to search it?&lt;/P&gt;&lt;P&gt;I will open a TAC case to further review.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2018 03:49:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27128#M5534</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-02-07T03:49:33Z</dc:date>
    </item>
    <item>
      <title>Re: Web Advertisements drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27129#M5535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Offhand I do not, but I did inquire internally with R&amp;amp;D about it and they suggested opening a task regarding the issue.&lt;/P&gt;&lt;P&gt;If you can send me the SR number privately, I'll make sure the dots are connected on the backend.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2018 16:23:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27129#M5535</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-07T16:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Web Advertisements drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27130#M5536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the client gets a REJECT the client knows it doesn't work and it will now it fast.&lt;/P&gt;&lt;P&gt;If you silently drop the SYN packet it is up to the client to retry a few times before giving up. This will give you a terrible penalty in the user experience.&lt;/P&gt;&lt;P&gt;As a rule of thumb I would considere to DROP anything from the outside that I don't want to allow. And REJECT anything from the inside that I don't want to allow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While some auditers may not approve I find it saves your users a lot time as they get an error very fast if you block them and they don't have to wait for the timeouts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 17:01:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27130#M5536</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-03-02T17:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Web Advertisements drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27131#M5537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Hugo.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are absolutely right about the drop and reject behaviors. However, some things like this must be modified if you update from R77.30 (where all work without this issues). Also I noticed this strange case is not only in Web Advertisements category but in some others like Social Networking or Media Streams (Peraphs for all dropped apps in R80.10??)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know the exact behavior of Block in R77.30 App rulebase? Remember this option does not exists in R80.10 App rulebase.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 19:41:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27131#M5537</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-03-02T19:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: Web Advertisements drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27132#M5538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kenny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it's on my todo list somewhere. Unfortunalty not on page 1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Mar 2018 09:28:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27132#M5538</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-03-05T09:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Web Advertisements drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27133#M5539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you open a TAC SR like I suggested above?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Mar 2018 14:23:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27133#M5539</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-05T14:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Web Advertisements drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27134#M5540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I was a little busy with other SR's for customers.&lt;/P&gt;&lt;P&gt;I will open the SR once the others had been closed.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 19:04:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27134#M5540</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-03-06T19:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Web Advertisements drop in R80.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27135#M5541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check Point published an official SK documentation for this behavior on Sep 2018 using my Reject workaround as one of the solutions (I'm waiting for sk modification with special thanks &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;sk135132: &lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk135132" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk135132"&gt;Websites take time to load when certain applications/links in APPI/URL Filtering rule base are blocked&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this be useful to all.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Mar 2019 19:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-drop-in-R80-10/m-p/27135#M5541</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2019-03-07T19:34:07Z</dc:date>
    </item>
  </channel>
</rss>

