<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Application Control not enforced in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Application-Control-not-enforced/m-p/48998#M9600</link>
    <description>&lt;P&gt;All logs are with same source, user, destination, FW. Its within one minute from eachother.&lt;/P&gt;&lt;P&gt;1. Non working HTTPS session: resource is "test.filtered.com".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-HTTPS-NO-FILT.png" style="width: 809px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/507iC816644219218F1C/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-HTTPS-NO-FILT.png" alt="APP-HTTPS-NO-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Working HTTPS session: resource is "test.filtered.com".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-HTTPS-WORK-FILT.PNG" style="width: 794px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/508iE2E007F2C9779B9B/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-HTTPS-WORK-FILT.PNG" alt="APP-HTTPS-WORK-FILT.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3. Non working firewall rule (This one doesnt has a session, Why?).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-FW1-NO-FILT.png" style="width: 794px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/506i4C5BFDDF608FE2DD/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-FW1-NO-FILT.png" alt="APP-FW1-NO-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;4. Working Firewall Rule. (this one has a session, Why?)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-FW1-WORK-FILT.png" style="width: 861px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/509iF5C74604585731A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-FW1-WORK-FILT.png" alt="APP-FW1-WORK-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;5. See this matches cleanup rule. (Non working)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-FW2-NO-FILT.png" style="width: 794px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/510i7C6A75EB06D7CADE/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-FW2-NO-FILT.png" alt="APP-FW2-NO-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;6. See this matches the application rule. (working)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-FW2-WORK-FILT.png" style="width: 859px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/511i2A2475842271EE76/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-FW2-WORK-FILT.png" alt="APP-FW2-WORK-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;7. this is the Session of the owrking one. Application is made by ACST and it matches based on 2 scenarions "*.filtered.com" (wildcard cert) and "test.filtered.com" as common name. This is the same resource as mentioned in both https inspection logs and also the subject/CN when going to the Server and checking the cert provided.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-FW3-WORK-FILT.png" style="width: 823px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/512i22E508283804E9ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-FW3-WORK-FILT.png" alt="APP-FW3-WORK-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Mar 2019 09:58:21 GMT</pubDate>
    <dc:creator>Filip_Wennerhul</dc:creator>
    <dc:date>2019-03-28T09:58:21Z</dc:date>
    <item>
      <title>Application Control not enforced</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-Control-not-enforced/m-p/48682#M9538</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Could someone shed some light in why the application control might be enforced in some ways but not in others.&lt;/P&gt;&lt;P&gt;* Version R80.10&lt;/P&gt;&lt;P&gt;* All sites are through HTTPS.&lt;/P&gt;&lt;P&gt;* SSL decryption is activated.&lt;/P&gt;&lt;P&gt;* All Sites are bypassed by SSL decryption&lt;/P&gt;&lt;P&gt;* Firewalls are not using probe Bypass (so the traffic should be inspected first?)&lt;/P&gt;&lt;P&gt;* All sites seem to be correctly categorized in the https log. (as a Custom application/Site with correct Url)&lt;/P&gt;&lt;P&gt;* The traffic is not hitting the firewall rules with said application (custom Site)&lt;/P&gt;&lt;P&gt;Why is the firewall not enforcing it when https inspection is detecting the correct site? (does it have to be inspected even though it can detect the application?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also Tried checkpoint ACST and created a signature for some of the sites using CN. These rules seem to hit the application rule some times and sometimes not.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be the cause of this? The https inspection is once again detecting and categorizing the application correctly every time but only stopping the traffic sometimes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 16:05:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-Control-not-enforced/m-p/48682#M9538</guid>
      <dc:creator>Filip_Wennerhul</dc:creator>
      <dc:date>2019-03-26T16:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: Application Control not enforced</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-Control-not-enforced/m-p/48712#M9539</link>
      <description>Logs of accepted and dropped traffic may be helpful, along with screenshots of the rules referenced in the logs.&lt;BR /&gt;&lt;BR /&gt;Also note that sometimes web applications can use different URLs, or even the same site may, at times, present different certificate CNs.&lt;BR /&gt;So it's possible more specific rules are required.</description>
      <pubDate>Tue, 26 Mar 2019 17:40:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-Control-not-enforced/m-p/48712#M9539</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-26T17:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Application Control not enforced</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-Control-not-enforced/m-p/48998#M9600</link>
      <description>&lt;P&gt;All logs are with same source, user, destination, FW. Its within one minute from eachother.&lt;/P&gt;&lt;P&gt;1. Non working HTTPS session: resource is "test.filtered.com".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-HTTPS-NO-FILT.png" style="width: 809px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/507iC816644219218F1C/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-HTTPS-NO-FILT.png" alt="APP-HTTPS-NO-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Working HTTPS session: resource is "test.filtered.com".&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-HTTPS-WORK-FILT.PNG" style="width: 794px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/508iE2E007F2C9779B9B/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-HTTPS-WORK-FILT.PNG" alt="APP-HTTPS-WORK-FILT.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3. Non working firewall rule (This one doesnt has a session, Why?).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-FW1-NO-FILT.png" style="width: 794px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/506i4C5BFDDF608FE2DD/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-FW1-NO-FILT.png" alt="APP-FW1-NO-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;4. Working Firewall Rule. (this one has a session, Why?)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-FW1-WORK-FILT.png" style="width: 861px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/509iF5C74604585731A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-FW1-WORK-FILT.png" alt="APP-FW1-WORK-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;5. See this matches cleanup rule. (Non working)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-FW2-NO-FILT.png" style="width: 794px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/510i7C6A75EB06D7CADE/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-FW2-NO-FILT.png" alt="APP-FW2-NO-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;6. See this matches the application rule. (working)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-FW2-WORK-FILT.png" style="width: 859px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/511i2A2475842271EE76/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-FW2-WORK-FILT.png" alt="APP-FW2-WORK-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;7. this is the Session of the owrking one. Application is made by ACST and it matches based on 2 scenarions "*.filtered.com" (wildcard cert) and "test.filtered.com" as common name. This is the same resource as mentioned in both https inspection logs and also the subject/CN when going to the Server and checking the cert provided.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="APP-FW3-WORK-FILT.png" style="width: 823px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/512i22E508283804E9ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="APP-FW3-WORK-FILT.png" alt="APP-FW3-WORK-FILT.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 09:58:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-Control-not-enforced/m-p/48998#M9600</guid>
      <dc:creator>Filip_Wennerhul</dc:creator>
      <dc:date>2019-03-28T09:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Application Control not enforced</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-Control-not-enforced/m-p/50742#M10043</link>
      <description>&lt;P&gt;Bump. Does bypassing SSL inspection hamper recognization or should it work the same was as when inspected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 11:56:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-Control-not-enforced/m-p/50742#M10043</guid>
      <dc:creator>Filip_Wennerhul</dc:creator>
      <dc:date>2019-04-12T11:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Application Control not enforced</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Application-Control-not-enforced/m-p/50745#M10044</link>
      <description>&lt;P&gt;How does Application and url filter work exactly. Do you have a good source thats collecting all the scenarios for when and how it filters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTTP traffic checks the URL from the GET/POST? True/False&lt;/P&gt;&lt;P&gt;HTTPS check the Certificate CN?&amp;nbsp;True/False&lt;/P&gt;&lt;P&gt;Custom Site with "example.com" matches "&lt;A href="http://www.example.com" target="_blank"&gt;www.example.com&lt;/A&gt;", "example.com" and "example.com/tes/b.htm" but not "mail.example.com" for HTTP? True /False&lt;/P&gt;&lt;P&gt;Custom Site with "example.com/tes/ff/" matches "example.com/tes/ff/", "example.com/tes/ff/b.htm" and "&lt;A href="http://www.example.com/tes/ff/sce/tt/g.htm" target="_blank"&gt;www.example.com/tes/ff/sce/tt/g.htm&lt;/A&gt;" but not "example.com" for HTTP? True /False&lt;/P&gt;&lt;P&gt;Custom site with "*.example.com" matches URLS(HTTP) and CN(Cert) for "mail.example.com" and "ftp.example.com/tes/b.htm" but not "example.com" or *.example.com?&lt;/P&gt;&lt;P&gt;Wildcard Cert does not work unless using ACST with adding "*.example.com" as CN? True/False&amp;nbsp;&lt;/P&gt;&lt;P&gt;During a redirect site you must both add "example.com" and "newexamplesite.com" to the custom site? True/False&lt;/P&gt;&lt;P&gt;During a redirect site with a wildcard cert you must both add a custom site with "example.com" and using ACST adding "*.newexamplesite.com"? True/False&lt;/P&gt;&lt;P&gt;Do you know the answers to these questions or can point me to where i can find the answers to these? From what i have learned through SK and testing my opinion is that all of these are true. Have i understood it correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 12:38:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Application-Control-not-enforced/m-p/50745#M10044</guid>
      <dc:creator>Filip_Wennerhul</dc:creator>
      <dc:date>2019-04-12T12:38:52Z</dc:date>
    </item>
  </channel>
</rss>

