<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Want help with traffic blocking from one side in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27048#M1151</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which means this is really an SMB question, so let's move it to the correct space: &lt;A href="https://community.checkpoint.com/space/2036"&gt;SMB and SMP&lt;/A&gt;‌&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 16 Sep 2018 16:26:45 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-09-16T16:26:45Z</dc:date>
    <item>
      <title>Want help with traffic blocking from one side</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27038#M1141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi guys, i have 40 computer setup on which online examinations are&amp;nbsp; going on. I want to block internet on all computers so that students cant cheat by looking on internet. but problem is teachers should be able to connect remotely to any computer from outside. is there any way, if so please help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Sep 2018 14:52:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27038#M1141</guid>
      <dc:creator>Satyam_mehrotra</dc:creator>
      <dc:date>2018-09-15T14:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Want help with traffic blocking from one side</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27039#M1142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the model of the gateway/management appliance you are using and the version of the software on it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2018 02:59:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27039#M1142</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-16T02:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Want help with traffic blocking from one side</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27040#M1143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another relevant question: how are the instructors connecting to the computers remotely?&lt;/P&gt;&lt;P&gt;Because that will determine what the policy looks like.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2018 05:37:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27040#M1143</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-16T05:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: Want help with traffic blocking from one side</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27041#M1144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Block http and https during exam, or setup non-working proxy which cannot be changed by students (only teachers - administrators).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2018 07:06:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27041#M1144</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-09-16T07:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Want help with traffic blocking from one side</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27042#M1145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;my UTM is 730 Wireless&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2018 12:50:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27042#M1145</guid>
      <dc:creator>Satyam_mehrotra</dc:creator>
      <dc:date>2018-09-16T12:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Want help with traffic blocking from one side</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27043#M1146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have 730 Wireless UTM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2018 12:51:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27043#M1146</guid>
      <dc:creator>Satyam_mehrotra</dc:creator>
      <dc:date>2018-09-16T12:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: Want help with traffic blocking from one side</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27044#M1147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;through remote desktop connection&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2018 12:52:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27044#M1147</guid>
      <dc:creator>Satyam_mehrotra</dc:creator>
      <dc:date>2018-09-16T12:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Want help with traffic blocking from one side</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27045#M1148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We should really know how the exam is being administered.&lt;/P&gt;&lt;P&gt;If it is a browser-based exam and the PCs should be able to access the resources outside to run it, we cannot simply block HTTP/HTTPS. You should define custom site and permit access to it using URLF/App Control in the rule above that preventing HTTP(S) access to other sites.&lt;/P&gt;&lt;P&gt;Remote administration of PCs could be accomplished by either configuring a mobile access for the teacher, to connect tot the gateway via VPN and running RDP to the PCs, or by deploying a jump host, like&amp;nbsp;&lt;A class="link-titled" href="https://guacamole.apache.org/" title="https://guacamole.apache.org/"&gt;Apache Guacamole™&lt;/A&gt;&amp;nbsp; ,configuring it to run on custom port not conflicting with any of Check Point services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Create custom HTTPS service:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" height="318" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70343_pastedImage_3.png" width="347" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Create these objects:&lt;/P&gt;&lt;P&gt;a dummy object with Gateway's external IP:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" height="201" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70344_pastedImage_4.png" width="358" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and a real object for the JumpHost:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" height="211" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70346_pastedImage_6.png" width="372" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;students's network:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-5 jive-image" height="402" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70348_pastedImage_8.png" width="331" /&gt;&amp;nbsp;&amp;nbsp;&lt;IMG class="image-6 jive-image" height="325" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70349_pastedImage_9.png" width="366" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;custom Site:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-7 jive-image" height="454" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70350_pastedImage_10.png" width="483" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and Test Time(s):&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-8" height="537" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70351_pastedImage_11.png" width="492" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Configure NAT rules:&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70347_pastedImage_7.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Enable "Time" column in the Policy view:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-9 jive-image" height="257" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70352_pastedImage_12.png" width="313" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. And configure the access rules:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-10" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70353_pastedImage_13.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should do it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2018 13:18:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27045#M1148</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-16T13:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: Want help with traffic blocking from one side</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27046#M1149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any way to connect through anydesk type software.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2018 14:17:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27046#M1149</guid>
      <dc:creator>Satyam_mehrotra</dc:creator>
      <dc:date>2018-09-16T14:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Want help with traffic blocking from one side</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27047#M1150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what I understand, it relies on unrestricted HTTPS connectivity from the clients, so this would likely be difficult to achieve.&lt;/P&gt;&lt;P&gt;You can try creating a custom site/URL with their site in it, permitting the traffic to it and to DNS from the students' PCs and restricting their access to anything else in the rule below to see if it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This scenario assumes that there is no Active Directory with recursive DNS server in place.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2018 14:49:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27047#M1150</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-16T14:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Want help with traffic blocking from one side</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27048#M1151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which means this is really an SMB question, so let's move it to the correct space: &lt;A href="https://community.checkpoint.com/space/2036"&gt;SMB and SMP&lt;/A&gt;‌&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Sep 2018 16:26:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/m-p/27048#M1151</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-16T16:26:45Z</dc:date>
    </item>
  </channel>
</rss>

