<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inconsistent URL filtering in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Inconsistent-URL-filtering/m-p/271193#M13681</link>
    <description>&lt;P&gt;Btw, see if this post I made about my lab setup helps.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-lab-video/td-p/270644" target="_blank"&gt;https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-lab-video/td-p/270644&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Feb 2026 03:21:48 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2026-02-18T03:21:48Z</dc:date>
    <item>
      <title>Inconsistent URL filtering</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Inconsistent-URL-filtering/m-p/271144#M13678</link>
      <description>&lt;P&gt;Firewall: 1900/2000 Appliance running version R81.10 with Application Control and URL Filtering enabled, as well as HTTPS-inspection. Obligatory heads-up, I am not an expert (or even intermediate) when it comes to networking and checkpoint.&lt;/P&gt;&lt;P&gt;Hi there checkmates,&lt;/P&gt;&lt;P&gt;We're trying to configure a firewall for a highly-regulated, mostly closed environment (meaning only specific software and addresses may be accessed from the internal network). To this end, we try to regulate access mostly based on custom applications/sites and built-in updatable objects. However, we've found something that seems quite inconsistent; the exact same url that is both allowed and blocked in two separate instances.&lt;/P&gt;&lt;P&gt;We are allowing traffic to the source&amp;nbsp;&lt;SPAN&gt;'api\.github\.com/repos/hashicorp/packer-plugin-vsphere/git/matching-refs/tags.*' (defined as a regex), but this is what we observed below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint_weird_filtering.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33371i6CCCC87AFF38609D/image-size/large?v=v2&amp;amp;px=999" role="button" title="checkpoint_weird_filtering.png" alt="checkpoint_weird_filtering.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Both these instances happen near-simultaneously. The rules were not changed in that short time (we've checked). We did see that both instances went to a different host (140.82.121.3 and ".6 respectively), but all hosts are allowed in this rule as long as the url matches, so this should not make a difference. Furthermore, in the Policy menu it shows both as blocked by the cleanup rule, even though one is still allowed. Does anyone here have an inkling as to what is going on here?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2026 15:58:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Inconsistent-URL-filtering/m-p/271144#M13678</guid>
      <dc:creator>AB136785</dc:creator>
      <dc:date>2026-02-17T15:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent URL filtering</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Inconsistent-URL-filtering/m-p/271158#M13679</link>
      <description>&lt;P&gt;Details tab of both screenshot would be to get better understanding.&lt;/P&gt;
&lt;P&gt;My guess is, first some data needs to pass / be allowed before the firewall can make the good policy decision.&lt;/P&gt;
&lt;P&gt;Could also be that the website has not yet been categorized and therefore is not present in the cache of the gateway. There are 2 settings, hold and background. Default is background and hold is more strict. It will hold the connection until the gateway gets the message from the cloud what category the URL is. Background is, first connections are allowed, in the mean time gw connects to cloud and gets the info and from that point it will be blocked. The data will then be added to gateway cache.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2026 18:53:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Inconsistent-URL-filtering/m-p/271158#M13679</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-02-17T18:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent URL filtering</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Inconsistent-URL-filtering/m-p/271164#M13680</link>
      <description>&lt;P&gt;I see the answer to your question on the left screenshot. Yes, shows accepted on network layer, but then shows inspect, which is on ssl inspection policy, which would essentially block it.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2026 19:53:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Inconsistent-URL-filtering/m-p/271164#M13680</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-17T19:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent URL filtering</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Inconsistent-URL-filtering/m-p/271193#M13681</link>
      <description>&lt;P&gt;Btw, see if this post I made about my lab setup helps.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-lab-video/td-p/270644" target="_blank"&gt;https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-inspection-lab-video/td-p/270644&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 03:21:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Inconsistent-URL-filtering/m-p/271193#M13681</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-18T03:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Inconsistent URL filtering</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Inconsistent-URL-filtering/m-p/271278#M13682</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Were you able to sort this out?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 03:31:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Inconsistent-URL-filtering/m-p/271278#M13682</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-19T03:31:24Z</dc:date>
    </item>
  </channel>
</rss>

