<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic APPC and URLF on SMB appliances in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/APPC-and-URLF-on-SMB-appliances/m-p/46636#M1797</link>
    <description>&lt;P&gt;Hi guys!&lt;BR /&gt;&lt;BR /&gt;I'm having a hard time configuring a navigation policy on a SMB appliance. It's really not working as intended as far as i'm concerned.&lt;BR /&gt;&lt;BR /&gt;I was wandering if a good practice would be to allow "network protocols" category as it contains OCSP, NCSI, ssl, and other network protocols designed for navigation but im worried if this would allow pages i dont want to allow.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I also find it works kinda randomly and sometimes i dont really dig how it works, sometimes it matches an application, sometimes the same petition does not match the application.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Lan Networks as a source should match identity awareness connections?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should i place a rule allowing "network protocols"?&lt;/P&gt;&lt;P&gt;Does anyone has any expirience on this and has already a template/good practice for nailing this?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 20:20:56 GMT</pubDate>
    <dc:creator>Juan_Lobera</dc:creator>
    <dc:date>2019-03-12T20:20:56Z</dc:date>
    <item>
      <title>APPC and URLF on SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/APPC-and-URLF-on-SMB-appliances/m-p/46636#M1797</link>
      <description>&lt;P&gt;Hi guys!&lt;BR /&gt;&lt;BR /&gt;I'm having a hard time configuring a navigation policy on a SMB appliance. It's really not working as intended as far as i'm concerned.&lt;BR /&gt;&lt;BR /&gt;I was wandering if a good practice would be to allow "network protocols" category as it contains OCSP, NCSI, ssl, and other network protocols designed for navigation but im worried if this would allow pages i dont want to allow.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I also find it works kinda randomly and sometimes i dont really dig how it works, sometimes it matches an application, sometimes the same petition does not match the application.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Lan Networks as a source should match identity awareness connections?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should i place a rule allowing "network protocols"?&lt;/P&gt;&lt;P&gt;Does anyone has any expirience on this and has already a template/good practice for nailing this?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 20:20:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/APPC-and-URLF-on-SMB-appliances/m-p/46636#M1797</guid>
      <dc:creator>Juan_Lobera</dc:creator>
      <dc:date>2019-03-12T20:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: APPC and URLF on SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/APPC-and-URLF-on-SMB-appliances/m-p/46679#M1798</link>
      <description>&lt;DIV class="cp_h2_black"&gt;&lt;SPAN&gt;I think it is quite tough to block and allow all websites. If you read sk112249:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112249&amp;amp;partition=General&amp;amp;product=Application" target="_self"&gt;Best Practices - Application Control &lt;/A&gt;It would be helpful..&lt;/DIV&gt;&lt;DIV class="cp_h2_black"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="cp_link_block"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 13 Mar 2019 04:46:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/APPC-and-URLF-on-SMB-appliances/m-p/46679#M1798</guid>
      <dc:creator>Gomboragchaa</dc:creator>
      <dc:date>2019-03-13T04:46:21Z</dc:date>
    </item>
  </channel>
</rss>

