<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ordering bypass rules in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ordering-bypass-rules/m-p/53048#M2078</link>
    <description>&lt;P&gt;I failed to comment that it is possible to access these sites and navigate through them, but the error of time-out constantly appears.&lt;/P&gt;&lt;P&gt;Even, although less consistently, I already reported that the error is already presented with the gmail portal, which is one of the most used in the company.&lt;/P&gt;&lt;P&gt;Tonight I will run the fw monitor to be able to answer your question, although it will not be with the normal traffic load.&lt;/P&gt;</description>
    <pubDate>Thu, 09 May 2019 17:32:38 GMT</pubDate>
    <dc:creator>LuisSP</dc:creator>
    <dc:date>2019-05-09T17:32:38Z</dc:date>
    <item>
      <title>Ordering bypass rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ordering-bypass-rules/m-p/52836#M2075</link>
      <description>&lt;P&gt;Hello checkmates! I've a client with NGFW 1490, blades enables are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;AppCtrl &amp;amp; UrlF&lt;/LI&gt;&lt;LI&gt;UsrAw&lt;/LI&gt;&lt;LI&gt;IPS&lt;/LI&gt;&lt;LI&gt;AV&lt;/LI&gt;&lt;LI&gt;AB&lt;/LI&gt;&lt;LI&gt;VPN RemAcc&lt;/LI&gt;&lt;LI&gt;Beside https categorization&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The&amp;nbsp;Version is : R77.20.85 (990172755).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently I have activated SSL-inspection, which&amp;nbsp;was activated some time ago for a short period of time because drawbacks during browsing on internet.&lt;/P&gt;&lt;P&gt;Nowadays, the problems previously presented mostly resolved with the build&amp;nbsp;990172755 (I know that exist update R77.20.86).&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, now there is a new issue, some https web sites shown time-out errors on browsers (chrome, mozilla, edge),&amp;nbsp; Such error don't been show before, that's mean with ssl-inspection disable.&lt;/P&gt;&lt;P&gt;DNS server is local. Inclusive I put in file HOST (pc's windows) the ip addres and domain name of trouble's web sites to resolve locally on client, but issue persist.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lastly, I put a exception to these web sites, but I don't think that is best idea.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help me please?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 01:21:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ordering-bypass-rules/m-p/52836#M2075</guid>
      <dc:creator>LuisSP</dc:creator>
      <dc:date>2019-05-08T01:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Ordering bypass rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ordering-bypass-rules/m-p/52956#M2076</link>
      <description>Are these HTTPS sites by chance that might be blocked by your policy?&lt;BR /&gt;Any clues in the logs or using tcpdump/fw monitor?</description>
      <pubDate>Thu, 09 May 2019 00:34:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ordering-bypass-rules/m-p/52956#M2076</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-09T00:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Ordering bypass rules</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ordering-bypass-rules/m-p/53048#M2078</link>
      <description>&lt;P&gt;I failed to comment that it is possible to access these sites and navigate through them, but the error of time-out constantly appears.&lt;/P&gt;&lt;P&gt;Even, although less consistently, I already reported that the error is already presented with the gmail portal, which is one of the most used in the company.&lt;/P&gt;&lt;P&gt;Tonight I will run the fw monitor to be able to answer your question, although it will not be with the normal traffic load.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 17:32:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Ordering-bypass-rules/m-p/53048#M2078</guid>
      <dc:creator>LuisSP</dc:creator>
      <dc:date>2019-05-09T17:32:38Z</dc:date>
    </item>
  </channel>
</rss>

