<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic site blocked ....internet server reset connection in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/site-blocked-internet-server-reset-connection/m-p/57176#M2220</link>
    <description>&lt;P&gt;Hi everyone, I've some cases, but I'll post each one separetelly.&lt;/P&gt;&lt;P&gt;I opened traffic to load images from arduino.cc site. Arduino use flickr service to show its images inside the portal.&lt;BR /&gt;First I tried with * .flickr.com and *.staticflickr.com, something similar worked well with other sites, but unfortunately this time it did not work. After a few hours I resolved it with regular expressions:&lt;/P&gt;&lt;P&gt;(^ |. * \.) * staticflickr \ .com&lt;BR /&gt;(^ |. * \.) * flickr \ .com&lt;/P&gt;&lt;P&gt;Now I try to open traffic to &lt;A href="http://www.manageengine.com" target="_blank"&gt;www.manageengine.com&lt;/A&gt;, but no custom application works properly:&lt;/P&gt;&lt;P&gt;* .manageengine.com&lt;BR /&gt;manageengine.com&lt;BR /&gt;(^ |. * \.) * manageengine \ .com (this as a regular expression in another app)&lt;BR /&gt;The browser sends an error ERR_CONNECTION_RESET.&lt;/P&gt;&lt;P&gt;In wireshark I can see that the manageengine.com server resets the connection.&lt;/P&gt;&lt;P&gt;If I open all internet traffic to single local ip address, &lt;A href="http://www.manageengine.com" target="_blank"&gt;www.manageengine.com&lt;/A&gt; load without problem in that host.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I doing wrong? Why in some cases did it work for me and not in this one?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-right" image-alt="error-manageengine.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1764iB7B11293FDDCC802/image-size/large?v=v2&amp;amp;px=999" role="button" title="error-manageengine.png" alt="error-manageengine.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jul 2019 21:22:26 GMT</pubDate>
    <dc:creator>LuisSP</dc:creator>
    <dc:date>2019-07-01T21:22:26Z</dc:date>
    <item>
      <title>site blocked ....internet server reset connection</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/site-blocked-internet-server-reset-connection/m-p/57176#M2220</link>
      <description>&lt;P&gt;Hi everyone, I've some cases, but I'll post each one separetelly.&lt;/P&gt;&lt;P&gt;I opened traffic to load images from arduino.cc site. Arduino use flickr service to show its images inside the portal.&lt;BR /&gt;First I tried with * .flickr.com and *.staticflickr.com, something similar worked well with other sites, but unfortunately this time it did not work. After a few hours I resolved it with regular expressions:&lt;/P&gt;&lt;P&gt;(^ |. * \.) * staticflickr \ .com&lt;BR /&gt;(^ |. * \.) * flickr \ .com&lt;/P&gt;&lt;P&gt;Now I try to open traffic to &lt;A href="http://www.manageengine.com" target="_blank"&gt;www.manageengine.com&lt;/A&gt;, but no custom application works properly:&lt;/P&gt;&lt;P&gt;* .manageengine.com&lt;BR /&gt;manageengine.com&lt;BR /&gt;(^ |. * \.) * manageengine \ .com (this as a regular expression in another app)&lt;BR /&gt;The browser sends an error ERR_CONNECTION_RESET.&lt;/P&gt;&lt;P&gt;In wireshark I can see that the manageengine.com server resets the connection.&lt;/P&gt;&lt;P&gt;If I open all internet traffic to single local ip address, &lt;A href="http://www.manageengine.com" target="_blank"&gt;www.manageengine.com&lt;/A&gt; load without problem in that host.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I doing wrong? Why in some cases did it work for me and not in this one?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-right" image-alt="error-manageengine.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1764iB7B11293FDDCC802/image-size/large?v=v2&amp;amp;px=999" role="button" title="error-manageengine.png" alt="error-manageengine.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 21:22:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/site-blocked-internet-server-reset-connection/m-p/57176#M2220</guid>
      <dc:creator>LuisSP</dc:creator>
      <dc:date>2019-07-01T21:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: site blocked ....internet server reset connection</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/site-blocked-internet-server-reset-connection/m-p/57491#M2242</link>
      <description>It has to do with the certificate provided by manageengine.com.&lt;BR /&gt;Specifically, it's not providing a CN or DN for us to match against.&lt;BR /&gt;And, unless you're either using HTTPS Inspection or R80.30, we can't see what server you're trying to connect to (R80.30 supports Verified SNI).&lt;BR /&gt;The RST is because it's HTTPS and we cannot inject a block page.&lt;BR /&gt;&lt;BR /&gt;Perhaps you can create a signature using the Application Control Signature Tool instead.&lt;BR /&gt;See: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103051" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103051&lt;/A&gt;</description>
      <pubDate>Thu, 04 Jul 2019 20:17:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/site-blocked-internet-server-reset-connection/m-p/57491#M2242</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-04T20:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: site blocked ....internet server reset connection</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/site-blocked-internet-server-reset-connection/m-p/57500#M2245</link>
      <description>&lt;P&gt;I use https categorization, so if I understand correctly, the FW in this configuration can compare the SUBJECT | CN property, but it does not verify the SUBJECT ALT NAME, where the domain of the site I want to access resides, and therefore the browser complains indicating that a secure connection could not be established (SECURE CONNECTION FAILED .... enfirefox) ... please confirm if I am correct.&lt;/P&gt;&lt;P&gt;My options are:&lt;BR /&gt;use the Application Control Signature Tool and test it.&lt;BR /&gt;Activate https inspection&lt;/P&gt;&lt;P&gt;I already verified with https inspection and yes it works. I want to try the first option too.&lt;/P&gt;&lt;P&gt;I notified you after the result.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 23:14:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/site-blocked-internet-server-reset-connection/m-p/57500#M2245</guid>
      <dc:creator>LuisSP</dc:creator>
      <dc:date>2019-07-04T23:14:57Z</dc:date>
    </item>
  </channel>
</rss>

