<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Check Page only showing up for some devices in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/User-Check-Page-only-showing-up-for-some-devices/m-p/62687#M2384</link>
    <description>Are you managing the policy for this SMB device locally via WebUI or from Central Management?&lt;BR /&gt;&lt;BR /&gt;The difference in block page behavior would be explained by using HTTPS Inspection on some segments, but not others.&lt;BR /&gt;Are you using it?&lt;BR /&gt;&lt;BR /&gt;This would also explain why 9gag is not being correctly detected in some instances.&lt;BR /&gt;This is because 9gag is using CloudFlare for DDoS protection, which uses a wildcard TLS certificate unrelated to 9gag.&lt;BR /&gt;With HTTPS Inspection, we can see what site the user is going to.&lt;BR /&gt;Without HTTPS Inspection, we have to rely on SNI detection, something the SMB codebase does not do currently.&lt;BR /&gt;For non-SMB gateways, this functionality was added In R80.30.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 13 Sep 2019 00:30:51 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-09-13T00:30:51Z</dc:date>
    <item>
      <title>User Check Page only showing up for some devices</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/User-Check-Page-only-showing-up-for-some-devices/m-p/62620#M2383</link>
      <description>&lt;P&gt;I am currently configuring URL Filtering on a Check Point 1430.&amp;nbsp; I have 2 LANs coming in. Comcast Network (CN) and Plant Network (PN). There is also a DMZ configuring on the firewall. There is a Domain running on the networks. The DC sits solely on PN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, I'm trying to block &lt;A href="https://www.netflix.com" target="_blank"&gt;https://www.netflix.com&lt;/A&gt; and &lt;A href="https://www.9gag.com" target="_blank"&gt;https://www.9gag.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On my phone 1, going through CN WiFi, I get the User Check Page when accessing either page.&lt;/P&gt;&lt;P&gt;On Desktop 1, not on domain, using a local user account, and hardwired into CN, I get the User Check Page when accessing 9gag. When accessing Netflix, I get Connection Failed screen.&lt;/P&gt;&lt;P&gt;On&amp;nbsp; desktop 2, not on domain, using a local Admin account, using CN WiFi, Netflix is blocked with secure connection failed. 9gag is NOT blocked at all.&lt;/P&gt;&lt;P&gt;On desktop 2, not on domain, using a local Admin account, hardwired into CN, Netflix is blocked with secure connection failed. 9gag is NOT blocked at all.&lt;/P&gt;&lt;P&gt;On a VM 1, on domain, using an Admin account for Domain, Hard Wired into either PN or DMZ, both sites are blocked with the User Check Page&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Priority is making sure things are blocked on WiFi, specifically phones and iPads, so the works can't access sites they shouldn't be with them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 14:30:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/User-Check-Page-only-showing-up-for-some-devices/m-p/62620#M2383</guid>
      <dc:creator>HunterMathews</dc:creator>
      <dc:date>2019-09-12T14:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: User Check Page only showing up for some devices</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/User-Check-Page-only-showing-up-for-some-devices/m-p/62687#M2384</link>
      <description>Are you managing the policy for this SMB device locally via WebUI or from Central Management?&lt;BR /&gt;&lt;BR /&gt;The difference in block page behavior would be explained by using HTTPS Inspection on some segments, but not others.&lt;BR /&gt;Are you using it?&lt;BR /&gt;&lt;BR /&gt;This would also explain why 9gag is not being correctly detected in some instances.&lt;BR /&gt;This is because 9gag is using CloudFlare for DDoS protection, which uses a wildcard TLS certificate unrelated to 9gag.&lt;BR /&gt;With HTTPS Inspection, we can see what site the user is going to.&lt;BR /&gt;Without HTTPS Inspection, we have to rely on SNI detection, something the SMB codebase does not do currently.&lt;BR /&gt;For non-SMB gateways, this functionality was added In R80.30.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 13 Sep 2019 00:30:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/User-Check-Page-only-showing-up-for-some-devices/m-p/62687#M2384</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-13T00:30:51Z</dc:date>
    </item>
  </channel>
</rss>

