<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incorrect categorization of url filtering when use Google Crhome in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85443#M3548</link>
    <description>Are you blocking QUIC?&lt;BR /&gt;&lt;BR /&gt;Just to note: we do not look at SNI at all on that SMB code release.&lt;BR /&gt;That capability was only added to R80.20.05, which is not available for the 1490 (but is on the newer 1500 series).&lt;BR /&gt;However, when I went to that site, the CN of the certificate looks correct, so we should see it.&lt;BR /&gt;</description>
    <pubDate>Fri, 15 May 2020 23:22:50 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-05-15T23:22:50Z</dc:date>
    <item>
      <title>Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85435#M3547</link>
      <description>&lt;P&gt;Hello and good morning&lt;/P&gt;&lt;P&gt;I have some problems with smb 1490&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know if anyone had the same problem or if it's a limitation of SMB 1400&lt;/P&gt;&lt;P&gt;When clients use the google chrome web browser for some web pages, checkpoint cant&amp;nbsp;categorized correctly by checkpoint&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chrome.block.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6103i799036B4FAF304AF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="chrome.block.png" alt="chrome.block.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Yes I have a rule that blocks all traffic that cannot be classified, but the problem is the&amp;nbsp; incorrect categorization.&lt;/P&gt;&lt;P&gt;note : this happen in all&amp;nbsp; SMB appliances(1400).&lt;/P&gt;&lt;P&gt;On the other hand, when the client uses firefox explorer in the same pages, these are correctly categorized after this if the client uses the google chrome explorer, again it is already correctly categorized by checkpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="firefox.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6105i576E03BE4D772286/image-size/medium?v=v2&amp;amp;px=400" role="button" title="firefox.png" alt="firefox.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logssmart.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6106i43AE6C674EE71687/image-size/medium?v=v2&amp;amp;px=400" role="button" title="logssmart.png" alt="logssmart.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="categorizacion.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6109i2AF8D3DB9FA7947A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="categorizacion.png" alt="categorizacion.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;to take into account that &lt;/P&gt;&lt;P&gt;1.- I don't have https inspection (resources problems) activated.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;But I understand that it complies with Categorize HTTPS Websites via Certificate Checking.&lt;BR /&gt;2.- the session is performed by the TLS1.2v on the clients.&lt;BR /&gt;3.- The SNI and the CN have the same name as the domain of the web page&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TLS.SNI.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6107i1ED874F1AFF96775/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TLS.SNI.png" alt="TLS.SNI.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CN.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6108i506D67228506DBF7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CN.png" alt="CN.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;4.- Google chrome and firefox&amp;nbsp; are updated (also try old versions with the same result).&lt;BR /&gt;5.- The smb is centrally administered&lt;/P&gt;&lt;P&gt;6.- the management and the smb is update.&lt;/P&gt;&lt;P&gt;SMB 1400 R77.20.87 (990173004).&amp;nbsp; &amp;nbsp;Management R80.30 JH take 191&lt;/P&gt;&lt;P&gt;7.- Trusted Ca and blacklist is update .&lt;/P&gt;&lt;P&gt;Please if someone has any clue or knows what could be happening? or if a limitation of smb&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2020 21:13:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85435#M3547</guid>
      <dc:creator>charcris</dc:creator>
      <dc:date>2020-05-15T21:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85443#M3548</link>
      <description>Are you blocking QUIC?&lt;BR /&gt;&lt;BR /&gt;Just to note: we do not look at SNI at all on that SMB code release.&lt;BR /&gt;That capability was only added to R80.20.05, which is not available for the 1490 (but is on the newer 1500 series).&lt;BR /&gt;However, when I went to that site, the CN of the certificate looks correct, so we should see it.&lt;BR /&gt;</description>
      <pubDate>Fri, 15 May 2020 23:22:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85443#M3548</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-15T23:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85466#M3549</link>
      <description>&lt;P&gt;Hello&amp;nbsp; and ty for the help PhoneBoy&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are you blocking QUIC?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Yes te quic protocol is blooqued by the firewall and i try to block in the client too , but with the the same results .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="QUIC.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6116i3D8297BD10AC8007/image-size/medium?v=v2&amp;amp;px=400" role="button" title="QUIC.png" alt="QUIC.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 May 2020 14:08:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85466#M3549</guid>
      <dc:creator>charcris</dc:creator>
      <dc:date>2020-05-16T14:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85467#M3550</link>
      <description>&lt;P&gt;Try to set in SmartConsole, Manage &amp;amp; Settings -&amp;gt; Blades -&amp;gt; APPCL &amp;amp; URLF -&amp;gt; CheckPoint online web service -&amp;gt; Web categorization mode to "Hold" and see if that makes any difference in observed behavior.&lt;/P&gt;</description>
      <pubDate>Sat, 16 May 2020 14:31:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85467#M3550</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-05-16T14:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85492#M3554</link>
      <description>mm yes right now the mode of web categorization is in hold , but the problem persist , ty for the help HristoGrigorov(you can see it in the 4° photo).&lt;BR /&gt;</description>
      <pubDate>Sun, 17 May 2020 03:22:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85492#M3554</guid>
      <dc:creator>charcris</dc:creator>
      <dc:date>2020-05-17T03:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85493#M3555</link>
      <description>&lt;P&gt;URL categorization is made in CheckPoint Cloud not on device itself. I think if for some reason it fails to do that it will threat it as uncategorized.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2020 03:28:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85493#M3555</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-05-17T03:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85495#M3556</link>
      <description>Yes, but when the client uses firefox as a browser, it seems that checkpoint can correctly categorize it.&lt;BR /&gt;so it is a bit strange that with firefox checkpoint can categorize it.</description>
      <pubDate>Sun, 17 May 2020 03:32:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85495#M3556</guid>
      <dc:creator>charcris</dc:creator>
      <dc:date>2020-05-17T03:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85497#M3558</link>
      <description>&lt;P&gt;Agree. It is worth involving TAC here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2020 03:34:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85497#M3558</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-05-17T03:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85501#M3560</link>
      <description>yes the tac is involved , but at the moment couldn't be determine what it could be, so I open this case in the community to find out if anyone may have had the same problem.&lt;BR /&gt;Any help is appreciated</description>
      <pubDate>Sun, 17 May 2020 03:52:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85501#M3560</guid>
      <dc:creator>charcris</dc:creator>
      <dc:date>2020-05-17T03:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85502#M3561</link>
      <description>&lt;P&gt;May be sniff the traffic between Firefox and SMB and then between Chrome and SMB and compare it. Pay special attention to HTTP headers and what browser sends as requested URL.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2020 04:05:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/85502#M3561</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-05-17T04:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/125338#M5454</link>
      <description>&lt;P&gt;Any progress with this?&amp;nbsp; We are seeing the same thing&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 15:10:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/125338#M5454</guid>
      <dc:creator>mconlogue</dc:creator>
      <dc:date>2021-07-30T15:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/125352#M5455</link>
      <description>&lt;P&gt;We're running into the same thing with several sites (running on 15400 appliances R80.40) which started up a few days ago, we do block uncategorized sites.&amp;nbsp; &amp;nbsp;I haven't had time to sift through the logs on all the sites but several of them appear to be hosted on AWS.&amp;nbsp; &amp;nbsp;Even &lt;A href="http://www.amazon.com" target="_blank"&gt;www.amazon.com&lt;/A&gt;&amp;nbsp;shopping site which we permit gets blocked when it reaches the uncategorized AWS hosts.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;Wonder if AWS added a new IP subnet that Checkpoint hasn't categorized yet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 18:35:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/125352#M5455</guid>
      <dc:creator>George_Casper</dc:creator>
      <dc:date>2021-07-30T18:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/125356#M5456</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/29136"&gt;@charcris&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since when you're experiencing the issue?&lt;/P&gt;&lt;P&gt;Have you been able to access any of those websites before?&lt;/P&gt;&lt;P&gt;Have you tried to access the website via IP like this: &lt;A href="https://185.76.64.164:443" target="_blank" rel="noopener"&gt;https://185.76.64.164:443&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also can you tried to disable enforce safe search &amp;gt; install policy &amp;gt; clear cookies/cache on browser or open a private tab and share the results.&lt;/P&gt;&lt;P&gt;Hablo español cualquier cosa amigo!&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 19:36:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/125356#M5456</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2021-07-30T19:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Incorrect categorization of url filtering when use Google Crhome</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/202640#M10087</link>
      <description>&lt;P&gt;After a lot of days of researchs I found a solution for this without enable HTTPS Inspection.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;- On Network Layer - create a Drop rule for UDP 443 QUIC&lt;/P&gt;&lt;P&gt;- On App control &amp;amp; URL Filtering layer - create a DROP rule for desired categories like Pornografy, Sex, Nudity ...&lt;BR /&gt;&lt;BR /&gt;- And the final key for firewall Drop correctly the sites on this categories for Google Chrome create a object New Override Categorization - and set a Risk High or Critical, after that the firewall will Drop with more criteria and priority all sites classified on this categories that you create a New Override Categorization object. Set one site just to save the object, but important thing here will be the risk&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;From the&amp;nbsp;Objects&amp;nbsp;tab of SmartConsole, select&amp;nbsp;New &amp;gt; More &amp;gt; Custom Application/Site &amp;gt; Override Categorization&lt;BR /&gt;&lt;BR /&gt;Before applied this configuration a lot of porn sites oppening just on the Google Chrome, and on this customer don't was possible enable HTTPS Inspection, with this configurations was possible drop everything just with URL Filtering.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="New-override-categorization.jpg" style="width: 424px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24030i62C3093DB0B4B503/image-size/large?v=v2&amp;amp;px=999" role="button" title="New-override-categorization.jpg" alt="New-override-categorization.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 19:28:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incorrect-categorization-of-url-filtering-when-use-Google-Crhome/m-p/202640#M10087</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2024-01-09T19:28:59Z</dc:date>
    </item>
  </channel>
</rss>

