<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Application control/URL and Antivirus in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-control-URL-and-Antivirus/m-p/91923#M3895</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;a couple of questions,using CP1490 local managed&lt;/P&gt;&lt;P&gt;1. has anyone enabled the URL for botnets or phishing?&amp;nbsp; if so any success to show it actual works?&lt;/P&gt;&lt;P&gt;2. has anyone had any success blocking pornography categorization?&amp;nbsp; just noticed mine is not working properly sites are accessible, hit and miss (some will display can't load page - don't have ssl inspection on or display the blocked if it's http)&amp;nbsp; However, I've noticed a spike in zombies everytime the firewall attempts to block the pornography sites.&amp;nbsp; Zoombies are on the httpd.&amp;nbsp; Have a TAC as I have a custom firmware B3034&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; I currently have the antibot blade on and considering the antivirus (don't have my own smtp server), any value.&amp;nbsp; my emails are all web based or IMAP on some machines, laptops mobile. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Definitely seeking some advise for those that are on similar platform or simply know from usage experience.&lt;/P&gt;&lt;P&gt;Thanks, &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jul 2020 11:27:50 GMT</pubDate>
    <dc:creator>Naftali_Oziel</dc:creator>
    <dc:date>2020-07-20T11:27:50Z</dc:date>
    <item>
      <title>Application control/URL and Antivirus</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-control-URL-and-Antivirus/m-p/91923#M3895</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;a couple of questions,using CP1490 local managed&lt;/P&gt;&lt;P&gt;1. has anyone enabled the URL for botnets or phishing?&amp;nbsp; if so any success to show it actual works?&lt;/P&gt;&lt;P&gt;2. has anyone had any success blocking pornography categorization?&amp;nbsp; just noticed mine is not working properly sites are accessible, hit and miss (some will display can't load page - don't have ssl inspection on or display the blocked if it's http)&amp;nbsp; However, I've noticed a spike in zombies everytime the firewall attempts to block the pornography sites.&amp;nbsp; Zoombies are on the httpd.&amp;nbsp; Have a TAC as I have a custom firmware B3034&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; I currently have the antibot blade on and considering the antivirus (don't have my own smtp server), any value.&amp;nbsp; my emails are all web based or IMAP on some machines, laptops mobile. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Definitely seeking some advise for those that are on similar platform or simply know from usage experience.&lt;/P&gt;&lt;P&gt;Thanks, &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 11:27:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-control-URL-and-Antivirus/m-p/91923#M3895</guid>
      <dc:creator>Naftali_Oziel</dc:creator>
      <dc:date>2020-07-20T11:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: Application control/URL and Antivirus</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-control-URL-and-Antivirus/m-p/91936#M3896</link>
      <description>&lt;P&gt;From your description, it doesn't look like you have ssl inspection on? The feature you want to work is best with ssl inspection on.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 13:43:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-control-URL-and-Antivirus/m-p/91936#M3896</guid>
      <dc:creator>Cyber_Serge</dc:creator>
      <dc:date>2020-07-20T13:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: Application control/URL and Antivirus</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-control-URL-and-Antivirus/m-p/91940#M3897</link>
      <description>&lt;P&gt;Thanks and it's off by design for now, it has it's pro's and con's. &amp;nbsp; The question is why the firewall is producing zombie entries for httpd when it hits the URL categorization block?&amp;nbsp; plus seeking if anyone have their anti-virus on and if it has shown any value?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 14:22:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-control-URL-and-Antivirus/m-p/91940#M3897</guid>
      <dc:creator>Naftali_Oziel</dc:creator>
      <dc:date>2020-07-20T14:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Application control/URL and Antivirus</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-control-URL-and-Antivirus/m-p/92026#M3905</link>
      <description>&lt;P&gt;AV does work for me (730), as well as ABOT and URLF. It is rather easy to test that, though 8)&lt;/img&gt;&amp;nbsp;Without https inspection, your possibilities are very limited as URL categorization will not be able to fully recognize all sites.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 08:49:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-control-URL-and-Antivirus/m-p/92026#M3905</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-07-21T08:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Application control/URL and Antivirus</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-control-URL-and-Antivirus/m-p/92063#M3907</link>
      <description>&lt;P&gt;Thanks, avoided the SSL inspection simply as my application is home usage and URLF is not required but interesting observations of why when it did detected a site in block the firewall produced zombie process for httpd?.&amp;nbsp;&amp;nbsp; However, do have the ABOT, IPS and APP. &amp;nbsp;&amp;nbsp; Am curious on your setup for AV do you have any internal mail servers?&amp;nbsp; does it catch more sites that could be deemed malware and block?&amp;nbsp;&amp;nbsp; does it take more memory or processor hits, slows down your traffic?&amp;nbsp; just determining if it will be of value for me to have it enabled?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 12:36:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Application-control-URL-and-Antivirus/m-p/92063#M3907</guid>
      <dc:creator>Naftali_Oziel</dc:creator>
      <dc:date>2020-07-21T12:36:40Z</dc:date>
    </item>
  </channel>
</rss>

