<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: White list URL in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15427#M441</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A site can't be HTTPS without having a certificate.&lt;/P&gt;&lt;P&gt;However, HTTPS Inspection can fail for any number of reasons.&lt;/P&gt;&lt;P&gt;There should be logs that indicate why it is failing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Dec 2017 17:00:35 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2017-12-01T17:00:35Z</dc:date>
    <item>
      <title>White list URL</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15422#M436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm using CheckPoint 790 appliance.&lt;BR /&gt;I'm trying to block all internal address outgoing to the internet except white list URL that I had made.&lt;BR /&gt;I set up the blade control regarding to the firewall policy on Strict mode, and now the last rule on Outgoing section on the policy is : Any- Internet - Block.&lt;BR /&gt;Above it, I made a manual rule says: Any - Internet - My white list URL and accept.&lt;/P&gt;&lt;P&gt;After this, no one can browse inside the organization to the internet to my White list.&lt;/P&gt;&lt;P&gt;I could have some help regarding to this, what do I do wrong?&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Nov 2017 18:32:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15422#M436</guid>
      <dc:creator>roy_adir</dc:creator>
      <dc:date>2017-11-29T18:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: White list URL</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15423#M437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you don't mind sharing, what is the URL in question?&lt;/P&gt;&lt;P&gt;Note that if it's an HTTPS URL, then you may also need to enable HTTPS Inspection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Nov 2017 00:27:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15423#M437</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-30T00:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: White list URL</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15424#M438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you for your respond!&lt;/P&gt;&lt;P&gt;its a mixed of web site, banks and web sites related to work.&lt;/P&gt;&lt;P&gt;I may have on that list HTTPS web sites.&lt;/P&gt;&lt;P&gt;but the thing is, when i'm doing the steps I wrote above, no one have an internet at all.&lt;/P&gt;&lt;P&gt;on the logs, it says the user has blocked because of rule number 5 which is the auto generated rule was created due Strict option I did on Firewall blade:&lt;/P&gt;&lt;P&gt;Any- Internet - Block..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Nov 2017 09:06:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15424#M438</guid>
      <dc:creator>roy_adir</dc:creator>
      <dc:date>2017-11-30T09:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: White list URL</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15425#M439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For some sites to be detected properly (particularly ones with HTTPS) you may need to enable HTTPS Inspection, which was added in the R70.20.70 firmware release.&lt;/P&gt;&lt;P&gt;If you do not do this, it is possible the gateway will not be able to detect the particular URL correctly.&lt;/P&gt;&lt;P&gt;If that's the case for all the URLs you've decided to whitelist, then the behavior you are seeing is expected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Nov 2017 15:45:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15425#M439</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-30T15:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: White list URL</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15426#M440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's helped, so thank you ver much for that!&lt;/P&gt;&lt;P&gt;however, I have one web site, which is HTTPS, and it doesnt have a certificate. so even with HTTPS inspection -&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot properly go into. only when i'm disable the inspection I can browse to it.&lt;/P&gt;&lt;P&gt;there is any way I can get his certificate from the owner and install it on the checkpoint?&lt;/P&gt;&lt;P&gt;if I can, how can I do it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2017 16:26:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15426#M440</guid>
      <dc:creator>roy_adir</dc:creator>
      <dc:date>2017-12-01T16:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: White list URL</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15427#M441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A site can't be HTTPS without having a certificate.&lt;/P&gt;&lt;P&gt;However, HTTPS Inspection can fail for any number of reasons.&lt;/P&gt;&lt;P&gt;There should be logs that indicate why it is failing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2017 17:00:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/White-list-URL/m-p/15427#M441</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-12-01T17:00:35Z</dc:date>
    </item>
  </channel>
</rss>

