<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to allow access to a web traffic ressource? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165838#M7976</link>
    <description>&lt;P&gt;Thanks for your replies.&lt;/P&gt;&lt;P&gt;Yes, the device is beeing managed by a central security management server (even tho its not a smart-1 but openserver based, makes no difference here). We actually tried making it work with domain objects like "domain.com" with FQDN set, had no success with it however. Since the external IP address in the destination field of the log is beeing resolved to sth different than what is displayed in the web traffic ressouce field , I assume we need to create a domain object which relates to the destination IP, rather than the ressouce shown.&lt;/P&gt;&lt;P&gt;We gonna try it out and give feedback here.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Dec 2022 07:30:19 GMT</pubDate>
    <dc:creator>FXB</dc:creator>
    <dc:date>2022-12-22T07:30:19Z</dc:date>
    <item>
      <title>How to allow access to a web traffic ressource?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165761#M7971</link>
      <description>&lt;P&gt;Dear community,&lt;/P&gt;&lt;P&gt;we are currently facing the challenge, that one of our employees is having a software installed which need to connect via MySQL (TCP 3306) to an external internet ressource.&lt;/P&gt;&lt;P&gt;Unfortunately that internet ressource has an ever-changing external IP so allowing the traffic with a static src/dest/port rule is not an option.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at the log we see that our checkpoint gateway recognized the web traffic ressouce (test.domain.com in this example) to which the software is trying to connect via MySQL (see attachment).&lt;/P&gt;&lt;P&gt;Is there a way to allow the access based on this web ressource?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The gateway is running R80.20.40, domain objects did not work (probably since its not a http(s) traffic but SQL).&lt;/P&gt;&lt;P&gt;Any hint is appreciated!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Franz&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 09:22:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165761#M7971</guid>
      <dc:creator>FXB</dc:creator>
      <dc:date>2022-12-21T09:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow access to a web traffic ressource?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165763#M7972</link>
      <description>&lt;P&gt;This is Embedded GAiA - why not allow all connections from&amp;nbsp;&lt;SPAN&gt;employees local IP / Access Role using&amp;nbsp;TCP 3306 to Internet ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 09:31:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165763#M7972</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-12-21T09:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow access to a web traffic ressource?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165765#M7973</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thanks for your response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Allowing all tcp_3306 traffic from the client to the internet would be the fall-back solution. We would like to have an as-tight-as- possible ruleset in regards to internet connections, so if there would be a way to use the web ressouce for the allow-rule that would be the prefered way.&lt;/P&gt;&lt;P&gt;Our mindset was that if checkpoint is detecting this ressouce, surely there could be some way to use this information for the ruleset?&lt;/P&gt;&lt;P&gt;You are correct in assuming its embedded-gaia, if this is the wrong section of the forum, please move the topic to the correct one if possible &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 09:42:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165765#M7973</guid>
      <dc:creator>FXB</dc:creator>
      <dc:date>2022-12-21T09:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow access to a web traffic ressource?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165780#M7974</link>
      <description>&lt;P&gt;I’ve moved it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mentioned you’re using an SMB device but the log card suggests it’s being managed by a Smart-1..correct?&lt;BR /&gt;The correct way to do this is with a Domain Object with the FQDN checkbox tagged in the relevant access policy rule, which will use DNS to determine what the IP will be.&lt;BR /&gt;Even if the device is locally managed, you can create a similar domain object for the policy.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 13:20:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165780#M7974</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-21T13:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow access to a web traffic ressource?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165832#M7975</link>
      <description>&lt;P&gt;I agree with advice&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;gave you. Domain object is way to go here.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 03:59:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165832#M7975</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-22T03:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow access to a web traffic ressource?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165838#M7976</link>
      <description>&lt;P&gt;Thanks for your replies.&lt;/P&gt;&lt;P&gt;Yes, the device is beeing managed by a central security management server (even tho its not a smart-1 but openserver based, makes no difference here). We actually tried making it work with domain objects like "domain.com" with FQDN set, had no success with it however. Since the external IP address in the destination field of the log is beeing resolved to sth different than what is displayed in the web traffic ressouce field , I assume we need to create a domain object which relates to the destination IP, rather than the ressouce shown.&lt;/P&gt;&lt;P&gt;We gonna try it out and give feedback here.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 07:30:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-allow-access-to-a-web-traffic-ressource/m-p/165838#M7976</guid>
      <dc:creator>FXB</dc:creator>
      <dc:date>2022-12-22T07:30:19Z</dc:date>
    </item>
  </channel>
</rss>

