<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URLF Blocked vs Reject? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/URLF-Blocked-vs-Reject/m-p/192778#M9500</link>
    <description>&lt;P&gt;To generate a block page consistently, HTTPS Inspection must be enabled.&lt;BR /&gt;This is because it is not possible to inject a block page once an HTTPS session starts because…it’s encrypted.&lt;BR /&gt;In this situation, you will get the “can’t reach this page” error.&lt;BR /&gt;In other words, this is expected behavior.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Sep 2023 15:19:58 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-09-15T15:19:58Z</dc:date>
    <item>
      <title>URLF Blocked vs Reject?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/URLF-Blocked-vs-Reject/m-p/192753#M9499</link>
      <description>&lt;P&gt;Why is some web traffic &lt;STRONG&gt;blocked&lt;/STRONG&gt;, and other traffic &lt;STRONG&gt;rejected&lt;/STRONG&gt;?&amp;nbsp; I’m having problems with Facebook and YouTube.&lt;/P&gt;&lt;P&gt;I have a Spark 1500, R81.10.05, currently managed via the Infinity Portal Spark Management, but I’ve also turn off Cloud management and tried locally and get the same results.&lt;/P&gt;&lt;P&gt;I have HTTPS Inspection enabled.&amp;nbsp; Trying to go back to basics, I’ve turn off all “bypass” categories:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="biskit_0-1694775304841.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22476i6FF5A5B307C39CD9/image-size/large?v=v2&amp;amp;px=999" role="button" title="biskit_0-1694775304841.png" alt="biskit_0-1694775304841.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a test I enabled URLF, in the &lt;STRONG&gt;Block Other… &lt;/STRONG&gt;box I only have &lt;STRONG&gt;Media Streams&lt;/STRONG&gt; selected.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="biskit_1-1694775304852.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22477iAB8D2AACF527B0E4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="biskit_1-1694775304852.png" alt="biskit_1-1694775304852.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="biskit_2-1694775304855.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22478i19E79C0E7D92B3E4/image-size/large?v=v2&amp;amp;px=999" role="button" title="biskit_2-1694775304855.png" alt="biskit_2-1694775304855.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I browse to &lt;A href="https://vimeo.com" target="_blank"&gt;https://vimeo.com&lt;/A&gt; I get a User Check block page.&amp;nbsp; The log shows the connection as “Blocked” and I see the redirect.&amp;nbsp; Great!&amp;nbsp; That’s what I expect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="biskit_3-1694775304860.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22479iD692C40A2DC9A806/image-size/large?v=v2&amp;amp;px=999" role="button" title="biskit_3-1694775304860.jpeg" alt="biskit_3-1694775304860.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But…&lt;/P&gt;&lt;P&gt;When I browse to &lt;A href="https://youtube.com" target="_blank"&gt;https://youtube.com&lt;/A&gt; I do &lt;STRONG&gt;not&lt;/STRONG&gt; get the block message.&amp;nbsp; Instead I just get “can’t reach this page”, and the log shows a Reject, and also that HTTPS Inspection was bypassed.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="biskit_4-1694775304863.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22481i083C2B7ACDDF17FF/image-size/large?v=v2&amp;amp;px=999" role="button" title="biskit_4-1694775304863.jpeg" alt="biskit_4-1694775304863.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="biskit_5-1694775304865.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22480iD646A3E87E854BEE/image-size/large?v=v2&amp;amp;px=999" role="button" title="biskit_5-1694775304865.png" alt="biskit_5-1694775304865.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Exactly the same thing happens when I add Facebook to the &lt;STRONG&gt;&lt;EM&gt;Block Other…&lt;/EM&gt;&lt;/STRONG&gt; group.&amp;nbsp; It is rejected, HTTPS bypassed, and I get no User Check block message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why do some sites get correctly categorised, blocked, and redirected to the User Check block page, while others are bypassed and rejected with no block message?&amp;nbsp; Why is YouTube and Facebook HTTPS Bypassed and then rejected with no block message?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 10:58:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/URLF-Blocked-vs-Reject/m-p/192753#M9499</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2023-09-15T10:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: URLF Blocked vs Reject?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/URLF-Blocked-vs-Reject/m-p/192778#M9500</link>
      <description>&lt;P&gt;To generate a block page consistently, HTTPS Inspection must be enabled.&lt;BR /&gt;This is because it is not possible to inject a block page once an HTTPS session starts because…it’s encrypted.&lt;BR /&gt;In this situation, you will get the “can’t reach this page” error.&lt;BR /&gt;In other words, this is expected behavior.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 15:19:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/URLF-Blocked-vs-Reject/m-p/192778#M9500</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-15T15:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: URLF Blocked vs Reject?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/URLF-Blocked-vs-Reject/m-p/192779#M9501</link>
      <description>&lt;P&gt;HTTPS Inspection &lt;FONT color="#000000"&gt;&lt;STRONG&gt;is &lt;/STRONG&gt;already&amp;nbsp;&lt;/FONT&gt;on.&lt;BR /&gt;I've put the same Spark box onto a proper SmartCenter today and from limited testing, I think I'm seeing the same behaviour.&amp;nbsp; &amp;nbsp;All sites tested are HTTPS and some sites get the block message, others get the "page not found" message.&amp;nbsp; &amp;nbsp;I can't figure out a pattern at the moment.&amp;nbsp; Maybe it's a Spark issue?&amp;nbsp; I'll test further next week and compare the same policy installed to a non-Spark.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 16:08:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/URLF-Blocked-vs-Reject/m-p/192779#M9501</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2023-09-15T16:08:53Z</dc:date>
    </item>
  </channel>
</rss>

