- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Good morning from Argentina, I hope you are well.
In my governmental CNV organization, I cannot allow the download of .jpg and .png files.
I attach the error and the policies that I implemented to allow jpg and png.
I can download the office files.
Muchas gracias, saludos!
Greetings from Canada! I have to say, Argentina is pretty cool country and in my opinion, BEST meat dishes in the world : - )
Anywho, I believe below is what you need, but will check with one of my colleagues.
Andy
Saludos again! I think this must be it.
Andy
Hello, thank you very much for your reply. We do have some very tasty meats, thank you!
I have the .jpg and .png exclusions activated and I cannot download those types of files. Ideally, they should not be excluded, but rather sanitized and returned clean.
The current policy shown in the photo would not impact my organization. What can I do?
Saludos!
That looks right to me. Sorry mate, Im not really endpoint furu, so would probably verify with TAC as well. lets see if anyone else may know.
Andy
Just checked client environment, dont see that option there...
Andy
Cloud or on-prem? if this is cloud, can you share a screenshot of the configuration available under 'download protection' in Advanced Settings?
This is cloud.
See below, unless Im looking at the wrong setting?
Andy
You are in a different view, we usually call it 'split mode' which is mostly common to tenants migrating from on-prem.
In any case, can you take a look under 'Threat Emulation' advanced settings?
Yup, see below. I see override action is available under threat emulation...I reckon that has to be it? 🙂
Andy
Yes 🙂
Cool, thank you! Lets see if thats same setting @earomero needs.
I more asked, just being curious : - )
Andy
Hello, greetings from Argentina, thank you very much for answering.
Yes, it does indeed work! However, this configuration is a bypass to the checkpoint agent. There is a way for .jpg and .png files to go through the agent and be sanitized. The objective is not to bypass checkpoint but to use it as a means to secure the environment.
Thank you very much, greetings!
Hi! Ok, I'm waiting for your reply.
Gracias!!
Hi, the recommendation you gave me is very good, however it is to allow unsupported files, creating a bypass in the checkpoint agent.
The objective is to allow .jpg and have them analyzed and sanitized by the checkpoint agent. It is difficult hahaha but not impossible, there must be a way to achieve it.
Greetings from Argentina!
Did you open TAC case yet?
Andy
What is a TAC case? How can I open it?
You need to have user center account or if someone else in your company does, they can open it for you. However, if you are an end user and have CP reseller, you can certainly ask them to open a case on your behalf.
Andy
Please reach out via feedback button in the UI, and I'll explain what can be done.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesThu 06 Nov 2025 @ 10:00 AM (CET)
CheckMates Live BeLux: Get to Know Veriti – What It Is, What It Does, and Why It MattersTue 11 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERTue 11 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY