- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Has anyone tested the custom rules in the application control? Honestly, I've tested everything and the custom rules don't work; only the rules defined in "app rules" work. For example: I want to create a rule that blocks all versions of Firefox.
Hi,
Just tested with field Issued to and worked fine, attaching the test rule i used. Version E89.05.
Can you please clarify what you define as being a "custom rule" and more specifically if this is being tested with / without HTTPS inspection and with what gateway version & JHF etc?
/Edit: Noted this is an Endpoint query.
These custom rules don't work; only the app rules work. See the images below.
Hey brother,
Mind sending a screenshot as an example of what you tested?
EDIT:
My reply below is about the Check Point Security Gateway capabilities and not Harmony Endpoint App Control capabilities.
I wonder if AppScan could help here.
-------------------------
Works for me
R82
No https inspection
New connection - first time Firefox is used - no caching
Firefox browser is blocked.
I actually tried same in my lab Don and it also blocked incognito window, so definitely works. But, I have a feeling @lluner was referring to endpoint policy, just my impression based on what was posted.
Ah, ooops. I didn't spot that it in the Endpoint forum.
Thanks for that.
The issue is that the blocking occurs at the harmony endpoint, not at the gateway checkpoint.
Thats what I figured based on your screenshots. Did you open TAC case yet?
I'm first trying to see if anyone can configure these settings and provide an example.
Let me ask one of my colleagues, have a call with him in few mins, he is very good with endpoint. Will update you after.
I've already tried using AppScan, and it works. The problem is that you need to create a custom rule for multiple versions of Adobe, Firefox, or 7-Zip. Using AppScan becomes impractical.
This is what my colleague showed me, not sure if you tried it or not.
I've tried everything to block Adobe and other applications, but nothing works.
So regardless of which application you try, same result?
Yes, I've tried everything. I tried following the manual exactly, but it doesn't work. It only works when I use AppScan, import the file, and then block it.
Configuring Application Permissions in the Application Control Policy
It only works by uploading the AppScan XML file. The "custom rules" option doesn't work at all.
Below are the application control logs using the AppScan XML file.
I would definitely open TAC case and reference this post.
That's what I'm going to do; I've already opened a ticket with a partner. I'll keep you updated here.
I will check with my colleague again, but I can tell by the things you post and try about harmony endpoint, that you are very FAMILIAR with it, so I trust all you did. Please keep us posted.
Excellent work, as always.
Hello,
We usually block apps using the field Issued To, and that blocks all versiones of the app. You can check on a couple diferent versions of firefox to check if the cert matchs just to double check. In some tests, we saw that the "Application Name" field is actually the name of the process running on windows, so for adobe i think you can use "Acrobat.exe" on your rule. Attaching an example to block opera. HTH.
Hey Daniel,
Just for my own knowledge, what is the key field in custom rule for it to work?
I've already tested all of that. I only see one thing: the endpoint version. What version are you using?
So no change regardless of what app is used?
I wonder if that field has to be 100% correct, since I just tried Mozilla, without corporation, but no joy.
It worked. Thanks for the help.
Excellent!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 3 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY