Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
007_mjn
Contributor
Jump to solution

Harmony endpoint url filtering

Hi All,

I'm using harmony endpoint cloud based for my 1000 users. I have a basic license for this endpoint.

I have enabled only firewall, application control, compliance and VPN blade for my endpoint clients.

I have also enabled anti-bot, url filtering, threat emulation, behavioral guard and forensics and anti-ransomware just for testing on my few clients. 

Can I enable only url filtering blade for my users?

I have set url filtering mode into prevent. And I have selected category is social networking. But I have to excluded facebook from this but still facebook blocked by url filtering.

I have attached images for this you can check this.

0 Kudos
1 Solution

Accepted Solutions
007_mjn
Contributor

yes, you are right. Now its working with *facebook*.

View solution in original post

0 Kudos
11 Replies
PhoneBoy
Admin
Admin

Pretty sure you have to deploy Anti-Bot for URL Filtering to be active.
That's based on the user-level documentation for the client: https://sc1.checkpoint.com/documents/HarmonyEndpoint/Endpoint_Security_Clients_for_Windows_UserGuide...

Also, they likely use similar infrastructure on the Endpoint similar to how it works on a gateway.
If you want URL Filtering only, then you might want to look at Harmony Browse.

0 Kudos
007_mjn
Contributor

Anti-bot is enabled too. Still it block it. is this the correct domain to exclude like *.facebook.com

0 Kudos
the_rock
Legend
Legend

That looks right, though me personally, I ALWAYS use an example, such as *facebook* and I never have an issue.

0 Kudos
007_mjn
Contributor

Thanks for the reply.

I have a question for application control.

I want to use application control blade for endpoint devices. I have run the appscan software on my desktop and it successfully scanned the application on my desktop of c:\ drive program files but it can't generate the xml files.

why it can't generate xml file?

why I can' make many rule for application control on SmartEndpoint server?

I have shared some screenshot you can check it.

0 Kudos
PhoneBoy
Admin
Admin

I recommend a TAC case for this: https://help.checkpoint.com 

0 Kudos
anstelios
Collaborator

There are examples in the UI about how URL exceptions are defined: http?://*.facebook.com  etc..

0 Kudos
the_rock
Legend
Legend

Keep in mind...all the examples given in guides and UI itself dont always work...I worked with TAC (tier2,3, escalation team) numerous times on this and literally every time, we ended up doing my suggestion, which was *fqdn*...so say *facebook*, *youtube*...etc

Is it perfect? Of course NOT, but, every customer I know would rather do it that way and call it a day then spend hours on end trying to make it work recommended way and not succeed.

0 Kudos
007_mjn
Contributor

yes, you are right. Now its working with *facebook*.

0 Kudos
the_rock
Legend
Legend

I am 100% sure that will always work...as I said, not perfect solution, but at least, it is somewhat good "workaround"

Andy

0 Kudos
007_mjn
Contributor

Thanks @the_rock 

I have a question for application control.

I want to use application control blade for endpoint devices. I have run appscan software on my desktop and it successfully scanned the application on my desktop of c:\ drive program files but it can't generate the xml files.

why it can't generate xml file?

why I can' make many rule for application control on SmartEndpoint server?

I have shared some screenshot you can check it.

0 Kudos
the_rock
Legend
Legend

Questions are free mate @007_mjn , all good :- )

Answer may cost you money...just kidding : ). But, in all seriousness, Im not that familiar with endpoint side, I mostly deal with firewalls, so I dont want to BS you and try to give you answer to something I have no clue about. Maybe someone else can confirm or you can double check with TAC on it.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events