- Products
- Learn
- Local User Groups
- Partners
- More
Simplify Admin Operations with R82.20
Watch HereThe State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
READY OR NOT: Securing the AI Enterprise
AI Research & Threat Landscape
CheckMates Go:
Half is Not Enough
Hi all,
Scenario:
I have been turning on URLF and AppControl and doing some testing on it. I created a very simple policy using inline layers
We found a High Risk (4) application in the logs but it is being allowed by the sub-layer 1 despite being a High Risk application.
The application definition says you need to apply HTTPS Inspection but the it is being properly categorised without HTTPS Inspection being applied yet is being caught by sub-layer 1.
Is this expected behaviour? Any other thoughts on how to resolve this?
I want to keep HTTPS Inspection to a minimum.
Categorisation set for background or hold?
Are you able to share the example application?
R81.20 Jumbo T65 or higher?
Is QUIC traffic blocked in the environment?
Hi Chris,
We're on Take 98 and QUIC is blocked.
I think I have found the reason for the Allow in the Matched Rules part of the log - it is classed as Medium risk. So why is a High risk app matching as Medium?
I can attached the sub-layers and log output.
Hi Chris,
We're on Take 98 and QUIC is blocked.
I think I have found the reason for the Allow in the Matched Rules part of the log - it is classed as Medium risk. So why is a High risk app matching as Medium?
I can attached the sub-layers and log output.
Hi Chris,
We're on Take 98 and QUIC is blocked.
I think I have found the reason for the Allow in the Matched Rules part of the log - it is classed as Medium risk. So why is a High risk app matching as Medium?
I can attached the sub-layers and log output.
Thanks Chris,
Could be that, I guess. I've scheduled and update to T05. Will report back.
Thanks Chris,
Could be that, I guess. I've scheduled and update to T05. Will report back.
All excellent questions by Chris. Apart from that, can you send the relevant log? Please blur out any sensitive data. I can tell you from my experience, below is what I found works best.
Andy
All excellent questions by Chris. Apart from that, can you send the relevant log? Please blur out any sensitive data. I can tell you from my experience, below is what I found works best.
Andy