- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
AI Security Masters E4:
Introducing Cyata - Securing the Agenic AI Era
AI Security Masters E3:
AI-Generated Malware
CheckMates Go:
CheckMates Fest
I don't know that being able to open its page on the chrome web store is a valid test.
yes, i am able to add chrome extension and able to use facebook which we blocked.
Traffic is allowed towards the chrome store not the ultrasurf website. If you want to manage web browser extensions it should be done on GPO level (AD). Or block the chrome store, but then you block all extensions
If user installs extension does this extension work? If so, do you run HTTPS inspection? Or you have categorize https websites enabled?
hi,
Ultrasurf is vpn proxy which used to bypass the firewall to use block website, so when we add ultrasurf on ext it will allow you to access all blocked content.
Go through below link
Solved: Best Practices Against Ultrasurf - Check Point CheckMates
Let me change my questions, why would you let users to install any extension what they want?
Now it is Ultrasurf next week something else. I think you should start with the basic and do something with GPO. There are malicious extension for example: https://www.kaspersky.com/blog/dangerous-browser-extensions-2023/50059/
we are doing setup for University where students will BYOD and we don't have control over them, so need to block what possibility we found .
What was already suggested is probably your best bet.
Andy
So no https inspection. That will be a pain. Is categorize https websites enabled in Smart Console?
Were you able to fix it?
What @Lesley said is 100% correct. I will test this in my lab tomorrow, since I have ssl inspection enabled, but I doubt it will be any different.
Andy
Allowing users to install random browser extensions is considered poor practice.
Having said that, to fully block Ultrasurf, you need to make sure you have a strict outbound policy (only specific web ports allowed) and use HTTPS Inspection + App Control.
Ultrasurf is also known to be very evasive and we’ve had to adjust the signature for it in the past.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 44 | |
| 28 | |
| 14 | |
| 13 | |
| 11 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 6 |
Mon 23 Feb 2026 @ 11:00 AM (EST)
Latest updates on Quantum Spark including R82 features and Spark Management zero touch - AMERTue 24 Feb 2026 @ 10:00 AM (CET)
Latest updates on Quantum Spark including R82 features and Spark Management zero touch - EMEATue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANMon 23 Feb 2026 @ 11:00 AM (EST)
Latest updates on Quantum Spark including R82 features and Spark Management zero touch - AMERTue 24 Feb 2026 @ 10:00 AM (CET)
Latest updates on Quantum Spark including R82 features and Spark Management zero touch - EMEATue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANThu 26 Feb 2026 @ 05:00 PM (CET)
AI Security Masters Session 4: Introducing Cyata, Securing the Agentic AI EraFri 06 Mar 2026 @ 08:00 AM (COT)
Check Point R82 Hands‑On Bootcamp – Comunidad DOJO PanamáAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY