Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SubZer0
Collaborator
Jump to solution

Block .lzn file extension in MTA Blade

I would like to block the .lzh file extension in MTA Blade. When I go to the settings, this extension is not listed, even though SK106123 https://support.checkpoint.com/results/sk/sk106123 states that Check Point supports it.

Does this extension need to be added manually or configured additionally in the firewall?

0 Kudos
1 Solution

Accepted Solutions
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Are you sure?

lzn-screen.png

CCSM R77/R80/ELITE

View solution in original post

23 Replies
Vincent_Bacher

You are talking about te blade, right?

Which release are you using?

 

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
SubZer0
Collaborator

I am using MTA blade: 81.20.991002020 https://support.checkpoint.com/results/sk/sk123174 

0 Kudos
Vincent_Bacher

I don't mean to be pedantic, but MTA is a feature, not a blade.

The question was relevant since you linked to a Threat Emulation SK.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Im fairly sure I know setting you are referring to, but screenshot would help confirm.

Best,
Andy
SubZer0
Collaborator

Screenshot 2025-12-15 204424.png

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Let me check it in the lab, but yea, thats it.

Best,
Andy
the_rock
MVP Platinum
MVP Platinum

Just verified, tested R82 lab as well. file not listed. Wish those files extensions can be sorted alphabetically, but either way, its not present.

Best,
Andy
SubZer0
Collaborator

Is it possible to add manually?

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Does not appear to be the case, cant find that option anywhere.

Best,
Andy
Vincent_Bacher

When I was still working intensively with it, I always had to be careful not to constantly confuse TE and TX, so I just remembered that there was an SK for TX where you could enable new file extensions via scrub configuration and add new extensions, while you had to submit a request for new file types for TE.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Good point Vince.

Best,
Andy
0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Note that you are looking at AV protections here and not TE.

The extension not being there doesn't imply that TE will take no action on malicious files.

Start here: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_ThreatPrevention_AdminGuide/Topics...

CCSM R77/R80/ELITE
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Just checked Chris, still not even there.

Best,
Andy
0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Are you sure?

lzn-screen.png

CCSM R77/R80/ELITE
the_rock
MVP Platinum
MVP Platinum

Yea, I know its there, I was referring to TP profile settings, its definitely not there. 

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Apologies Chris, I see it worked now in the lab. I made sure lzh extension was enabled in blade settings, pushed policy and then it came up in the profile.

Best,
Andy
0 Kudos
SubZer0
Collaborator

Thank you all for your cooperation. However, I still have an open question.

Is it possible to block attachments with the .lzh file extension on the MTA?

Under Threat Prevention → Threat Emulation, I have the .lzh extension enabled.

Screenshot 2025-12-16 154517.png

However, when I go to Threat Prevention → Threat Extraction → Configure File Type Support, the .lzh extension is not listed.

Screenshot 2025-12-16 154600.png

The same extension is also not available under Profiles → Anti-Virus, where it would otherwise be possible to block the file type.

Screenshot 2025-12-16 154634.png

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Keep in mind, those are 2 separate blades.

Best,
Andy
SubZer0
Collaborator

I understand that Threat Emulation has this capability and Threat Extraction does not.
However, is it possible to add this functionality to Threat Extraction?

0 Kudos
the_rock
MVP Platinum
MVP Platinum

If its listed in the file list, then you can try add it.

Best,
Andy
SubZer0
Collaborator

Yes but how can I add it? 

0 Kudos
Vincent_Bacher

There was an old SK
sk112240 - How to add support for new file types in Threat Extraction
But newer releases are not listed and no clue how it's done nowadays.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
PhoneBoy
Admin
Admin

I didn't see the relevant files in R82.
Sounds like it might be worth a TAC case, referencing sk112240.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events