- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hello TaylorHung,
it is difficult to troubleshoot without further information. I suggest either contacting TAC or if you can add a screenshot of the configuration you used?
*Remember this is a public forum. Make sure you do not share any personal data (IPs, passwords etc..)
Yep, I enabled the application and URL Filtering but it doesn't work
As @G_W_Albrecht advised, check the logs, see where its accepted and we can better assist. Rule loos fine, but that on its own does not mean much, unless we can see from the logs why its being accepted.
Andy
Hello TaylorHung,
Like others were stating, we're missing some information like what you defined in those Applications/URL Filtering objects.
Any reason you did not used the YouTube Application defined by Checkpoint ?
Youtube:
MSTeams:
Thank you,
What is shown in Logs ? If you use Any as Source instead of Admin ?
Hello Albrecht,
I tried it, it didn't work. i cant understand. I think this is product trial then block URL
Hello,
Can you share a picture showing what you have insie "Youtube.com" object? I usually block Youtube using the pre-defined application object "Youtube" + a custom Application site with following DNS names: youtube.com, *.youtube.com. Maybe you will need to add more DNS names, you can check the entire list in the Certificate Subject Alternative Name section in youtube's certificate, it will also depends what you are seeing in logs, try searching by IP and port 443 with profile Access Control on logs, you can check wich sites is browsing that IP (check image).
About teams, i always used the updatable object to allow deny this traffic, check if that is feasible for you it will be easier. Never tried with APC/URL blades. HTH
Regards
Hello Daniel,
I have defined application youtube with dns name: youtube.com, *.youtube.com, *.youtube.com.* but it doesn't work
Regards
Is HTTPS inspection enabled and how are those App/URL/service objects defined?
If your end users are using the Chrome browser, does your policy block QUIC traffic?
Note we have built-in objects such as:
Hello Chris_Atkinson,
I attached the picture. I don't think that Checkpoint can't block URL.
How to fix that if you know.
Thanks a lot
I always do the way you do it, except I simply add *youtube*, works like a charm. You can follow same logic for any other website.
You did not answer the question. Do you have HTTPS Inspection enabled? If not, the application you defined will not be detected on TLS traffic, which is 100% of Youtube.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
19 | |
17 | |
12 | |
11 | |
11 | |
8 | |
8 | |
8 | |
5 | |
5 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY