- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: How to block path wise URL.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to block path wise URL.
Want to block this type of url. Already follow the custom URL block procedure, but the URL is still accessible.
We want to block
hxxps://github.com/agbusi/keteorie/bojb/gain/yrsfaction_Rkoj_jpg.zip
this type of URL. Where hxxps=https.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just add *github* as custom app site object and use that in the policy rule. I always do so in app/url ordered layer.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @the_rock
I want to block the whole path only, not the full application/site. Is it possible?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello mate,
I think that if you want to block this specific URL, you need inspect the https traffic to know the HTTP URI. As @the_rock said, the other way is blocking the domain github, that is possible because the TLS SNI header is not encrypted.
BR.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Mate. So, if i want to block specific URLs then i must need HTTPS inspection blade enabled?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
correct!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thats right, so you definitely need https inspection feature turned on.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @the_rock
Thanks for your response. Is there any SK/Document available regarding this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I cnt think of any off the top of my head, but will see if I can find it. Ping me offline if you need more help, I have really good https inspetion lab...well, 2 as a matter of fact, but 1 I always use it.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Best I found is below.
Andy
https://support.checkpoint.com/results/sk/sk108202
https://support.checkpoint.com/results/sk/sk65123
