Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
flachance
Advisor

Is there a way to block an app or process to access the Internet

Is there a way with either the gateway or the endpoint client to block an app or process to access the Internet?

We don't want to restrict the app from running but we don't want it to access the Internet.

Francis

0 Kudos
7 Replies
Tal_Paz-Fridman
Employee
Employee

You can use the Application Control and URL Filtering blades on the Security Gateway. 

In Rulebase add the relevant application to the Services & Applications column:

 

Applications.png

 

 

0 Kudos
flachance
Advisor

Yes our problem is it's some small/obscure app that is not part of Checkpoint applications list

0 Kudos
Tal_Paz-Fridman
Employee
Employee

For that you can create a custom application using the URLs it uses

 

New Application.png

 

the_rock
Legend
Legend

As @Tal_Paz-Fridman said, thats your best bet, for sure. As a matter of fact, I did the same in my lab and few customers and works 100% of the time.

Below is example in my R81.20 lab.

Andy

 

 

 

Screenshot_1.png

0 Kudos
flachance
Advisor

hmmm ok. But this feels more like URL filtering. You'd have to know where the app might try to connect to which is not our case unfortunately

0 Kudos
the_rock
Legend
Legend

Yes Francis, as @Tal_Paz-Fridman said, you can use app control/urlf for this. I can show you in my R81.20 lab where I have dedicated ordered layer just for this.

Andy

 

Screenshot_1.png

0 Kudos
RS_Daniel
Advisor

Hello,

Yes, there is. I think both fw and endpoint can do it, but if you have endpoint much better. You can use Application Control blade and you two options, terminate the app when it starts to run, or terminate the app when it tries to connect to network.

https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/...

On firewall it is also possible, you can use the option provieded before (yes it is more like URL filtering feture). Or you can create a custom signature for specific application.

https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/...

On both cases you must know where  the app might tries to connect (If not, how could the firewall know what it has to block?). If you do not know you can always take some traffic captures and check.

Regards

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events