The program is an executable. When you double click it the program calls out to the licensing server in the cloud, verifies the license is good, then a big mapping page opens. This works off our network on my laptop. When I put my laptop behind our firewall (including directly behind so no network involvement), it calls out to the license server, My laptop is not the issue as it works off network. I see the license transaction go through, we receive a 200 from the remote server, and I see traffic going back and forth and then it just stops and the program does not open. This is all on port 80 but I added an https bypass exception also just in case.
I put in a rule in our policy which allows this particular desktop to go anywhere on any port (wasn't going to keep it there, just for testing), we also added a global exception for any IPS, AV or AB. No luck.
Checkpoint added a rule through the CLI directly on the gateway so that even the basic packet inspection would not occur. I apologize but I don't know exactly what it was, and that worked. It was some kind of acceleration, but we have SecureXL on, this was in addition to that. Also, SecureXL had to be on for the rule to work, when he turned it off the program stopped working again. The rule also just allowed the workstation to go anywhere on any port without any packet inspection at all.
The firewall logs all show the traffic going through and being accepted on port 80. On the pcap where it works you see the last traffic comes from the vendor. On the pcap where it does not you see our desktop calling out again and no response. Checkpoint says the last call does not work with the basic inspection and they need to discuss it with the vendor to find out why. I appreciate that they are willing to do that and I am trying to get an IT number there so I can get a conference call going.
I am really just trying to find out if this indeed an issue with this particular program. We are getting ready to move ~4000 employees to this firewall for internet traffic. I only have about 30 going through now. I am worried if this is not a one-off, and if it is an issue with the firewall, I am really going to have my hands full when we move everyone. 😞
Any insight or thoughts you have are greatly appreciated.
Thanks
terri