- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Starting today November 21. 06am (local time in Germany) we could observe a lot of false positives with application control/url filter. Most of legitimate traffic will be detected as "ExpressVPN". This application has risk level critical and will be blocked.
Interesting detail, only traffic related to proxy connections will be detect as "expressVPN". We can see this for connections proxy => proxy and between client and proxy
This view shows timeline of the application "expressVPN" only:
Anyone seeing same problem?
@_Val_ problem is solved with an updated package for ApplicationControl/URLFilter from the last night. This was a little nightmare last day, because most of all Internet traffic was detected as "critical" and blocked. Teams, O365, sometimes www.google.de and a lot more.
Hi,
I can confirm this, same behaviour here.
kind regards,
mp2012
Trying to figure out if there is an easy way to test this in the lab with just one windows PC behind it...I did filter like below for 30 days in my lab and dont see anything, but will ask customer who runs app control to do it and see what they get.
blade:"Application Control" AND appi_name:ExpressVPN
@the_rock it's only seen with involved proxy, without no problem !
Ah, gotcha...never mind then.
Do you have a TAC case for this?
TAC case is open, R&D is working on it. Told me ther's a known issue with the application database.
Is this resolved for you yet?
Hi,
for me problem is solved now (environment with proxies involved too).
kind regards,
mp2012
@_Val_ problem is solved with an updated package for ApplicationControl/URLFilter from the last night. This was a little nightmare last day, because most of all Internet traffic was detected as "critical" and blocked. Teams, O365, sometimes www.google.de and a lot more.
I certainly understand, and I am sorry about it.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 6 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY