- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
All,
I have URL blocking enabled for some domains via Harmony Connect. I believe they are mostly SPAM purveyors but they may also be doing website analytics. However, perusing the logs I can see these domains are bypassing the rules. I am using the same method for other URL's and they are working. These domains are flagged as suspicious and high risk yet I cannot stop them. Interestingly one of the domains in the Harmony Connect Weekly report I receive triggers both Accept AND Reject actions.
Any ideas?
Just to make sure, you have those domains blocked in the same rule as the ones that are blocked properly?
Moving this to the correct space.
Is HTTPS Inspection enabled here?
You might need to engage the TAC to see what's really happening here.
Thanks. HTTPS is not enabled so that could be part of it but I would think that
any simple call to an offending domain would be stopped. If I get some time I'll
contact TAC.
Technically, if those other sites are blocked without inspection on, there is no reason logically why ones you have issues would not be either. Though, obviously, you wont get block page presented, but they should be blocked with message that page cant be loaded or is reset. Do you get any warnings/errors at all or pages simply come up as they normally would?
Andy
Well it's difficult to tell if there are warnings/errors presented as I am not the affected user. Best I can do is ask if there are any page load issues. However, one user is my spouse so I'm fairly certain I would hear about it. 🙂 I will check with her.
Well, I aint Dr Phil, but you BETTER hear from your spouse, HAHAHA. Anyway, without https inspection, no user will ever get block page, as there is nothing for gateway to intercept, but page definitely wont come up.
@the_rock /insert vague admin notice about maintaining a professional discussion here/
@_Val_ Its just light-hearted joke brother, no malicious intent whatsoever : - )
HAPPY NEW YEAR!
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY