Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
OldCLTGeek
Participant
Jump to solution

Anonymizer filtering blocks access to Intuit / Quicken services :-(

I have an SMB customer on 730 box that is under subscription maint.

Everything has been fine for years. Last night or today something changed.

Client is small tax firm with only a couple of employees. They use  Quicken/Intuit software to complete tax returns.

Quicken/Intuit is apparently routing traffic to akamaitechnologies.com owned sites and the 730 is blocking it.

An example IP is:  a23-212-249-86.deploy.static.akamaitechnologies.com    [23.212.249.86]

I have disabled Anonymizer URL filtering for the moment so tax returns can be prepared.

Very small company of trusted employees. I'm thinking there is no big risk of having the filter turned off...

but am looking for other opinions, or suggestions to tighten things up.

THANKS!

OldGeek

 

0 Kudos
2 Solutions

Accepted Solutions
Lesley
Advisor

I would block Anonymizer , because if users figured out how this works the rest of the policy you made can by bypassed via proxy.

Same for VPN's. If they run and are allowed to run VPN all traffic is encrypted and the policy you made is not usefull.

Second point, looks like there was a false positive. If I check the URL now it should be allowed. 

Can be verified on: https://urlcat.checkpoint.com/urlcat/main.htm

-------
If you like this post please give a thumbs up(kudo)! 🙂

View solution in original post

0 Kudos
OldCLTGeek
Participant

Thanks Lesley!

I did not know about the URL lookup feature ... silly old man that I am ... 🙄

It does appear to have been false positive! I'll tell him to  "Try it now"   😉

 

 

View solution in original post

0 Kudos
8 Replies
PhoneBoy
Admin
Admin

The latest software for the 730 does not support SNI which is how we are able to categorize websites without full HTTPS Inspection.
That means sites will be categorized according to the site certificate CN only, which will often reflect a different site (e.g. Akamai) if a CDN or similar is used.
The only solution to this problem is to upgrade to newer hardware that supports newer software versions that support SNI...or use full HTTPS Inspection.

(1)
OldCLTGeek
Participant

Thanks PhoneBoy!

The 730 is more than a few years old.... I'll suggest the budget for a new device (when tax season is over  😉

 

0 Kudos
Lesley
Advisor

I would block Anonymizer , because if users figured out how this works the rest of the policy you made can by bypassed via proxy.

Same for VPN's. If they run and are allowed to run VPN all traffic is encrypted and the policy you made is not usefull.

Second point, looks like there was a false positive. If I check the URL now it should be allowed. 

Can be verified on: https://urlcat.checkpoint.com/urlcat/main.htm

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
OldCLTGeek
Participant

Thanks Lesley!

I did not know about the URL lookup feature ... silly old man that I am ... 🙄

It does appear to have been false positive! I'll tell him to  "Try it now"   😉

 

 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Which version & build of firmware is used on this 700, these will be EOL in October 2024.

Further to the limitations called out above note there were some recent issues with categorisation which I believe were resolved since.

https://community.checkpoint.com/t5/Management/Lots-of-sites-being-categorized-as-anonymizers-inc-Sp...

CCSM R77/R80/ELITE
0 Kudos
OldCLTGeek
Participant

Thanks Chris!

I'm traveling today and don't have the details with me, but the unit is under service contract.

We will budget for replacement over the summer, once the "thrill" of tax season is over!

 

 

 

 

0 Kudos
Tom_Hinoue
Advisor
Advisor

I believe this is related to the mass false positive that occurred around Sun~Mon last week.
The IPs categorized as Anonymizer should be mostly fixed by now. Do you still experience the issue?

0 Kudos
OldCLTGeek
Participant

Thanks Tom - will be testing this soon!

 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events