- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello and good morning
I have some problems with smb 1490
I don't know if anyone had the same problem or if it's a limitation of SMB 1400
When clients use the google chrome web browser for some web pages, checkpoint cant categorized correctly by checkpoint
Yes I have a rule that blocks all traffic that cannot be classified, but the problem is the incorrect categorization.
note : this happen in all SMB appliances(1400).
On the other hand, when the client uses firefox explorer in the same pages, these are correctly categorized after this if the client uses the google chrome explorer, again it is already correctly categorized by checkpoint.
to take into account that
1.- I don't have https inspection (resources problems) activated.
But I understand that it complies with Categorize HTTPS Websites via Certificate Checking.
2.- the session is performed by the TLS1.2v on the clients.
3.- The SNI and the CN have the same name as the domain of the web page
4.- Google chrome and firefox are updated (also try old versions with the same result).
5.- The smb is centrally administered
6.- the management and the smb is update.
SMB 1400 R77.20.87 (990173004). Management R80.30 JH take 191
7.- Trusted Ca and blacklist is update .
Please if someone has any clue or knows what could be happening? or if a limitation of smb
Thanks for the help.
Hello and ty for the help PhoneBoy
Are you blocking QUIC?
Yes te quic protocol is blooqued by the firewall and i try to block in the client too , but with the the same results .
Try to set in SmartConsole, Manage & Settings -> Blades -> APPCL & URLF -> CheckPoint online web service -> Web categorization mode to "Hold" and see if that makes any difference in observed behavior.
URL categorization is made in CheckPoint Cloud not on device itself. I think if for some reason it fails to do that it will threat it as uncategorized.
Agree. It is worth involving TAC here.
May be sniff the traffic between Firefox and SMB and then between Chrome and SMB and compare it. Pay special attention to HTTP headers and what browser sends as requested URL.
Any progress with this? We are seeing the same thing
We're running into the same thing with several sites (running on 15400 appliances R80.40) which started up a few days ago, we do block uncategorized sites. I haven't had time to sift through the logs on all the sites but several of them appear to be hosted on AWS. Even www.amazon.com shopping site which we permit gets blocked when it reaches the uncategorized AWS hosts.
Wonder if AWS added a new IP subnet that Checkpoint hasn't categorized yet?
Hello @charcris
Since when you're experiencing the issue?
Have you been able to access any of those websites before?
Have you tried to access the website via IP like this: https://185.76.64.164:443
Also can you tried to disable enforce safe search > install policy > clear cookies/cache on browser or open a private tab and share the results.
Hablo español cualquier cosa amigo!
Thanks!
Thanks
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY