Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
arsathparves
Contributor

Restricting Gmail access to custom domain

Is it possible to block personal email accounts and allow only specific domains for example in my scenario I want to block users access to personal gmail / drive and allow only work email / drive? 

#QuantumSpark#1600

0 Kudos
9 Replies
PhoneBoy
Admin
Admin

I have no idea if this feature works on SMB appliances (centrally or locally managed), but the feature is documented here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... 

0 Kudos
G_W_Albrecht
Legend
Legend

I have asked that in my feedback to sk146993 😎

CCSE CCTE CCSM SMB Specialist
0 Kudos
the_rock
Legend
Legend

I believe you can create custom domains and allow/block them that way.

0 Kudos
arsathparves
Contributor

how would you do that ? for example if you take google workspace for example to login into that it you have to navigate to eg:mail.gmail.com  if i block this whole domain and allow only "myworkemail.com" I wont be able go to that site to login to my custom domains

0 Kudos
the_rock
Legend
Legend

I would have to show you on remote session. Essentially, you create rule above the blocked rule that would allow users to connect to what you need them to connect to.

0 Kudos
arsathparves
Contributor

Ok thanks I will try this out

0 Kudos
PhoneBoy
Admin
Admin

In this case, you have to inject specific headers into the communication which tells the remote end what accounts are allowed.
It cannot be accomplished by simply filtering for specific domains in an Access Policy.

the_rock
Legend
Legend

Sorry, Im not sure if it works differently with quantum 1600 (smb) appliances, but Im sure you would know better : - )

0 Kudos
PhoneBoy
Admin
Admin

It has nothing to do with an SMB appliance, it has to do with how the authentication for Google Workspace works.
More precisely, the same URLs are used for Gmail and Google Workspace.
As a result, by blocking the URLs, you're preventing use of ANY Google services, not just Gmail.

By injecting the appropriate HTTP header as described in the SK, you are telling Google that only specific Google Workspace accounts are allowed.
Google ultimately enforces this.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events