Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
pendekarblank
Explorer
Jump to solution

Spark Appliance not working on blocking TikTok URL

Hi Everyone,

 

New joiner in here, I have a problem with TikTok traffic over my network company.

Basically, we already block the TikTok URLs below, as my team seen these URLs has the high consume bandwidth (the traffic over our appliance monitoring)

tiktokcdn.com

tiktokv.com

Then, we already blocked those 2 URL in firewall policy (outgoing traffic), btw this is my first time handling spark appliance, and it looks not having (appliance policy like the security gateways).

Turns out, the traffic of both blocked URLs still appears, most frustrating (for myself), that to check the logs on this appliance is quite taking time and after that not showing anything.

what I search on the logs = dst:tiktokcdn.com or dst:tiktokv.com ---> error showing because taking time to load the logs

Then another confusion coming, when I tried to domain look-up the tiktokcdn.com, it doesn't resolve to any IP addresses.

Just FYI, this is basically outgoing traffic for internet, this is in simple way

PC/phone --> internal equipment --> Check Point Quantum Appliance (DNS configured by the ISP one, not our external DNS) --> internet

Then jump to my question, what is the correct way to block this URLs over this appliance? I guest our firewall rule is not working 😞

source: LAN

destination: tiktokcdn.com; tiktokv.com

application/service: any

action: block

 

Kindest Regards,

Pendekarblank. 

0 Kudos
1 Solution

Accepted Solutions
pendekarblank
Explorer

Hi Amir_Erman, the_rock, Chris_Atkinson, Lesley and Noa_Alon,

Thank you so much for your support, currently the issue solved by another help whit this one --> pi-hole 😄

just apply it as DNS blocker and it works, TikTok traffic now intermittent here (not clearly loaded).

since we found that QUIC traffic used 443/UDP, so we prefer to use another device and act as DNS blocker.

Nevertheless, a case has been raised to vendor as well for further checking.

 

Kind Regards,

Pendekarblank.

View solution in original post

0 Kudos
12 Replies
Amir_Erman
Employee
Employee

To accelerate the analysis - I would try Quantum centrally managed, SPARK centrally managed as well

(For simplicity VM version can be used)

It will allow us to pinpoint where the problem is. 

0 Kudos
pendekarblank
Explorer

Hi Amir_Erman,

Thank you for the suggestion, that's correct we better have centralized management for firewall gateway. but looks like we won't implement it since this appliance is for local break-out only (separate public internet for guest/visitors only). So, it's only 1 appliance -__-"

0 Kudos
the_rock
Legend
Legend

Probably best to have TAC verify all this.

Andy

0 Kudos
pendekarblank
Explorer

Hi the_rock,

That's correct, but currently I don't have receive any information for the raising a case to TAC support (not yet) since we're supporting on branch site, will reach my team more for this one.

0 Kudos
the_rock
Legend
Legend

Thats totally fair. I suggested that since I figured it would be easiest if they did remote to verify all the rules/settings.

Andy

0 Kudos
Chris_Atkinson
Employee Employee
Employee

DoH could be a factor, is HTTPS inspection used and QUIC traffic also blocked?

CCSM R77/R80/ELITE
0 Kudos
pendekarblank
Explorer

Hi Chris_Atkinson,

Uhm, I check on the setting, for SSL inspection, it's only checklist for "HTTPS categorization". It's configured from the beginning, I think.

QUIC, like UDP? I check the firewall rules; we only have specific like this.

specific one.

ANY --> URL --> blocked

.. more blocked rules, then

ANY --> Internet --> Accept.

 

It's the existing configuration.

0 Kudos
Lesley
Mentor Mentor
Mentor

Is this enabled?

  1. Check the value of 'HTTPS categorization  on the Gateways. Log in to the gateway: Device > Advanced Settings > search for "https categorization" and check if it is set to true.
  2. Or check here for the setting:  Access Policy -> SSL Inspection

And why not block all of the TikTok application and only 2 urls?

https://community.checkpoint.com/t5/Security-Gateways/Can-not-block-TikTok/m-p/137254#M20770

 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Noa_Alon
Employee
Employee

Hi,

We verified this scenario in R&D and it works. That means these domains were indeed blocked.

We would like to connect to the relevant environment for investigation to understand the root cause of this issue.

Thanks,

0 Kudos
pendekarblank
Explorer

Hi Lesley,

No, the existing site were checklist for "HTTPS Categorization", looks like I need to enable/choose this one since the other responder suggest this too :D, I will talk to my team first, thank you for the suggestion.

 

edited: why only 2 URLs? because only both still seen on the traffic, and today, appear one more.

listed below.

tiktokcdn.com

tiktokv.com

v16.tiktokcdn.com

0 Kudos
pendekarblank
Explorer

Hi Amir_Erman, the_rock, Chris_Atkinson, Lesley and Noa_Alon,

Thank you so much for your support, currently the issue solved by another help whit this one --> pi-hole 😄

just apply it as DNS blocker and it works, TikTok traffic now intermittent here (not clearly loaded).

since we found that QUIC traffic used 443/UDP, so we prefer to use another device and act as DNS blocker.

Nevertheless, a case has been raised to vendor as well for further checking.

 

Kind Regards,

Pendekarblank.

0 Kudos
the_rock
Legend
Legend

Good job!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events