Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
pendekarblank
Explorer

Spark Appliance not working on blocking TikTok URL

Hi Everyone,

 

New joiner in here, I have a problem with TikTok traffic over my network company.

Basically, we already block the TikTok URLs below, as my team seen these URLs has the high consume bandwidth (the traffic over our appliance monitoring)

tiktokcdn.com

tiktokv.com

Then, we already blocked those 2 URL in firewall policy (outgoing traffic), btw this is my first time handling spark appliance, and it looks not having (appliance policy like the security gateways).

Turns out, the traffic of both blocked URLs still appears, most frustrating (for myself), that to check the logs on this appliance is quite taking time and after that not showing anything.

what I search on the logs = dst:tiktokcdn.com or dst:tiktokv.com ---> error showing because taking time to load the logs

Then another confusion coming, when I tried to domain look-up the tiktokcdn.com, it doesn't resolve to any IP addresses.

Just FYI, this is basically outgoing traffic for internet, this is in simple way

PC/phone --> internal equipment --> Check Point Quantum Appliance (DNS configured by the ISP one, not our external DNS) --> internet

Then jump to my question, what is the correct way to block this URLs over this appliance? I guest our firewall rule is not working 😞

source: LAN

destination: tiktokcdn.com; tiktokv.com

application/service: any

action: block

 

Kindest Regards,

Pendekarblank. 

0 Kudos
4 Replies
Amir_Erman
Employee
Employee

To accelerate the analysis - I would try Quantum centrally managed, SPARK centrally managed as well

(For simplicity VM version can be used)

It will allow us to pinpoint where the problem is. 

0 Kudos
the_rock
Legend
Legend

Probably best to have TAC verify all this.

Andy

0 Kudos
Chris_Atkinson
Employee Employee
Employee

DoH could be a factor, is HTTPS inspection used and QUIC traffic also blocked?

CCSM R77/R80/ELITE
0 Kudos
Lesley
Mentor Mentor
Mentor

Is this enabled?

  1. Check the value of 'HTTPS categorization  on the Gateways. Log in to the gateway: Device > Advanced Settings > search for "https categorization" and check if it is set to true.
  2. Or check here for the setting:  Access Policy -> SSL Inspection

And why not block all of the TikTok application and only 2 urls?

https://community.checkpoint.com/t5/Security-Gateways/Can-not-block-TikTok/m-p/137254#M20770

 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events