Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ANANTADSULE
Contributor

Specific URL block or allow

Dear All,
Device details as follows.
1550 Appliance
R81.10.17 (996004620)

Locally Managed 

Firewall is set to standard firewall mode with HTTPS inspection and App,URL filterling enabled and I'm trying to block specific url using manual rule but not be able to block it and it's accesible.
Access policy structure as follows.
RUle 1,2,3,4 are SMP cloud rules for other source and destination.'

Rule No 5(Top Manual rule)
Source-192.168.1.97(SGNSB)
Destination-Internet
Application/Services-JIO(tried both-https://*.jio.com and https://www.jio.com)
Action-Block
Log-Log
Rule 6 is for other source and destination working as expected.
Rule 7,8,9 are default rule created by Checkpoint for Standard firewall mode(Untouched)

Please help me to understand the access policy workflow and exact issue with the rule.

Approach is to allow specific urls/applications only.
screenshots attached herewith for your reference.

0 Kudos
7 Replies
the_rock
MVP Gold
MVP Gold

Can you send the log you see about it?

Andy

0 Kudos
ANANTADSULE
Contributor

Have a look at logs.

Same rule but two different action Block and Reject.

I have removed the financial category from SSL bypass,but still same issue if there is any concern.

0 Kudos
the_rock
MVP Gold
MVP Gold

I would check with TAC support on this.

Andy

0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Is it accessible from different browser flavours, is it still accessible on successive / subsequent attempts?

QUIC Protocol & URL Categorization mode - Background vs Hold could be potential factors.

CCSM R77/R80/ELITE
0 Kudos
ANANTADSULE
Contributor

I've updated same rule with following changes and now it's reacting differently.

added two urls- 1)*jio.com getting proper block message now 2)*rbi.org.in getting "This site can’t be reached

" instead of block message.

Screenshot attached for reference. (JIO.jpeg,RBI.jpeg)

0 Kudos
the_rock
MVP Gold
MVP Gold

So its working partially now?

Andy

0 Kudos
ANANTADSULE
Contributor

Yes

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events