- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I'm using CheckPoint 790 appliance.
I'm trying to block all internal address outgoing to the internet except white list URL that I had made.
I set up the blade control regarding to the firewall policy on Strict mode, and now the last rule on Outgoing section on the policy is : Any- Internet - Block.
Above it, I made a manual rule says: Any - Internet - My white list URL and accept.
After this, no one can browse inside the organization to the internet to my White list.
I could have some help regarding to this, what do I do wrong?
thanks!
If you don't mind sharing, what is the URL in question?
Note that if it's an HTTPS URL, then you may also need to enable HTTPS Inspection.
Hi,
Thank you for your respond!
its a mixed of web site, banks and web sites related to work.
I may have on that list HTTPS web sites.
but the thing is, when i'm doing the steps I wrote above, no one have an internet at all.
on the logs, it says the user has blocked because of rule number 5 which is the auto generated rule was created due Strict option I did on Firewall blade:
Any- Internet - Block..
For some sites to be detected properly (particularly ones with HTTPS) you may need to enable HTTPS Inspection, which was added in the R70.20.70 firmware release.
If you do not do this, it is possible the gateway will not be able to detect the particular URL correctly.
If that's the case for all the URLs you've decided to whitelist, then the behavior you are seeing is expected.
That's helped, so thank you ver much for that!
however, I have one web site, which is HTTPS, and it doesnt have a certificate. so even with HTTPS inspection -
I cannot properly go into. only when i'm disable the inspection I can browse to it.
there is any way I can get his certificate from the owner and install it on the checkpoint?
if I can, how can I do it?
thank you!
A site can't be HTTPS without having a certificate.
However, HTTPS Inspection can fail for any number of reasons.
There should be logs that indicate why it is failing.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY