- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Hello colleague!
Please help me understand how to implement the following settings.
Our system
SMS Gaia R81.20
ClusterXL Gaia R81.10
Our Web resource has been published on the Internet and is available at (as an example)
https://web-site.com/
We want to leave access only for this path (from Internet)
https://web-site.com/folder/data/
and deny access along the path:
https://web-site.com/folder/catalog/
Is this possible to do using rules on the gateway?
Yes, using a custom application/site and HTTPS Inspection (required to see the URLs accessed).
Yes, using a custom application/site and HTTPS Inspection (required to see the URLs accessed).
Am I correct in understanding that the rule structure itself should look like this (as an example)?
P.S.
SSL inspections activated.
That should work or what I always do is say you want to block anything facebook, I just put it as *facebook* in URL list.
Andy
Unfortunately rule 1.1 does not work.
The traffic eventually goes through rule 1.2
Please show a full log card (mask sensitive data) where that happens (i.e. traffic matches 1.2).
Please also show the certificate used for the website in question when the traffic is accepted.
That only answers the first question.
For the second question, we'll need to know what the actual site you're trying to configure blocking on versus what the certificate for that site says.
You're probably in TAC territory now: https://help.checkpoint.com
Just do wildcard, it will work.
Andy
I tried different options, but unfortunately it didn't solve the problem.
If you are allowed to send me website in private message, so I can test it in the lab?
Andy
I don't see how you can test this given that the site is located in our perimeter.
Or did I misunderstand the question?
You got the answer from phoneboy, for this, you 100% need https inspection.
Andy
URL is encrypted so what the other guys said I agree with. In this case it will be a 'reverse HTTPS inspection'.
So you need to intercept the traffic towards the public server
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 35 | |
| 22 | |
| 17 | |
| 12 | |
| 9 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 7 |
Tue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY