- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
One of our customers have a use case of allowing only business / corporate Dropbox accounts and block the personal ones via Checkpoint firewall.
I request your suggestions on how we can achieve this.
One possibility is to use HTTPS Inspection and leverage HTTP Header insertion and create restriction based on Dropbox team IDs.
(
:appi_parameters (
: (
:app_id (10050988)
:parameters (
: (
:parameter_type ("Header Injection")
:parameter_values (
: (
:type ("Header Name")
:value ("X-Dropbox-allowed-Team-Ids")
)
: (
:type ("Header Value")
:value ("**This will be replaced with TeamID**")
)
)
)
)
)
)
)Where 10050988 is the application ID of Dropbox and the gateway intercepts requests related to Dropbox and adds the HTTP header X-Dropbox-allowed-Team-Ids (Values of the Dropbox Team ID field). This header's value is the business account's team ID.
The above approach must block access to personal accounts and allow access to only specified teams, but the challenge here is that if there are 100s or 1000s of teams this is not a feasible / scalable approach as collection of team IDs and configuring the application parameter file is a tedious task.
I wanted to know, does checkpoint provide any out-of-the-box solution for this problem via app control? or there are any other ways that can fulfil this business requirement. For ex. restrict the access if the user is trying to login from personal mail account.
Regards,
Chethan
CCSM R80
Quantum Force (Security Gateways) Security Gateway Appliances Quantum Solution Family
In order to use the header injection bits, you need to use HTTPS Inspection.
Problem is, Dropbox uses Certificate Pinning and will not work with HTTPS Inspection.
This is how others are doing it too.
Is there any other way to block personal Dropbox accounts?
So, in that case bypass HTTPS inspection for Dropbox or block it entirely?
I got private message you sent me about this, will respond there.
Best,
Andy
Thank you, I've replied to it.
Same here...Im still working at 10 pm at night, never expected CP upgrade to take 4 hours LOL
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY